fix unescaped parameter, see PMASA-2013-8 for details
[phpmyadmin.git] / browse_foreigners.php
blob9a9fdf904385e1220ff09b1d3de98bff526d9d85
1 <?php
2 /* vim: set expandtab sw=4 ts=4 sts=4: */
3 /**
4 * display selection for relational field values
6 * @package PhpMyAdmin
7 */
9 require_once 'libraries/common.inc.php';
10 require_once 'libraries/transformations.lib.php';
12 /**
13 * Sets globals from $_REQUEST
15 $request_params = array(
16 'field',
17 'fieldkey',
18 'foreign_filter',
19 'pos',
20 'rownumber'
23 foreach ($request_params as $one_request_param) {
24 if (isset($_REQUEST[$one_request_param])) {
25 $GLOBALS[$one_request_param] = $_REQUEST[$one_request_param];
29 PMA_Util::checkParameters(array('db', 'table', 'field'));
31 $response = PMA_Response::getInstance();
32 $response->getFooter()->setMinimal();
33 $header = $response->getHeader();
34 $header->disableMenu();
35 $header->setBodyId('body_browse_foreigners');
37 /**
38 * Displays the frame
41 $cfgRelation = PMA_getRelationsParam();
42 $foreigners = ($cfgRelation['relwork'] ? PMA_getForeigners($db, $table) : false);
44 $override_total = true;
46 if (! isset($pos)) {
47 $pos = 0;
50 $foreign_limit = 'LIMIT ' . $pos . ', ' . $GLOBALS['cfg']['MaxRows'] . ' ';
51 if (isset($foreign_navig) && $foreign_navig == __('Show all')) {
52 unset($foreign_limit);
55 $foreignData = PMA_getForeignData(
56 $foreigners, $field, $override_total,
57 isset($foreign_filter) ? $foreign_filter : '', $foreign_limit
60 if (isset($rownumber)) {
61 $rownumber_param = '&amp;rownumber=' . urlencode($rownumber);
62 } else {
63 $rownumber_param = '';
66 $gotopage = '';
67 $showall = '';
69 if (is_array($foreignData['disp_row'])) {
71 if ($cfg['ShowAll']
72 && ($foreignData['the_total'] > $GLOBALS['cfg']['MaxRows'])
73 ) {
74 $showall = '<input type="submit" name="foreign_navig" value="'
75 . __('Show all') . '" />';
78 $session_max_rows = $GLOBALS['cfg']['MaxRows'];
79 $pageNow = @floor($pos / $session_max_rows) + 1;
80 $nbTotalPage = @ceil($foreignData['the_total'] / $session_max_rows);
82 if ($foreignData['the_total'] > $GLOBALS['cfg']['MaxRows']) {
83 $gotopage = PMA_Util::pageselector(
84 'pos',
85 $session_max_rows,
86 $pageNow,
87 $nbTotalPage,
88 200,
91 20,
92 10,
93 __('Page number:')
100 if (isset($rownumber)) {
101 $element_name = " var element_name = field + '[multi_edit]["
102 . htmlspecialchars($rownumber) . "][' + fieldmd5 + ']';\n"
103 . " var null_name = field_null + '[multi_edit]["
104 . htmlspecialchars($rownumber) . "][' + fieldmd5 + ']';\n";
105 } else {
106 $element_name = "var element_name = field + '[]'";
108 $error = PMA_jsFormat(
110 'The target browser window could not be updated. '
111 . 'Maybe you have closed the parent window, or '
112 . 'your browser\'s security settings are '
113 . 'configured to block cross-window updates.'
118 if (! isset($fieldkey) || ! is_numeric($fieldkey)) {
119 $fieldkey = 0;
122 $code = <<<EOC
123 self.focus();
124 function formupdate(fieldmd5, key) {
125 var \$inline = window.opener.jQuery('.browse_foreign_clicked');
126 if (\$inline.length != 0) {
127 \$inline.removeClass('browse_foreign_clicked')
128 // for grid editing,
129 // puts new value in the previous element which is
130 // a span with class curr_value, and trigger .change()
131 .prev('.curr_value').text(key).change();
132 // for zoom-search editing, puts new value in the previous
133 // element which is an input field
134 \$inline.prev('input[type=text]').val(key);
135 self.close();
136 return false;
139 if (opener && opener.document && opener.document.insertForm) {
140 var field = 'fields';
141 var field_null = 'fields_null';
143 $element_name
145 var element_name_alt = field + '[$fieldkey]';
147 if (opener.document.insertForm.elements[element_name]) {
148 // Edit/Insert form
149 opener.document.insertForm.elements[element_name].value = key;
150 if (opener.document.insertForm.elements[null_name]) {
151 opener.document.insertForm.elements[null_name].checked = false;
153 self.close();
154 return false;
155 } else if (opener.document.insertForm.elements[element_name_alt]) {
156 // Search form
157 opener.document.insertForm.elements[element_name_alt].value = key;
158 self.close();
159 return false;
163 alert('$error');
165 EOC;
167 $header->getScripts()->addCode($code);
169 // HTML output
170 $output = '<form action="browse_foreigners.php" method="post">'
171 . '<fieldset>'
172 . PMA_generate_common_hidden_inputs($db, $table)
173 . '<input type="hidden" name="field" value="' . htmlspecialchars($field) . '" />'
174 . '<input type="hidden" name="fieldkey" value="'
175 . (isset($fieldkey) ? htmlspecialchars($fieldkey) : '') . '" />';
177 if (isset($rownumber)) {
178 $output .= '<input type="hidden" name="rownumber" value="'
179 . htmlspecialchars($rownumber) . '" />';
181 $output .= '<span class="formelement">'
182 . '<label for="input_foreign_filter">' . __('Search') . ':' . '</label>'
183 . '<input type="text" name="foreign_filter" id="input_foreign_filter" value="'
184 . (isset($foreign_filter) ? htmlspecialchars($foreign_filter) : '') . '" />'
185 . '<input type="submit" name="submit_foreign_filter" value="'
186 . __('Go') . '" />'
187 . '</span>'
188 . '<span class="formelement">' . $gotopage . '</span>'
189 . '<span class="formelement">' . $showall . '</span>'
190 . '</fieldset>'
191 . '</form>';
193 $output .= '<table width="100%">';
195 if (is_array($foreignData['disp_row'])) {
196 $header = '<tr>
197 <th>' . __('Keyname') . '</th>
198 <th>' . __('Description') . '</th>
199 <td width="20%"></td>
200 <th>' . __('Description') . '</th>
201 <th>' . __('Keyname') . '</th>
202 </tr>';
204 $output .= '<thead>' . $header . '</thead>' . "\n"
205 . '<tfoot>' . $header . '</tfoot>' . "\n"
206 . '<tbody>' . "\n";
208 $values = array();
209 $keys = array();
210 foreach ($foreignData['disp_row'] as $relrow) {
211 if ($foreignData['foreign_display'] != false) {
212 $values[] = $relrow[$foreignData['foreign_display']];
213 } else {
214 $values[] = '';
217 $keys[] = $relrow[$foreignData['foreign_field']];
220 asort($keys);
222 $hcount = 0;
223 $odd_row = true;
224 $val_ordered_current_row = 0;
225 $val_ordered_current_equals_data = false;
226 $key_ordered_current_equals_data = false;
227 foreach ($keys as $key_ordered_current_row => $value) {
228 $hcount++;
230 if ($cfg['RepeatCells'] > 0 && $hcount > $cfg['RepeatCells']) {
231 $output .= $header;
232 $hcount = 0;
233 $odd_row = true;
236 $key_ordered_current_key = $keys[$key_ordered_current_row];
237 $key_ordered_current_val = $values[$key_ordered_current_row];
239 $val_ordered_current_key = $keys[$val_ordered_current_row];
240 $val_ordered_current_val = $values[$val_ordered_current_row];
242 $val_ordered_current_row++;
244 if (PMA_strlen($val_ordered_current_val) <= $cfg['LimitChars']) {
245 $val_ordered_current_val = htmlspecialchars(
246 $val_ordered_current_val
248 $val_ordered_current_val_title = '';
249 } else {
250 $val_ordered_current_val_title = htmlspecialchars(
251 $val_ordered_current_val
253 $val_ordered_current_val = htmlspecialchars(
254 PMA_substr($val_ordered_current_val, 0, $cfg['LimitChars'])
255 . '...'
258 if (PMA_strlen($key_ordered_current_val) <= $cfg['LimitChars']) {
259 $key_ordered_current_val = htmlspecialchars(
260 $key_ordered_current_val
262 $key_ordered_current_val_title = '';
263 } else {
264 $key_ordered_current_val_title = htmlspecialchars(
265 $key_ordered_current_val
267 $key_ordered_current_val = htmlspecialchars(
268 PMA_substr(
269 $key_ordered_current_val, 0, $cfg['LimitChars']
270 ) . '...'
274 if (! empty($data)) {
275 $val_ordered_current_equals_data = $val_ordered_current_key == $data;
276 $key_ordered_current_equals_data = $key_ordered_current_key == $data;
279 $output .= '<tr class="noclick ' . ($odd_row ? 'odd' : 'even') . '">';
280 $odd_row = ! $odd_row;
282 $output .= '<td class="nowrap">'
283 . ($key_ordered_current_equals_data ? '<strong>' : '')
284 . '<a href="#" title="' . __('Use this value')
285 . ($key_ordered_current_val_title != ''
286 ? ': ' . $key_ordered_current_val_title
287 : '') . '"'
288 . ' onclick="formupdate(\'' . md5($field) . '\', \''
289 . PMA_jsFormat($key_ordered_current_key, false) . '\'); return false;">'
290 . htmlspecialchars($key_ordered_current_key)
291 . '</a>' . ($key_ordered_current_equals_data ? '</strong>' : '')
292 . '</td>';
294 $output .= '<td>'
295 . ($key_ordered_current_equals_data ? '<strong>' : '')
296 . '<a href="#" title="' . __('Use this value')
297 . ($key_ordered_current_val_title != '' ? ': '
298 . $key_ordered_current_val_title : '') . '" onclick="formupdate(\''
299 . md5($field) . '\', \''
300 . PMA_jsFormat($key_ordered_current_key, false)
301 . '\'); return false;">'
302 . $key_ordered_current_val . '</a>'
303 . ($key_ordered_current_equals_data ? '</strong>' : '')
304 . '</td>';
306 $output .= '<td width="20%">'
307 . '<img src="' . $GLOBALS['pmaThemeImage'] . 'spacer.png" alt=""'
308 . ' width="1" height="1" /></td>';
310 $output .= '<td>'
311 . ($val_ordered_current_equals_data ? '<strong>' : '')
312 . '<a href="#" title="' . __('Use this value')
313 . ($val_ordered_current_val_title != '' ? ': '
314 . $val_ordered_current_val_title : '') . '" onclick="formupdate(\''
315 . md5($field) . '\', \''
316 . PMA_jsFormat($val_ordered_current_key, false)
317 . '\'); return false;">'
318 . $val_ordered_current_val . '</a>'
319 . ($val_ordered_current_equals_data ? '</strong>' : '')
320 . '</td>';
322 $output .= '<td class="nowrap">'
323 . ($val_ordered_current_equals_data ? '<strong>' : '')
324 . '<a href="#" title="' . __('Use this value')
325 . ($val_ordered_current_val_title != ''
326 ? ': ' . $val_ordered_current_val_title : '')
327 . '" onclick="formupdate(\'' . md5($field) . '\', \''
328 . PMA_jsFormat($val_ordered_current_key, false) . '\'); return false;">'
329 . htmlspecialchars($val_ordered_current_key)
330 . '</a>' . ($val_ordered_current_equals_data ? '</strong>' : '')
331 . '</td>';
332 $output .= '</tr>';
333 } // end while
336 $output .= '</tbody>'
337 . '</table>';
339 $response->addHtml($output);