sql_helper.rb 5.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227
  1. # Copyright (C) 2012-2023 Zammad Foundation, https://zammad-foundation.org/
  2. class SqlHelper
  3. def self.quote_string(value)
  4. ActiveRecord::Base.connection.quote_string(value)
  5. end
  6. def self.quote_like(...)
  7. ApplicationModel.sanitize_sql_like(...)
  8. end
  9. def initialize(object:, table_name: nil)
  10. @object = object
  11. @table_name = table_name
  12. end
  13. def db_column(column)
  14. "#{ActiveRecord::Base.connection.quote_table_name(@table_name || @object.table_name)}.#{ActiveRecord::Base.connection.quote_column_name(column)}"
  15. end
  16. def get_param_key(key, params)
  17. sort_by = []
  18. if params[key].present? && params[key].is_a?(String)
  19. params[key] = params[key].split(%r{\s*,\s*})
  20. elsif params[key].blank?
  21. params[key] = []
  22. end
  23. sort_by
  24. end
  25. =begin
  26. This function will check the params for the "sort_by" attribute
  27. and validate its values.
  28. sql_helper = SqlHelper.new(object: Ticket)
  29. sort_by = sql_helper.get_sort_by(params, default)
  30. returns
  31. sort_by = [
  32. 'created_at',
  33. 'updated_at',
  34. ]
  35. =end
  36. def get_sort_by(params, default = nil)
  37. sort_by = get_param_key(:sort_by, params)
  38. # check order
  39. params[:sort_by].each do |value|
  40. # only accept values which are set for the db schema
  41. raise "Found invalid column '#{value}' for sorting." if @object.columns_hash[value].blank?
  42. sort_by.push(value)
  43. end
  44. if sort_by.blank? && default.present?
  45. if default.is_a?(Array)
  46. sort_by = default
  47. else
  48. sort_by.push(default)
  49. end
  50. end
  51. sort_by
  52. end
  53. =begin
  54. This function will check the params for the "order_by" attribute
  55. and validate its values.
  56. sql_helper = SqlHelper.new(object: Ticket)
  57. order_by = sql_helper.get_order_by(params, default)
  58. returns
  59. order_by = [
  60. 'asc',
  61. 'desc',
  62. ]
  63. =end
  64. def get_order_by(params, default = nil)
  65. order_by = get_param_key(:order_by, params)
  66. # check order
  67. params[:order_by].each do |value|
  68. raise "Found invalid order by value #{value}. Please use 'asc' or 'desc'." if !value.match?(%r{\A(asc|desc)\z}i)
  69. order_by.push(value.downcase)
  70. end
  71. if order_by.blank? && default.present?
  72. if default.is_a?(Array)
  73. order_by = default
  74. else
  75. order_by.push(default)
  76. end
  77. end
  78. order_by
  79. end
  80. def set_sql_order_default(sql, default)
  81. if sql.blank? && default.present?
  82. sql.push(db_column(default))
  83. end
  84. sql
  85. end
  86. =begin
  87. This function will use the evaluated values for sort_by and
  88. order_by to generate the ORDER-SELECT sql statement for the sorting
  89. of the result.
  90. sort_by = [ 'created_at', 'updated_at' ]
  91. order_by = [ 'asc', 'desc' ]
  92. default = 'tickets.created_at'
  93. sql_helper = SqlHelper.new(object: Ticket)
  94. sql = sql_helper.get_order_select(sort_by, order_by, default)
  95. returns
  96. sql = 'tickets.created_at, tickets.updated_at'
  97. =end
  98. def get_order_select(sort_by, order_by, default = nil)
  99. sql = []
  100. sort_by.each_with_index do |value, index|
  101. next if value.blank?
  102. next if order_by[index].blank?
  103. sql.push(db_column(value))
  104. end
  105. sql = set_sql_order_default(sql, default)
  106. sql.join(', ')
  107. end
  108. =begin
  109. This function will use the evaluated values for sort_by and
  110. order_by to generate the ORDER- sql statement for the sorting
  111. of the result.
  112. sort_by = [ 'created_at', 'updated_at' ]
  113. order_by = [ 'asc', 'desc' ]
  114. default = 'tickets.created_at DESC'
  115. sql_helper = SqlHelper.new(object: Ticket)
  116. sql = sql_helper.get_order(sort_by, order_by, default)
  117. returns
  118. sql = 'tickets.created_at ASC, tickets.updated_at DESC'
  119. =end
  120. def get_order(sort_by, order_by, default = nil)
  121. sql = []
  122. sort_by.each_with_index do |value, index|
  123. next if value.blank?
  124. next if order_by[index].blank?
  125. sql.push("#{db_column(value)} #{order_by[index]}")
  126. end
  127. sql = set_sql_order_default(sql, default)
  128. sql.join(', ')
  129. end
  130. def containable?(attribute)
  131. ObjectManager::Attribute.for_object(@object).exists?(name: attribute, data_type: %w[multiselect multi_tree_select])
  132. end
  133. def array_contains_all(attribute, value, negated: false)
  134. value = [''] if value.blank?
  135. value = Array(value)
  136. result = if Rails.application.config.db_column_array
  137. "(#{db_column(attribute)} @> ARRAY[#{value.map { |v| "'#{self.class.quote_string(v)}'" }.join(',')}]::varchar[])"
  138. else
  139. "JSON_CONTAINS(#{db_column(attribute)}, '#{self.class.quote_string(value.to_json)}', '$')"
  140. end
  141. negated ? "NOT(#{result})" : "(#{result})"
  142. end
  143. def array_contains_one(attribute, value, negated: false)
  144. value = [''] if value.blank?
  145. value = Array(value)
  146. result = if Rails.application.config.db_column_array
  147. "(#{db_column(attribute)} && ARRAY[#{value.map { |v| "'#{self.class.quote_string(v)}'" }.join(',')}]::varchar[])"
  148. else
  149. value.map { |v| "JSON_CONTAINS(#{db_column(attribute)}, '#{self.class.quote_string(v.to_json)}', '$')" }.join(' OR ')
  150. end
  151. negated ? "NOT(#{result})" : "(#{result})"
  152. end
  153. def regex_match(attribute, negated: false)
  154. operator = if mysql?
  155. negated ? 'NOT REGEXP' : 'REGEXP'
  156. else
  157. negated ? '!~*' : '~*'
  158. end
  159. "#{attribute} #{operator} (?)"
  160. end
  161. private
  162. def mysql?
  163. ActiveRecord::Base.connection_db_config.configuration_hash[:adapter] == 'mysql2'
  164. end
  165. end