Make WordPress Core


Ignore:
Timestamp:
03/05/2009 11:47:02 PM (17 years ago)
Author:
ryan
Message:

Add typecasting to wpdb::insert() and update(). Props filosofo. fixes #7171

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-includes/wp-db.php

    r10721 r10724  
    700700         * @param string $table WARNING: not sanitized!
    701701         * @param array $data Should not already be SQL-escaped
     702         * @param array|string $format The format of the field values.
    702703         * @return mixed Results of $this->query()
    703704         */
    704         function insert($table, $data) {
    705                 $data = $this->_escape($data);
     705        function insert($table, $data, $format = '%s') {
     706                $format = (array) $format;
    706707                $fields = array_keys($data);
    707                 return $this->query("INSERT INTO $table (`" . implode('`,`',$fields) . "`) VALUES ('".implode("','",$data)."')");
     708                $formatted_fields = array();
     709                foreach ( $data as $field ) {
     710                        $form = ( $form = array_shift($format) ) ? $form : $formatted_fields[0];
     711                        $formatted_fields[] = $form;
     712                }
     713                $sql = "INSERT INTO $table (`" . implode( '`,`', $fields ) . "`) VALUES ('" . implode( "','", $formatted_fields ) . "')";
     714                return $this->query( $this->prepare( $sql, $data) );
    708715        }
    709716
     
    716723         * @param array $data Should not already be SQL-escaped
    717724         * @param array $where A named array of WHERE column => value relationships.  Multiple member pairs will be joined with ANDs.  WARNING: the column names are not currently sanitized!
     725         * @param array|string $format The format of the field values.
     726         * @param array|string $where_format The format of the where field values.
    718727         * @return mixed Results of $this->query()
    719728         */
    720         function update($table, $data, $where){
    721                 $data = $this->_escape($data);
     729        function update($table, $data, $where, $format = '%s', $where_format = '%s') {
     730                if ( !is_array( $where ) )
     731                        return false;
     732
     733                $formats = $format = (array) $format;
    722734                $bits = $wheres = array();
    723                 foreach ( (array) array_keys($data) as $k )
    724                         $bits[] = "`$k` = '$data[$k]'";
    725 
    726                 if ( is_array( $where ) )
    727                         foreach ( $where as $c => $v )
    728                                 $wheres[] = "$c = '" . $this->_escape( $v ) . "'";
    729                 else
    730                         return false;
    731 
    732                 return $this->query( "UPDATE $table SET " . implode( ', ', $bits ) . ' WHERE ' . implode( ' AND ', $wheres ) );
     735                foreach ( (array) array_keys($data) as $k ) {
     736                        $form = ( $form = array_shift($formats) ) ? $form : $format[0];
     737                        $bits[] = "`$k` = {$form}";
     738                }
     739
     740                $where_formats = $where_format = (array) $where_format;
     741                foreach ( $where as $c => $v ) {
     742                        $form = ( $form = array_shift($where_formats) ) ? $form : $where_format[0];
     743                        $wheres[] = "$c = {$form}";
     744                }
     745
     746                $sql = "UPDATE $table SET " . implode( ', ', $bits ) . ' WHERE ' . implode( ' AND ', $wheres );
     747                return $this->query( $this->prepare( $sql, array_merge(array_values($data), array_values($where))) );
    733748        }
    734749
Note: See TracChangeset for help on using the changeset viewer.