You are here

public function FrxPDO::format in Forena Reports 6.2

Same name and namespace in other branches
  1. 6 plugins/FrxPDO.inc \FrxPDO::format()
  2. 7 plugins/FrxPDO.inc \FrxPDO::format()
  3. 7.2 plugins/FrxPDO.inc \FrxPDO::format()
  4. 7.3 plugins/FrxPDO.inc \FrxPDO::format()
  5. 7.4 plugins/FrxPDO.inc \FrxPDO::format()

Implement custom SQL formatter to make sure that strings are properly escaped. Ideally we'd replace this with something that handles prepared statements, but it wouldn't work for

Parameters

unknown_type $value:

unknown_type $key:

unknown_type $data:

File

plugins/FrxPDO.inc, line 143
General database engine used to do sql queries.

Class

FrxPDO
@file General database engine used to do sql queries.

Code

public function format($value, $key, $data) {
  $db = $this->db;
  if ($db) {
    if ($value === '' || $value === NULL || $value === array()) {
      $value = 'NULL';
    }
    elseif (is_array($value)) {
      if ($value == array()) {
        $value = 'NULL';
      }
      else {

        // Build a array of values string
        $i = 0;
        $val = '';
        foreach ($value as $v) {
          $i++;
          if ($i != 1) {
            $val .= ',';
          }
          $val .= $this
            ->quote($v);
        }
        $value = $val;
      }
    }
    else {
      $value = $this
        ->quote($value);
    }
  }
  return (string) $value;
}