Issues (138)

Security Analysis    not enabled

This project does not seem to handle request data directly as such no vulnerable execution paths were found.

  Cross-Site Scripting
Cross-Site Scripting enables an attacker to inject code into the response of a web-request that is viewed by other users. It can for example be used to bypass access controls, or even to take over other users' accounts.
  File Exposure
File Exposure allows an attacker to gain access to local files that he should not be able to access. These files can for example include database credentials, or other configuration files.
  File Manipulation
File Manipulation enables an attacker to write custom data to files. This potentially leads to injection of arbitrary code on the server.
  Object Injection
Object Injection enables an attacker to inject an object into PHP code, and can lead to arbitrary code execution, file exposure, or file manipulation attacks.
  Code Injection
Code Injection enables an attacker to execute arbitrary code on the server.
  Response Splitting
Response Splitting can be used to send arbitrary responses.
  File Inclusion
File Inclusion enables an attacker to inject custom files into PHP's file loading mechanism, either explicitly passed to include, or for example via PHP's auto-loading mechanism.
  Command Injection
Command Injection enables an attacker to inject a shell command that is execute with the privileges of the web-server. This can be used to expose sensitive data, or gain access of your server.
  SQL Injection
SQL Injection enables an attacker to execute arbitrary SQL code on your database server gaining access to user data, or manipulating user data.
  XPath Injection
XPath Injection enables an attacker to modify the parts of XML document that are read. If that XML document is for example used for authentication, this can lead to further vulnerabilities similar to SQL Injection.
  LDAP Injection
LDAP Injection enables an attacker to inject LDAP statements potentially granting permission to run unauthorized queries, or modify content inside the LDAP tree.
  Header Injection
  Other Vulnerability
This category comprises other attack vectors such as manipulating the PHP runtime, loading custom extensions, freezing the runtime, or similar.
  Regex Injection
Regex Injection enables an attacker to execute arbitrary code in your PHP process.
  XML Injection
XML Injection enables an attacker to read files on your local filesystem including configuration files, or can be abused to freeze your web-server process.
  Variable Injection
Variable Injection enables an attacker to overwrite program variables with custom data, and can lead to further vulnerabilities.
Unfortunately, the security analysis is currently not available for your project. If you are a non-commercial open-source project, please contact support to gain access.

code/control/PageRaterExtension_Controller.php (38 issues)

Upgrade to new PHP Analysis Engine

These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more

1
<?php
2
3
4
5
class PageRaterExtension_Controller extends Extension
0 ignored issues
show
Coding Style Compatibility introduced by
PSR1 recommends that each class must be in a namespace of at least one level to avoid collisions.

You can fix this by adding a namespace to your class:

namespace YourVendor;

class YourClass { }

When choosing a vendor namespace, try to pick something that is not too generic to avoid conflicts with other libraries.

Loading history...
6
{
7
8
9
    /**
10
     * add the default rating to each page ...
11
     * @var boolean
12
     */
13
    private static $items_per_page = 8;
0 ignored issues
show
The property $items_per_page is not used and could be removed.

This check marks private properties in classes that are never used. Those properties can be removed.

Loading history...
14
15
    /**
16
     * @var string
17
     */
18
    private static $field_title = "Click on any star to rate:";
0 ignored issues
show
The property $field_title is not used and could be removed.

This check marks private properties in classes that are never used. Those properties can be removed.

Loading history...
19
20
    /**
21
     * @var string
22
     */
23
    private static $field_right_title = "On a scale from 1 to 5, with 5 being the best";
0 ignored issues
show
The property $field_right_title is not used and could be removed.

This check marks private properties in classes that are never used. Those properties can be removed.

Loading history...
24
25
    /**
26
     * @var boolean
27
     */
28
    private static $show_average_rating_in_rating_field = false;
0 ignored issues
show
The property $show_average_rating_in_rating_field is not used and could be removed.

This check marks private properties in classes that are never used. Those properties can be removed.

Loading history...
29
30
    /**
31
     * @var boolean
32
     */
33
    private static $only_show_approved = false;
0 ignored issues
show
The property $only_show_approved is not used and could be removed.

This check marks private properties in classes that are never used. Those properties can be removed.

Loading history...
34
35
    private static $allowed_actions = array(
0 ignored issues
show
Comprehensibility introduced by
Consider using a different property name as you override a private property of the parent class.
Loading history...
The property $allowed_actions is not used and could be removed.

This check marks private properties in classes that are never used. Those properties can be removed.

Loading history...
36
        "PageRatingForm",
37
        "rateagain",
38
        "dopagerating",
39
        "removedefaultpageratings",
40
        "removeallpageratings"
41
    );
42
43
    /**
44
     * action to allow use to rate again...
45
     */
46
    public function rateagain($request)
0 ignored issues
show
The return type could not be reliably inferred; please add a @return annotation.

Our type inference engine in quite powerful, but sometimes the code does not provide enough clues to go by. In these cases we request you to add a @return annotation as described here.

Loading history...
The parameter $request is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
47
    {
48
        $id = intval(Session::get('PageRated'.$this->owner->dataRecord->ID))-0;
0 ignored issues
show
The property dataRecord does not seem to exist in SS_Object.

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
49
        $pageRating = PageRating::get()->byID($id);
50
        if ($pageRating) {
51
            $pageRating->delete();
52
        }
53
        Session::set('PageRated'.$this->owner->dataRecord->ID, false);
0 ignored issues
show
false is of type boolean, but the function expects a string.

It seems like the type of the argument is not accepted by the function/method which you are calling.

In some cases, in particular if PHP’s automatic type-juggling kicks in this might be fine. In other cases, however this might be a bug.

We suggest to add an explicit type cast like in the following example:

function acceptsInteger($int) { }

$x = '123'; // string "123"

// Instead of
acceptsInteger($x);

// we recommend to use
acceptsInteger((integer) $x);
Loading history...
54
        Session::clear('PageRated'.$this->owner->dataRecord->ID);
55
        return $this->owner->redirect($this->owner->Link());
56
    }
57
58
    /**
59
     * @return Form
60
     */
61
    public function PageRatingForm()
62
    {
63
        Requirements::themedCSS('PageRater', "pagerater");
64
        if ($this->owner->PageHasBeenRatedByUser()) {
65
            $ratingField = LiteralField::create("RatingFor".$this->owner->dataRecord->ID, $this->owner->renderWith("PageRaterAjaxReturn"));
0 ignored issues
show
The property dataRecord does not seem to exist in SS_Object.

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
66
            $actions = FieldList::create();
67
            $requiredFields = null;
68
        } else {
69
            if (Config::inst()->get("PageRaterExtension_Controller", "show_average_rating_in_rating_field")) {
70
                $defaultStart = $this->owner->getStarRating();
71
            } else {
72
                $defaultStart = 0;
73
            }
74
            $ratingField = PageRaterStarField::create(
75
                'RatingFor'.$this->owner->dataRecord->ID,
76
                Config::inst()->get("PageRaterExtension_Controller", "field_title"),
77
                $defaultStart,
78
                PageRating::get_number_of_stars()
79
            );
80
            $ratingField->setRightTitle(Config::inst()->get("PageRaterExtension_Controller", "field_right_title"));
81
            $requiredFields = RequiredFields::create($ratingField->getRequiredFields());
82
            $actions = FieldList::create(FormAction::create('dopagerating', 'Submit'));
83
        }
84
        $fields = FieldList::create(
85
            $ratingField,
86
            HiddenField::create('ParentID', "ParentID", $this->owner->dataRecord->ID)
87
        );
88
89
        return Form::create($this->owner, 'PageRatingForm', $fields, $actions, $requiredFields);
90
    }
91
92
    /**
93
     * action Page Rating Form
94
     */
95
    public function dopagerating($data, $form)
0 ignored issues
show
The return type could not be reliably inferred; please add a @return annotation.

Our type inference engine in quite powerful, but sometimes the code does not provide enough clues to go by. In these cases we request you to add a @return annotation as described here.

Loading history...
96
    {
97
        $id = $this->owner->dataRecord->ID;
0 ignored issues
show
The property dataRecord does not seem to exist in SS_Object.

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
98
        $fieldName = "RatingFor".$id;
99
        $data = Convert::raw2sql($data);
100
        $pageRating = PageRating::create();
101
        $form->saveInto($pageRating);
102
        $pageRating->ParentID = $this->owner->dataRecord->ID;
0 ignored issues
show
The property ParentID does not exist on object<PageRating>. Since you implemented __set, maybe consider adding a @property annotation.

Since your code implements the magic setter _set, this function will be called for any write access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

Since the property has write access only, you can use the @property-write annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
103
        if (isset($data[$fieldName])) {
104
            $pageRating->Rating = floatval($data[$fieldName]);
0 ignored issues
show
The property Rating does not seem to exist. Did you mean round_rating?

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
105
        }
106
        if (isset($data[$fieldName."_Comment"])) {
107
            $pageRating->Comment = Convert::raw2sql($data[$fieldName."_Comment"]);
0 ignored issues
show
The property Comment does not exist on object<PageRating>. Since you implemented __set, maybe consider adding a @property annotation.

Since your code implements the magic setter _set, this function will be called for any write access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

Since the property has write access only, you can use the @property-write annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
108
        }
109
        if (isset($data[$fieldName."_Name"])) {
110
            $pageRating->Name = Convert::raw2sql($data[$fieldName."_Name"]);
0 ignored issues
show
The property Name does not exist on object<PageRating>. Since you implemented __set, maybe consider adding a @property annotation.

Since your code implements the magic setter _set, this function will be called for any write access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

Since the property has write access only, you can use the @property-write annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
111
        }
112
        if (isset($data[$fieldName."_Title"])) {
113
            $pageRating->Title = Convert::raw2sql($data[$fieldName."_Title"]);
0 ignored issues
show
The property Title does not exist on object<PageRating>. Since you implemented __set, maybe consider adding a @property annotation.

Since your code implements the magic setter _set, this function will be called for any write access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

Since the property has write access only, you can use the @property-write annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
114
        }
115
        $pageRating->write();
116
        Session::set('PageRated'.$this->owner->dataRecord->ID, $pageRating->ID);
117
        if (Director::is_ajax()) {
118
            return $this->owner->renderWith("PageRaterAjaxReturn");
119
        } else {
120
            $this->owner->redirectBack();
121
        }
122
    }
123
124
125
    public function removedefaultpageratings()
126
    {
127
        if (Permission::check("ADMIN")) {
128
            DB::query("DELETE FROM PageRating WHERE IsDefault = 1;");
129
            debug::show("removed all default ratings for all pages");
130
        } else {
131
            Security::permissionFailure($this->owner, _t('Security.PERMFAILURE', ' This page is secured and you need administrator rights to access it. Enter your credentials below and we will send you right along.'));
0 ignored issues
show
$this->owner is of type object<SS_Object>, but the function expects a object<Controller>|null.

It seems like the type of the argument is not accepted by the function/method which you are calling.

In some cases, in particular if PHP’s automatic type-juggling kicks in this might be fine. In other cases, however this might be a bug.

We suggest to add an explicit type cast like in the following example:

function acceptsInteger($int) { }

$x = '123'; // string "123"

// Instead of
acceptsInteger($x);

// we recommend to use
acceptsInteger((integer) $x);
Loading history...
132
        }
133
    }
134
135
    public function removeallpageratings()
136
    {
137
        if (Permission::check("ADMIN")) {
138
            DB::query("DELETE FROM PageRating;");
139
            debug::show("removed all ratings for all pages");
140
        } else {
141
            Security::permissionFailure($this->owner, _t('Security.PERMFAILURE', ' This page is secured and you need administrator rights to access it. Enter your credentials below and we will send you right along.'));
0 ignored issues
show
$this->owner is of type object<SS_Object>, but the function expects a object<Controller>|null.

It seems like the type of the argument is not accepted by the function/method which you are calling.

In some cases, in particular if PHP’s automatic type-juggling kicks in this might be fine. In other cases, however this might be a bug.

We suggest to add an explicit type cast like in the following example:

function acceptsInteger($int) { }

$x = '123'; // string "123"

// Instead of
acceptsInteger($x);

// we recommend to use
acceptsInteger((integer) $x);
Loading history...
142
        }
143
    }
144
145
146
147
148
149
    /**
150
     * rating for this page ...
151
     * @return ArrayList
152
     */
153 View Code Duplication
    public function PageRatingResults()
0 ignored issues
show
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
154
    {
155
        $sqlQuery = new SQLQuery();
0 ignored issues
show
Deprecated Code introduced by
The class SQLQuery has been deprecated with message: since version 4.0

This class, trait or interface has been deprecated. The supplier of the file has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the type will be removed from the class and what other constant to use instead.

Loading history...
156
        $sqlQuery->setSelect("AVG(\"PageRating\".\"Rating\") RatingAverage, ParentID");
157
        $sqlQuery->setFrom("\"PageRating\" ");
158
        if ($this->onlyShowApprovedPageRatings()) {
159
            $sqlQuery->setWhere("\"ParentID\" = ".$this->owner->ID." AND \"PageRating\".\"IsApproved\" = 1");
0 ignored issues
show
The property ID does not seem to exist in SS_Object.

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
160
        } else {
161
            $sqlQuery->setWhere("\"ParentID\" = ".$this->owner->ID."");
162
        }
163
        $sqlQuery->setOrderBy("RatingAverage DESC");
164
        $sqlQuery->setGroupby("\"ParentID\"");
165
        $sqlQuery->setLimit(1);
166
        return $this->turnPageRaterSQLIntoArrayList($sqlQuery, "PageRatingResults");
167
    }
168
169
    /**
170
     * rating of this page by this user ...
171
     * @return ArrayList
172
     */
173 View Code Duplication
    public function CurrentUserRating()
0 ignored issues
show
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
174
    {
175
        $sqlQuery = new SQLQuery();
0 ignored issues
show
Deprecated Code introduced by
The class SQLQuery has been deprecated with message: since version 4.0

This class, trait or interface has been deprecated. The supplier of the file has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the type will be removed from the class and what other constant to use instead.

Loading history...
176
        $sqlQuery->setSelect("AVG(\"PageRating\".\"Rating\") RatingAverage, ParentID");
177
        $sqlQuery->setFrom("\"PageRating\" ");
178
        if ($this->onlyShowApprovedPageRatings()) {
179
            $sqlQuery->setWhere("\"ParentID\" = ".$this->owner->ID." AND \"PageRating\".\"ID\" = '".Session::get('PageRated'.$this->owner->ID)."' AND \"PageRating\".\"IsApproved\" = 1");
0 ignored issues
show
The property ID does not seem to exist in SS_Object.

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
180
        } else {
181
            $sqlQuery->setWhere("\"ParentID\" = ".$this->owner->ID." AND \"PageRating\".\"ID\" = '".Session::get('PageRated'.$this->owner->ID)."'");
182
        }
183
184
        $sqlQuery->setOrderBy("RatingAverage DESC");
185
        $sqlQuery->setGroupby("\"ParentID\"");
186
        $sqlQuery->setLimit(1);
187
        return $this->turnPageRaterSQLIntoArrayList($sqlQuery, "CurrentUserRating");
188
    }
189
190
    /**
191
     * list of all rated pages ...
192
     * @return ArrayList
193
     */
194
    public function PageRaterListOfAllForPage($paginated = false)
195
    {
196
        if ($this->owner->onlyShowApprovedPageRatings()) {
197
            $list = $this->owner->turnPageRaterSQLIntoArrayList(
198
                $this->owner->PageRatings()->filter(array("IsApproved" => 1)),
199
                "PageRaterListOfAllForPage"
200
            );
201
        } else {
202
            $list = $this->owner->turnPageRaterSQLIntoArrayList(
203
                $this->owner->PageRatings(),
204
                "PageRaterListOfAllForPage"
205
            );
206
        }
207
        if ($paginated) {
208
            $limit = Config::inst()->get('PageRaterExtension_Controller', 'items_per_page');
209
            if ($limit) {
210
                $list = PaginatedList::create($list, $this->owner->getRequest());
211
                $list->setPageLength($limit);
212
            }
213
        }
214
        return $list;
215
    }
216
217
218
    public function PageRaterListAll()
219
    {
220
        $sqlQuery = new SQLQuery();
0 ignored issues
show
Deprecated Code introduced by
The class SQLQuery has been deprecated with message: since version 4.0

This class, trait or interface has been deprecated. The supplier of the file has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the type will be removed from the class and what other constant to use instead.

Loading history...
221
        $sqlQuery->setSelect("\"PageRating\".\"Rating\" AS RatingAverage, \"PageRating\".\"ParentID\"");
222
        if ($this->owner->onlyShowApprovedPageRatings()) {
223
            $sqlQuery->setWhere("\"PageRating\".\"IsApproved\" = 1");
224
        }
225
        $sqlQuery->setFrom(" \"PageRating\"");
226
        $sqlQuery->addInnerJoin("SiteTree", " \"PageRating\".\"ParentID\" = \"SiteTree\".\"ID\"");
227
        $sqlQuery->setOrderBy("RatingAverage DESC");
228
        $sqlQuery->setGroupby("\"SiteTree\".\"ParentID\"");
229
        return $this->turnPageRaterSQLIntoArrayList($sqlQuery, "PageRaterList");
230
    }
231
232
    /**
233
     * @param $data $sqlQuery | DataList
0 ignored issues
show
The doc-type $data could not be parsed: Unknown type name "$data" at position 0. (view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
There is no parameter named $sqlQuery. Was it maybe removed?

This check looks for PHPDoc comments describing methods or function parameters that do not exist on the corresponding method or function.

Consider the following example. The parameter $italy is not defined by the method finale(...).

/**
 * @param array $germany
 * @param array $island
 * @param array $italy
 */
function finale($germany, $island) {
    return "2:1";
}

The most likely cause is that the parameter was removed, but the annotation was not.

Loading history...
234
     * @param string $method
235
     *
236
     * @return ArrayList
237
     */
238 View Code Duplication
    protected function turnPageRaterSQLIntoArrayList($data, $method = "unknown")
0 ignored issues
show
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
239
    {
240
        if ($data instanceof SQLQuery) {
241
            $data = $data->execute();
242
        }
243
        $al = new ArrayList();
244
        if ($data) {
245
            foreach ($data as $record) {
246
                if ($record instanceof PageRating) {
247
                    $record->Method = $method;
0 ignored issues
show
The property Method does not seem to exist. Did you mean built_in_methods?

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
248
                } else {
249
                    $score = $record["RatingAverage"];
250
                    $parentID = $record["ParentID"];
251
                    $record = PageRating::get_star_details_as_array_data($score, $parentID, $method);
252
                }
253
                $al->push($record);
254
            }
255
        }
256
        return $al;
257
    }
258
259
    /**
260
     * @return boolean
261
     */
262
    public function PageHasBeenRatedByUser()
263
    {
264
        return Session::get('PageRated'.$this->owner->ID) ? true : false;
0 ignored issues
show
The property ID does not seem to exist in SS_Object.

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
265
    }
266
267
    /**
268
     *
269
     * @return int
270
     */
271 View Code Duplication
    public function NumberOfPageRatings()
0 ignored issues
show
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
272
    {
273
        $doSet = new ArrayList();
0 ignored issues
show
$doSet is not used, you could remove the assignment.

This check looks for variable assignements that are either overwritten by other assignments or where the variable is not used subsequently.

$myVar = 'Value';
$higher = false;

if (rand(1, 6) > 3) {
    $higher = true;
} else {
    $higher = false;
}

Both the $myVar assignment in line 1 and the $higher assignment in line 2 are dead. The first because $myVar is never used and the second because $higher is always overwritten for every possible time line.

Loading history...
274
        $sqlQuery = new SQLQuery();
0 ignored issues
show
Deprecated Code introduced by
The class SQLQuery has been deprecated with message: since version 4.0

This class, trait or interface has been deprecated. The supplier of the file has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the type will be removed from the class and what other constant to use instead.

Loading history...
275
        $sqlQuery->setSelect("COUNT(\"PageRating\".\"Rating\") RatingCount");
276
        $sqlQuery->setFrom("\"PageRating\" ");
277
        if ($this->onlyShowApprovedPageRatings()) {
278
            $sqlQuery->setWhere("\"ParentID\" = ".$this->owner->ID." AND \"PageRating\".\"IsApproved\" = 1");
0 ignored issues
show
The property ID does not seem to exist in SS_Object.

An attempt at access to an undefined property has been detected. This may either be a typographical error or the property has been renamed but there are still references to its old name.

If you really want to allow access to undefined properties, you can define magic methods to allow access. See the php core documentation on Overloading.

Loading history...
279
        } else {
280
            $sqlQuery->setWhere("\"ParentID\" = ".$this->owner->ID."");
281
        }
282
        $sqlQuery->setOrderBy("RatingCount ASC");
283
        $sqlQuery->setGroupBy("\"ParentID\"");
284
        $sqlQuery->setLimit(1);
285
        $data = $sqlQuery->execute();
286
        if ($data) {
287
            foreach ($data as $record) {
288
                return $record["RatingCount"];
289
            }
290
        }
291
        return 0;
292
    }
293
294
    protected function onlyShowApprovedPageRatings()
295
    {
296
        return Config::inst()->get("PageRaterExtension_Controller", "only_show_approved");
297
    }
298
299
300
    /**
301
     * return the average rating...
302
     * @return Double
303
     */
304
    public function getStarRating()
305
    {
306
        $ratings = $this->owner->PageRatingResults();
307
        $rating = 0;
308
        if ($ratings->Count() == 1) {
309
            foreach ($ratings as $ratingItem) {
310
                $rating = $ratingItem->Stars;
311
            }
312
        }
313
        return $rating;
314
    }
315
}
316