Completed
Branch master (62f6c6)
by
unknown
21:31
created

ApiQueryBlocks::execute()   F

Complexity

Conditions 40
Paths > 20000

Size

Total Lines 201
Code Lines 140

Duplication

Lines 7
Ratio 3.48 %

Importance

Changes 0
Metric Value
cc 40
eloc 140
nc 2066400
nop 0
dl 7
loc 201
rs 2
c 0
b 0
f 0

How to fix   Long Method    Complexity   

Long Method

Small methods make your code easier to understand, in particular if combined with a good name. Besides, if your method is small, finding a good name is usually much easier.

For example, if you find yourself adding comments to a method's body, this is usually a good sign to extract the commented part to a new method, and use the comment as a starting point when coming up with a good name for this new method.

Commonly applied refactorings include:

1
<?php
2
/**
3
 *
4
 *
5
 * Created on Sep 10, 2007
6
 *
7
 * Copyright © 2007 Roan Kattouw "<Firstname>.<Lastname>@gmail.com"
8
 *
9
 * This program is free software; you can redistribute it and/or modify
10
 * it under the terms of the GNU General Public License as published by
11
 * the Free Software Foundation; either version 2 of the License, or
12
 * (at your option) any later version.
13
 *
14
 * This program is distributed in the hope that it will be useful,
15
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17
 * GNU General Public License for more details.
18
 *
19
 * You should have received a copy of the GNU General Public License along
20
 * with this program; if not, write to the Free Software Foundation, Inc.,
21
 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
22
 * http://www.gnu.org/copyleft/gpl.html
23
 *
24
 * @file
25
 */
26
27
/**
28
 * Query module to enumerate all user blocks
29
 *
30
 * @ingroup API
31
 */
32
class ApiQueryBlocks extends ApiQueryBase {
33
34
	public function __construct( ApiQuery $query, $moduleName ) {
35
		parent::__construct( $query, $moduleName, 'bk' );
36
	}
37
38
	public function execute() {
39
		global $wgContLang;
40
41
		$db = $this->getDB();
42
		$params = $this->extractRequestParams();
43
		$this->requireMaxOneParameter( $params, 'users', 'ip' );
44
45
		$prop = array_flip( $params['prop'] );
46
		$fld_id = isset( $prop['id'] );
47
		$fld_user = isset( $prop['user'] );
48
		$fld_userid = isset( $prop['userid'] );
49
		$fld_by = isset( $prop['by'] );
50
		$fld_byid = isset( $prop['byid'] );
51
		$fld_timestamp = isset( $prop['timestamp'] );
52
		$fld_expiry = isset( $prop['expiry'] );
53
		$fld_reason = isset( $prop['reason'] );
54
		$fld_range = isset( $prop['range'] );
55
		$fld_flags = isset( $prop['flags'] );
56
57
		$result = $this->getResult();
58
59
		$this->addTables( 'ipblocks' );
60
		$this->addFields( [ 'ipb_auto', 'ipb_id', 'ipb_timestamp' ] );
61
62
		$this->addFieldsIf( [ 'ipb_address', 'ipb_user' ], $fld_user || $fld_userid );
63
		$this->addFieldsIf( 'ipb_by_text', $fld_by );
64
		$this->addFieldsIf( 'ipb_by', $fld_byid );
65
		$this->addFieldsIf( 'ipb_expiry', $fld_expiry );
66
		$this->addFieldsIf( 'ipb_reason', $fld_reason );
67
		$this->addFieldsIf( [ 'ipb_range_start', 'ipb_range_end' ], $fld_range );
68
		$this->addFieldsIf( [ 'ipb_anon_only', 'ipb_create_account', 'ipb_enable_autoblock',
69
			'ipb_block_email', 'ipb_deleted', 'ipb_allow_usertalk' ],
70
			$fld_flags );
71
72
		$this->addOption( 'LIMIT', $params['limit'] + 1 );
73
		$this->addTimestampWhereRange(
74
			'ipb_timestamp',
75
			$params['dir'],
76
			$params['start'],
77
			$params['end']
78
		);
79
		// Include in ORDER BY for uniqueness
80
		$this->addWhereRange( 'ipb_id', $params['dir'], null, null );
81
82
		if ( !is_null( $params['continue'] ) ) {
83
			$cont = explode( '|', $params['continue'] );
84
			$this->dieContinueUsageIf( count( $cont ) != 2 );
85
			$op = ( $params['dir'] == 'newer' ? '>' : '<' );
86
			$continueTimestamp = $db->addQuotes( $db->timestamp( $cont[0] ) );
0 ignored issues
show
Security Bug introduced by
It seems like $db->timestamp($cont[0]) targeting DatabaseBase::timestamp() can also be of type false; however, DatabaseBase::addQuotes() does only seem to accept string|object<Blob>, did you maybe forget to handle an error condition?
Loading history...
87
			$continueId = (int)$cont[1];
88
			$this->dieContinueUsageIf( $continueId != $cont[1] );
89
			$this->addWhere( "ipb_timestamp $op $continueTimestamp OR " .
90
				"(ipb_timestamp = $continueTimestamp AND " .
91
				"ipb_id $op= $continueId)"
92
			);
93
		}
94
95
		if ( isset( $params['ids'] ) ) {
96
			$this->addWhereFld( 'ipb_id', $params['ids'] );
97
		}
98
		if ( isset( $params['users'] ) ) {
99
			$usernames = [];
100
			foreach ( (array)$params['users'] as $u ) {
101
				$usernames[] = $this->prepareUsername( $u );
102
			}
103
			$this->addWhereFld( 'ipb_address', $usernames );
104
			$this->addWhereFld( 'ipb_auto', 0 );
105
		}
106
		if ( isset( $params['ip'] ) ) {
107
			$blockCIDRLimit = $this->getConfig()->get( 'BlockCIDRLimit' );
108
			if ( IP::isIPv4( $params['ip'] ) ) {
109
				$type = 'IPv4';
110
				$cidrLimit = $blockCIDRLimit['IPv4'];
111
				$prefixLen = 0;
112
			} elseif ( IP::isIPv6( $params['ip'] ) ) {
113
				$type = 'IPv6';
114
				$cidrLimit = $blockCIDRLimit['IPv6'];
115
				$prefixLen = 3; // IP::toHex output is prefixed with "v6-"
116
			} else {
117
				$this->dieUsage( 'IP parameter is not valid', 'param_ip' );
118
			}
119
120
			# Check range validity, if it's a CIDR
121
			list( $ip, $range ) = IP::parseCIDR( $params['ip'] );
122
			if ( $ip !== false && $range !== false && $range < $cidrLimit ) {
123
				$this->dieUsage(
124
					"$type CIDR ranges broader than /$cidrLimit are not accepted",
0 ignored issues
show
Bug introduced by
The variable $type does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
Bug introduced by
The variable $cidrLimit does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
125
					'cidrtoobroad'
126
				);
127
			}
128
129
			# Let IP::parseRange handle calculating $upper, instead of duplicating the logic here.
130
			list( $lower, $upper ) = IP::parseRange( $params['ip'] );
131
132
			# Extract the common prefix to any rangeblock affecting this IP/CIDR
133
			$prefix = substr( $lower, 0, $prefixLen + floor( $cidrLimit / 4 ) );
0 ignored issues
show
Bug introduced by
The variable $prefixLen does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
134
135
			# Fairly hard to make a malicious SQL statement out of hex characters,
136
			# but it is good practice to add quotes
137
			$lower = $db->addQuotes( $lower );
138
			$upper = $db->addQuotes( $upper );
139
140
			$this->addWhere( [
141
				'ipb_range_start' . $db->buildLike( $prefix, $db->anyString() ),
142
				'ipb_range_start <= ' . $lower,
143
				'ipb_range_end >= ' . $upper,
144
				'ipb_auto' => 0
145
			] );
146
		}
147
148
		if ( !is_null( $params['show'] ) ) {
149
			$show = array_flip( $params['show'] );
150
151
			/* Check for conflicting parameters. */
152 View Code Duplication
			if ( ( isset( $show['account'] ) && isset( $show['!account'] ) )
153
				|| ( isset( $show['ip'] ) && isset( $show['!ip'] ) )
154
				|| ( isset( $show['range'] ) && isset( $show['!range'] ) )
155
				|| ( isset( $show['temp'] ) && isset( $show['!temp'] ) )
156
			) {
157
				$this->dieUsageMsg( 'show' );
158
			}
159
160
			$this->addWhereIf( 'ipb_user = 0', isset( $show['!account'] ) );
161
			$this->addWhereIf( 'ipb_user != 0', isset( $show['account'] ) );
162
			$this->addWhereIf( 'ipb_user != 0 OR ipb_range_end > ipb_range_start', isset( $show['!ip'] ) );
163
			$this->addWhereIf( 'ipb_user = 0 AND ipb_range_end = ipb_range_start', isset( $show['ip'] ) );
164
			$this->addWhereIf( 'ipb_expiry = ' .
165
				$db->addQuotes( $db->getInfinity() ), isset( $show['!temp'] ) );
166
			$this->addWhereIf( 'ipb_expiry != ' .
167
				$db->addQuotes( $db->getInfinity() ), isset( $show['temp'] ) );
168
			$this->addWhereIf( 'ipb_range_end = ipb_range_start', isset( $show['!range'] ) );
169
			$this->addWhereIf( 'ipb_range_end > ipb_range_start', isset( $show['range'] ) );
170
		}
171
172
		if ( !$this->getUser()->isAllowed( 'hideuser' ) ) {
173
			$this->addWhereFld( 'ipb_deleted', 0 );
174
		}
175
176
		// Purge expired entries on one in every 10 queries
177
		if ( !mt_rand( 0, 10 ) ) {
178
			Block::purgeExpired();
179
		}
180
181
		$res = $this->select( __METHOD__ );
182
183
		$count = 0;
184
		foreach ( $res as $row ) {
185
			if ( ++$count > $params['limit'] ) {
186
				// We've had enough
187
				$this->setContinueEnumParameter( 'continue', "$row->ipb_timestamp|$row->ipb_id" );
188
				break;
189
			}
190
			$block = [
191
				ApiResult::META_TYPE => 'assoc',
192
			];
193
			if ( $fld_id ) {
194
				$block['id'] = (int)$row->ipb_id;
195
			}
196
			if ( $fld_user && !$row->ipb_auto ) {
197
				$block['user'] = $row->ipb_address;
198
			}
199
			if ( $fld_userid && !$row->ipb_auto ) {
200
				$block['userid'] = (int)$row->ipb_user;
201
			}
202
			if ( $fld_by ) {
203
				$block['by'] = $row->ipb_by_text;
204
			}
205
			if ( $fld_byid ) {
206
				$block['byid'] = (int)$row->ipb_by;
207
			}
208
			if ( $fld_timestamp ) {
209
				$block['timestamp'] = wfTimestamp( TS_ISO_8601, $row->ipb_timestamp );
210
			}
211
			if ( $fld_expiry ) {
212
				$block['expiry'] = $wgContLang->formatExpiry( $row->ipb_expiry, TS_ISO_8601 );
213
			}
214
			if ( $fld_reason ) {
215
				$block['reason'] = $row->ipb_reason;
216
			}
217
			if ( $fld_range && !$row->ipb_auto ) {
218
				$block['rangestart'] = IP::formatHex( $row->ipb_range_start );
219
				$block['rangeend'] = IP::formatHex( $row->ipb_range_end );
220
			}
221
			if ( $fld_flags ) {
222
				// For clarity, these flags use the same names as their action=block counterparts
223
				$block['automatic'] = (bool)$row->ipb_auto;
224
				$block['anononly'] = (bool)$row->ipb_anon_only;
225
				$block['nocreate'] = (bool)$row->ipb_create_account;
226
				$block['autoblock'] = (bool)$row->ipb_enable_autoblock;
227
				$block['noemail'] = (bool)$row->ipb_block_email;
228
				$block['hidden'] = (bool)$row->ipb_deleted;
229
				$block['allowusertalk'] = (bool)$row->ipb_allow_usertalk;
230
			}
231
			$fit = $result->addValue( [ 'query', $this->getModuleName() ], null, $block );
232
			if ( !$fit ) {
233
				$this->setContinueEnumParameter( 'continue', "$row->ipb_timestamp|$row->ipb_id" );
234
				break;
235
			}
236
		}
237
		$result->addIndexedTagName( [ 'query', $this->getModuleName() ], 'block' );
238
	}
239
240
	protected function prepareUsername( $user ) {
241
		if ( !$user ) {
242
			$this->dieUsage( 'User parameter may not be empty', 'param_user' );
243
		}
244
		$name = User::isIP( $user )
245
			? $user
246
			: User::getCanonicalName( $user, 'valid' );
247
		if ( $name === false ) {
248
			$this->dieUsage( "User name {$user} is not valid", 'param_user' );
249
		}
250
		return $name;
251
	}
252
253
	public function getAllowedParams() {
254
		$blockCIDRLimit = $this->getConfig()->get( 'BlockCIDRLimit' );
255
256
		return [
257
			'start' => [
258
				ApiBase::PARAM_TYPE => 'timestamp'
259
			],
260
			'end' => [
261
				ApiBase::PARAM_TYPE => 'timestamp',
262
			],
263
			'dir' => [
264
				ApiBase::PARAM_TYPE => [
265
					'newer',
266
					'older'
267
				],
268
				ApiBase::PARAM_DFLT => 'older',
269
				ApiBase::PARAM_HELP_MSG => 'api-help-param-direction',
270
			],
271
			'ids' => [
272
				ApiBase::PARAM_TYPE => 'integer',
273
				ApiBase::PARAM_ISMULTI => true
274
			],
275
			'users' => [
276
				ApiBase::PARAM_TYPE => 'user',
277
				ApiBase::PARAM_ISMULTI => true
278
			],
279
			'ip' => [
280
				ApiBase::PARAM_HELP_MSG => [
281
					'apihelp-query+blocks-param-ip',
282
					$blockCIDRLimit['IPv4'],
283
					$blockCIDRLimit['IPv6'],
284
				],
285
			],
286
			'limit' => [
287
				ApiBase::PARAM_DFLT => 10,
288
				ApiBase::PARAM_TYPE => 'limit',
289
				ApiBase::PARAM_MIN => 1,
290
				ApiBase::PARAM_MAX => ApiBase::LIMIT_BIG1,
291
				ApiBase::PARAM_MAX2 => ApiBase::LIMIT_BIG2
292
			],
293
			'prop' => [
294
				ApiBase::PARAM_DFLT => 'id|user|by|timestamp|expiry|reason|flags',
295
				ApiBase::PARAM_TYPE => [
296
					'id',
297
					'user',
298
					'userid',
299
					'by',
300
					'byid',
301
					'timestamp',
302
					'expiry',
303
					'reason',
304
					'range',
305
					'flags'
306
				],
307
				ApiBase::PARAM_ISMULTI => true,
308
				ApiBase::PARAM_HELP_MSG_PER_VALUE => [],
309
			],
310
			'show' => [
311
				ApiBase::PARAM_TYPE => [
312
					'account',
313
					'!account',
314
					'temp',
315
					'!temp',
316
					'ip',
317
					'!ip',
318
					'range',
319
					'!range',
320
				],
321
				ApiBase::PARAM_ISMULTI => true
322
			],
323
			'continue' => [
324
				ApiBase::PARAM_HELP_MSG => 'api-help-param-continue',
325
			],
326
		];
327
	}
328
329
	protected function getExamplesMessages() {
330
		return [
331
			'action=query&list=blocks'
332
				=> 'apihelp-query+blocks-example-simple',
333
			'action=query&list=blocks&bkusers=Alice|Bob'
334
				=> 'apihelp-query+blocks-example-users',
335
		];
336
	}
337
338
	public function getHelpUrls() {
339
		return 'https://www.mediawiki.org/wiki/API:Blocks';
340
	}
341
}
342