view_create.php 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204
  1. <?php
  2. /* vim: set expandtab sw=4 ts=4 sts=4: */
  3. /**
  4. * handles creation of VIEWs
  5. *
  6. * @todo js error when view name is empty (strFormEmpty)
  7. * @todo (also validate if js is disabled, after form submission?)
  8. * @package PhpMyAdmin
  9. */
  10. use PhpMyAdmin\Core;
  11. use PhpMyAdmin\Url;
  12. use PhpMyAdmin\Response;
  13. use PhpMyAdmin\Template;
  14. require_once './libraries/common.inc.php';
  15. /**
  16. * Runs common work
  17. */
  18. require './libraries/db_common.inc.php';
  19. $url_params['goto'] = 'tbl_structure.php';
  20. $url_params['back'] = 'view_create.php';
  21. $response = Response::getInstance();
  22. $view_algorithm_options = array(
  23. 'UNDEFINED',
  24. 'MERGE',
  25. 'TEMPTABLE',
  26. );
  27. $view_with_options = array(
  28. 'CASCADED',
  29. 'LOCAL'
  30. );
  31. $view_security_options = array(
  32. 'DEFINER',
  33. 'INVOKER'
  34. );
  35. // View name is a compulsory field
  36. if (isset($_REQUEST['view']['name'])
  37. && empty($_REQUEST['view']['name'])
  38. ) {
  39. $message = PhpMyAdmin\Message::error(__('View name can not be empty!'));
  40. $response->addJSON(
  41. 'message',
  42. $message
  43. );
  44. $response->setRequestStatus(false);
  45. exit;
  46. }
  47. if (isset($_REQUEST['createview']) || isset($_REQUEST['alterview'])) {
  48. /**
  49. * Creates the view
  50. */
  51. $sep = "\r\n";
  52. if (isset($_REQUEST['createview'])) {
  53. $sql_query = 'CREATE';
  54. if (isset($_REQUEST['view']['or_replace'])) {
  55. $sql_query .= ' OR REPLACE';
  56. }
  57. } else {
  58. $sql_query = 'ALTER';
  59. }
  60. if (Core::isValid($_REQUEST['view']['algorithm'], $view_algorithm_options)) {
  61. $sql_query .= $sep . ' ALGORITHM = ' . $_REQUEST['view']['algorithm'];
  62. }
  63. if (! empty($_REQUEST['view']['definer'])) {
  64. if (strpos($_REQUEST['view']['definer'], '@') === false) {
  65. $sql_query .= $sep . 'DEFINER='
  66. . PhpMyAdmin\Util::backquote($_REQUEST['view']['definer']);
  67. } else {
  68. $arr = explode('@', $_REQUEST['view']['definer']);
  69. $sql_query .= $sep . 'DEFINER=' . PhpMyAdmin\Util::backquote($arr[0]);
  70. $sql_query .= '@' . PhpMyAdmin\Util::backquote($arr[1]) . ' ';
  71. }
  72. }
  73. if (isset($_REQUEST['view']['sql_security'])) {
  74. if (in_array($_REQUEST['view']['sql_security'], $view_security_options)) {
  75. $sql_query .= $sep . ' SQL SECURITY '
  76. . $_REQUEST['view']['sql_security'];
  77. }
  78. }
  79. $sql_query .= $sep . ' VIEW '
  80. . PhpMyAdmin\Util::backquote($_REQUEST['view']['name']);
  81. if (! empty($_REQUEST['view']['column_names'])) {
  82. $sql_query .= $sep . ' (' . $_REQUEST['view']['column_names'] . ')';
  83. }
  84. $sql_query .= $sep . ' AS ' . $_REQUEST['view']['as'];
  85. if (isset($_REQUEST['view']['with'])) {
  86. if (in_array($_REQUEST['view']['with'], $view_with_options)) {
  87. $sql_query .= $sep . ' WITH ' . $_REQUEST['view']['with']
  88. . ' CHECK OPTION';
  89. }
  90. }
  91. if (!$GLOBALS['dbi']->tryQuery($sql_query)) {
  92. if (! isset($_REQUEST['ajax_dialog'])) {
  93. $message = PhpMyAdmin\Message::rawError($GLOBALS['dbi']->getError());
  94. return;
  95. }
  96. $response->addJSON(
  97. 'message',
  98. PhpMyAdmin\Message::error(
  99. "<i>" . htmlspecialchars($sql_query) . "</i><br /><br />"
  100. . $GLOBALS['dbi']->getError()
  101. )
  102. );
  103. $response->setRequestStatus(false);
  104. exit;
  105. }
  106. // If different column names defined for VIEW
  107. $view_columns = array();
  108. if (isset($_REQUEST['view']['column_names'])) {
  109. $view_columns = explode(',', $_REQUEST['view']['column_names']);
  110. }
  111. $column_map = $GLOBALS['dbi']->getColumnMapFromSql(
  112. $_REQUEST['view']['as'], $view_columns
  113. );
  114. $systemDb = $GLOBALS['dbi']->getSystemDatabase();
  115. $pma_transformation_data = $systemDb->getExistingTransformationData(
  116. $GLOBALS['db']
  117. );
  118. if ($pma_transformation_data !== false) {
  119. // SQL for store new transformation details of VIEW
  120. $new_transformations_sql = $systemDb->getNewTransformationDataSql(
  121. $pma_transformation_data, $column_map,
  122. $_REQUEST['view']['name'], $GLOBALS['db']
  123. );
  124. // Store new transformations
  125. if ($new_transformations_sql != '') {
  126. $GLOBALS['dbi']->tryQuery($new_transformations_sql);
  127. }
  128. }
  129. unset($pma_transformation_data);
  130. if (! isset($_REQUEST['ajax_dialog'])) {
  131. $message = PhpMyAdmin\Message::success();
  132. include 'tbl_structure.php';
  133. } else {
  134. $response->addJSON(
  135. 'message',
  136. PhpMyAdmin\Util::getMessage(
  137. PhpMyAdmin\Message::success(),
  138. $sql_query
  139. )
  140. );
  141. $response->setRequestStatus(true);
  142. }
  143. exit;
  144. }
  145. $sql_query = ! empty($_GET['sql_query']) ? $_GET['sql_query'] : '';
  146. // prefill values if not already filled from former submission
  147. $view = array(
  148. 'operation' => 'create',
  149. 'or_replace' => '',
  150. 'algorithm' => '',
  151. 'definer' => '',
  152. 'sql_security' => '',
  153. 'name' => '',
  154. 'column_names' => '',
  155. 'as' => $sql_query,
  156. 'with' => '',
  157. );
  158. if (Core::isValid($_REQUEST['view'], 'array')) {
  159. $view = array_merge($view, $_REQUEST['view']);
  160. }
  161. $url_params['db'] = $GLOBALS['db'];
  162. $url_params['reload'] = 1;
  163. echo Template::get('view_create')->render([
  164. 'ajax_dialog' => isset($_REQUEST['ajax_dialog']),
  165. 'text_dir' => $text_dir,
  166. 'url_params' => $url_params,
  167. 'view' => $view,
  168. 'view_algorithm_options' => $view_algorithm_options,
  169. 'view_with_options' => $view_with_options,
  170. 'view_security_options' => $view_security_options,
  171. ]);