The SQL query that was being generated was messed up. I've attempted to refactor the way the query gets generated. Not 100% certain this is the best way to go about it

This commit is contained in:
David Bell
2016-03-08 14:56:25 +00:00
parent 03b8cc0c1b
commit f381adad45

View File

@@ -1,28 +1,28 @@
<?php <?php
$where = '1'; $where = '';
if (!empty($_POST['searchPhrase'])) { if (!empty($_POST['searchPhrase'])) {
$where .= ' AND S.msg LIKE "%'.mres($_POST['searchPhrase']).'%"'; $where .= 'S.msg LIKE "%'.mres($_POST['searchPhrase']).'%" AND ';
} }
if ($_POST['program']) { if ($_POST['program']) {
$where .= ' AND S.program = ?'; $where .= 'S.program = ? AND ';
$param[] = $_POST['program']; $param[] = $_POST['program'];
} }
if (is_numeric($_POST['device'])) { if (is_numeric($_POST['device'])) {
$where .= ' AND S.device_id = ?'; $where .= ' S.device_id = ? AND ';
$param[] = $_POST['device']; $param[] = $_POST['device'];
} }
if (!empty($_POST['from'])) { if (!empty($_POST['from'])) {
$where .= ' AND timestamp >= ?'; $where .= 'timestamp >= ? AND ';
$param[] = $_POST['from']; $param[] = $_POST['from'];
} }
if (!empty($_POST['to'])) { if (!empty($_POST['to'])) {
$where .= ' AND timestamp <= ?'; $where .= 'timestamp <= ? AND ';
$param[] = $_POST['to']; $param[] = $_POST['to'];
} }
@@ -31,9 +31,9 @@ if ($_SESSION['userlevel'] >= '5') {
$sql .= ' WHERE '.$where; $sql .= ' WHERE '.$where;
} }
else { else {
$sql = 'FROM syslog AS S, devices_perms AS P'; $sql = 'FROM syslog AS S, devices_perms AS P ';
$sql .= 'WHERE S.device_id = P.device_id AND P.user_id = ?'; $sql .= 'WHERE S.device_id = P.device_id AND P.user_id = ? AND ';
$sql .= $where; $sql .= $where . "1";
$param = array_merge(array($_SESSION['user_id']), $param); $param = array_merge(array($_SESSION['user_id']), $param);
} }
@@ -60,6 +60,7 @@ if ($rowCount != -1) {
$sql = "SELECT S.*, DATE_FORMAT(timestamp, '".$config['dateformat']['mysql']['compact']."') AS date $sql"; $sql = "SELECT S.*, DATE_FORMAT(timestamp, '".$config['dateformat']['mysql']['compact']."') AS date $sql";
foreach (dbFetchRows($sql, $param) as $syslog) { foreach (dbFetchRows($sql, $param) as $syslog) {
$dev = device_by_id_cache($syslog['device_id']); $dev = device_by_id_cache($syslog['device_id']);
$response[] = array( $response[] = array(