This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
0 ignored issues
–
show
|
|||
2 | /** |
||
3 | * Move a batch of pages. |
||
4 | * |
||
5 | * This program is free software; you can redistribute it and/or modify |
||
6 | * it under the terms of the GNU General Public License as published by |
||
7 | * the Free Software Foundation; either version 2 of the License, or |
||
8 | * (at your option) any later version. |
||
9 | * |
||
10 | * This program is distributed in the hope that it will be useful, |
||
11 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
12 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
13 | * GNU General Public License for more details. |
||
14 | * |
||
15 | * You should have received a copy of the GNU General Public License along |
||
16 | * with this program; if not, write to the Free Software Foundation, Inc., |
||
17 | * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. |
||
18 | * http://www.gnu.org/copyleft/gpl.html |
||
19 | * |
||
20 | * @file |
||
21 | * @ingroup Maintenance |
||
22 | * @author Tim Starling |
||
23 | * |
||
24 | * USAGE: php moveBatch.php [-u <user>] [-r <reason>] [-i <interval>] [-noredirects] [listfile] |
||
25 | * |
||
26 | * [listfile] - file with two titles per line, separated with pipe characters; |
||
27 | * the first title is the source, the second is the destination. |
||
28 | * Standard input is used if listfile is not given. |
||
29 | * <user> - username to perform moves as |
||
30 | * <reason> - reason to be given for moves |
||
31 | * <interval> - number of seconds to sleep after each move |
||
32 | * <noredirects> - suppress creation of redirects |
||
33 | * |
||
34 | * This will print out error codes from Title::moveTo() if something goes wrong, |
||
35 | * e.g. immobile_namespace for namespaces which can't be moved |
||
36 | */ |
||
37 | |||
38 | require_once __DIR__ . '/Maintenance.php'; |
||
39 | |||
40 | /** |
||
41 | * Maintenance script to move a batch of pages. |
||
42 | * |
||
43 | * @ingroup Maintenance |
||
44 | */ |
||
45 | class MoveBatch extends Maintenance { |
||
46 | View Code Duplication | public function __construct() { |
|
47 | parent::__construct(); |
||
48 | $this->addDescription( 'Moves a batch of pages' ); |
||
49 | $this->addOption( 'u', "User to perform move", false, true ); |
||
50 | $this->addOption( 'r', "Reason to move page", false, true ); |
||
51 | $this->addOption( 'i', "Interval to sleep between moves" ); |
||
52 | $this->addOption( 'noredirects', "Suppress creation of redirects" ); |
||
53 | $this->addArg( 'listfile', 'List of pages to move, newline delimited', false ); |
||
54 | } |
||
55 | |||
56 | public function execute() { |
||
57 | global $wgUser; |
||
58 | |||
59 | # Change to current working directory |
||
60 | $oldCwd = getcwd(); |
||
61 | chdir( $oldCwd ); |
||
62 | |||
63 | # Options processing |
||
64 | $user = $this->getOption( 'u', false ); |
||
65 | $reason = $this->getOption( 'r', '' ); |
||
66 | $interval = $this->getOption( 'i', 0 ); |
||
67 | $noredirects = $this->getOption( 'noredirects', false ); |
||
68 | if ( $this->hasArg() ) { |
||
69 | $file = fopen( $this->getArg(), 'r' ); |
||
70 | } else { |
||
71 | $file = $this->getStdin(); |
||
72 | } |
||
73 | |||
74 | # Setup |
||
75 | if ( !$file ) { |
||
76 | $this->error( "Unable to read file, exiting", true ); |
||
77 | } |
||
78 | View Code Duplication | if ( $user === false ) { |
|
79 | $wgUser = User::newSystemUser( 'Move page script', [ 'steal' => true ] ); |
||
80 | } else { |
||
81 | $wgUser = User::newFromName( $user ); |
||
82 | } |
||
83 | if ( !$wgUser ) { |
||
84 | $this->error( "Invalid username", true ); |
||
85 | } |
||
86 | |||
87 | # Setup complete, now start |
||
88 | $dbw = $this->getDB( DB_MASTER ); |
||
89 | // @codingStandardsIgnoreStart Ignore avoid function calls in a FOR loop test part warning |
||
90 | for ( $linenum = 1; !feof( $file ); $linenum++ ) { |
||
91 | // @codingStandardsIgnoreEnd |
||
92 | $line = fgets( $file ); |
||
93 | if ( $line === false ) { |
||
94 | break; |
||
95 | } |
||
96 | $parts = array_map( 'trim', explode( '|', $line ) ); |
||
97 | if ( count( $parts ) != 2 ) { |
||
98 | $this->error( "Error on line $linenum, no pipe character" ); |
||
99 | continue; |
||
100 | } |
||
101 | $source = Title::newFromText( $parts[0] ); |
||
102 | $dest = Title::newFromText( $parts[1] ); |
||
103 | if ( is_null( $source ) || is_null( $dest ) ) { |
||
104 | $this->error( "Invalid title on line $linenum" ); |
||
105 | continue; |
||
106 | } |
||
107 | |||
108 | $this->output( $source->getPrefixedText() . ' --> ' . $dest->getPrefixedText() ); |
||
109 | $this->beginTransaction( $dbw, __METHOD__ ); |
||
0 ignored issues
–
show
It seems like
$dbw defined by $this->getDB(DB_MASTER) on line 88 can be null ; however, Maintenance::beginTransaction() does not accept null , maybe add an additional type check?
Unless you are absolutely sure that the expression can never be null because of other conditions, we strongly recommend to add an additional type check to your code: /** @return stdClass|null */
function mayReturnNull() { }
function doesNotAcceptNull(stdClass $x) { }
// With potential error.
function withoutCheck() {
$x = mayReturnNull();
doesNotAcceptNull($x); // Potential error here.
}
// Safe - Alternative 1
function withCheck1() {
$x = mayReturnNull();
if ( ! $x instanceof stdClass) {
throw new \LogicException('$x must be defined.');
}
doesNotAcceptNull($x);
}
// Safe - Alternative 2
function withCheck2() {
$x = mayReturnNull();
if ($x instanceof stdClass) {
doesNotAcceptNull($x);
}
}
![]() |
|||
110 | $mp = new MovePage( $source, $dest ); |
||
111 | $status = $mp->move( $wgUser, $reason, !$noredirects ); |
||
0 ignored issues
–
show
It seems like
$wgUser can also be of type false or null ; however, MovePage::move() does only seem to accept object<User> , maybe add an additional type check?
If a method or function can return multiple different values and unless you are sure that you only can receive a single value in this context, we recommend to add an additional type check: /**
* @return array|string
*/
function returnsDifferentValues($x) {
if ($x) {
return 'foo';
}
return array();
}
$x = returnsDifferentValues($y);
if (is_array($x)) {
// $x is an array.
}
If this a common case that PHP Analyzer should handle natively, please let us know by opening an issue. ![]() |
|||
112 | if ( !$status->isOK() ) { |
||
113 | $this->output( "\nFAILED: " . $status->getWikiText( false, false, 'en' ) ); |
||
114 | } |
||
115 | $this->commitTransaction( $dbw, __METHOD__ ); |
||
0 ignored issues
–
show
It seems like
$dbw defined by $this->getDB(DB_MASTER) on line 88 can be null ; however, Maintenance::commitTransaction() does not accept null , maybe add an additional type check?
Unless you are absolutely sure that the expression can never be null because of other conditions, we strongly recommend to add an additional type check to your code: /** @return stdClass|null */
function mayReturnNull() { }
function doesNotAcceptNull(stdClass $x) { }
// With potential error.
function withoutCheck() {
$x = mayReturnNull();
doesNotAcceptNull($x); // Potential error here.
}
// Safe - Alternative 1
function withCheck1() {
$x = mayReturnNull();
if ( ! $x instanceof stdClass) {
throw new \LogicException('$x must be defined.');
}
doesNotAcceptNull($x);
}
// Safe - Alternative 2
function withCheck2() {
$x = mayReturnNull();
if ($x instanceof stdClass) {
doesNotAcceptNull($x);
}
}
![]() |
|||
116 | $this->output( "\n" ); |
||
117 | |||
118 | if ( $interval ) { |
||
119 | sleep( $interval ); |
||
120 | } |
||
121 | wfWaitForSlaves(); |
||
0 ignored issues
–
show
The function
wfWaitForSlaves() has been deprecated with message: since 1.27 Use LBFactory::waitForReplication
This function has been deprecated. The supplier of the file has supplied an explanatory message. The explanatory message should give you some clue as to whether and when the function will be removed from the class and what other function to use instead. ![]() |
|||
122 | } |
||
123 | } |
||
124 | } |
||
125 | |||
126 | $maintClass = "MoveBatch"; |
||
127 | require_once RUN_MAINTENANCE_IF_MAIN; |
||
128 |
The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.
The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.
To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.