Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

1,188 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

The Database Package Build StatusBuild status

Latest Stable VersionTotal DownloadsLatest Unstable VersionLicense

Introduction

The Database package is designed to manage the operations of data management through the use of a generic database engine.

// Example for initialising a database driver in a custom application class.useJoomla\Application\AbstractApplication;
useJoomla\Database;
class MyApplication extends AbstractApplication
{
/** * Database driver. * * @var Database\DatabaseDriver * @since 1.0 */protected$db;
protectedfunctiondoExecute()
{
// Do stuff
}
protectedfunctioninitialise()
{
// Make the database driver.$dbFactory = newDatabase\DatabaseFactory;
$this->db = $dbFactory->getDriver(
$this->get('database.driver'),
array(
'host' => $this->get('database.host'),
'user' => $this->get('database.user'),
'password' => $this->get('database.password'),
'port' => $this->get('database.port'),
'socket' => $this->get('database.socket'),
'database' => $this->get('database.name'),
)
);
}
}

Escaping Strings and Input

Strings must be escaped before using them in queries (never trust any variable input, even if it comes from a previous database query from your own data source). This can be done using the escape and the quote method.

The escape method will generally backslash unsafe characters (unually quote characters but it depends on the database engine). It also allows for optional escaping of additional characters (such as the underscore or percent when used in conjunction with a LIKE clause).

The quote method will escape a string and wrap it in quotes, however, the escaping can be turned off which is desirable in some situations. The quote method will also accept an array of strings and return an array quoted and escaped (unless turned off) string.

functionsearch($title)
{
// Get the database driver from the factory, or by some other suitable means.$db = DatabaseDriver::getInstance($options);
// Search for an exact match of the title, correctly sanitising the untrusted input.$sql1 = 'SELECT * FROM #__content WHERE title = ' . $db->quote($title);
// Special treatment for a LIKE clause.$search = $db->quote($db->escape($title, true) . '%', false);
$sql2 = 'SELECT * FROM #__content WHERE title LIKE ' . $search;
if (is_array($title))
{
$sql3 = 'SELECT * FROM #__content WHERE title IN ('
. implode(',', $db->quote($title)) . ')';
}
// Do the database calls.
}

In the first case, the title variable is simply escaped and quoted. Any quote characters in the title string will be prepended with a backslash and the whole string will be wrapped in quotes.

In the second case, the example shows how to treat a search string that will be used in a LIKE clause. In this case, the title variable is manually escaped using escape with a second argument of true. This will force other special characters to be escaped (otherwise you could set youself up for serious performance problems if the user includes too many wildcards). Then, the result is passed to the quote method but escaping is turned off (because it has already been done manually).

In the third case, the title variable is an array so the whole array can be passed to the quote method (this saves using a closure and a )

Shorthand versions are available the these methods:

  • q can be used instead of quote
  • qn can be used instead of quoteName
  • e can be used instead of escape

These shorthand versions are also available when using the Database\DatabaseQuery class.

Iterating Over Results

The Database\DatabaseIterator class allows iteration over database results

$db = DatabaseDriver::getInstance($options);
$iterator = $db->setQuery(
$db->getQuery(true)->select('*')->from('#__content')
)->getIterator();
foreach ($iteratoras$row)
{
// Deal with $row
}

It allows also to count the results.

$count = count($iterator);

Logging

Database\DatabaseDriver implements the Psr\Log\LoggerAwareInterface so is ready for intergrating with a logging package that supports that standard.

Drivers log all errors with a log level of LogLevel::ERROR.

If debugging is enabled (using setDebug(true)), all queries are logged with a log level of LogLevel::DEBUG. The context of the log include:

  • sql : The query that was executed.
  • category : A value of "databasequery" is used.

An example to log error by Monolog

Add this to composer.json

{
"require" : {
"monolog/monolog" : "1.*"
}
}

Then we push Monolog into Database instance.

useMonolog\Logger;
useMonolog\Handler\StreamHandler;
useMonolog\Processor\PsrLogMessageProcessor;
// Create logger object$logger = newLogger('sql');
// Push logger handler, use DEBUG level that we can log all information$logger->pushHandler(newStreamHandler('path/to/log/sql.log', Logger::DEBUG));
// Use PSR-3 logger processor that we can replace {sql} with context like array('sql' => 'XXX')$logger->pushProcessor(newPsrLogMessageProcessor);
// Push into DB$db->setLogger($logger);
$db->setDebug(true);
// Do something$db->setQuery('A WRONG QUERY')->execute();

This is the log file:

[2014-07-29 07:25:22] sql.DEBUG: A WRONG QUERY {"sql":"A WRONG QUERY","category":"databasequery","trace":[...]} []
[2014-07-29 07:36:01] sql.ERROR: Database query failed (error #42000): SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1 {"code":42000,"message":"SQL: 42000, 1064, You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A WRONG QUERY' at line 1"} []

Installation via Composer

Add "joomla/database": "~2.0" to the require block in your composer.json and then run composer install.

{
"require": {
"joomla/database": "~2.0"
}
}

Alternatively, you can simply run the following from the command line:

composer require joomla/database "~2.0"

If you want to include the test sources, use

composer require --prefer-source joomla/database "~2.0"

About

Joomla Framework Database Package

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages