Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 28 additions & 22 deletions classes/Utils.php
Original file line number Diff line number Diff line change
Expand Up @@ -1334,7 +1334,7 @@
$user_id = $this->get_user_id( $user_id );

// Delete Quiz submissions.
$attempts = \Tutor\Models\QuizModel::get_quiz_attempts_by_course_ids( $start = 0, $limit = 99999999, $course_ids = array( $course_id ), $search_filter = '', $course_filter = '', $date_filter = '', $order_filter = '', $user_id = $user_id, false, true );

Check failure on line 1337 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Assignments must be the first block of code on a line

if ( is_array( $attempts ) ) {
$attempt_ids = array_map(
Expand Down Expand Up @@ -1512,7 +1512,7 @@
ON topic.ID = items.post_parent
WHERE topic.post_parent = %d
AND items.post_status = %s
" . ( $post_type ? " AND items.post_type='{$post_type}' " : '' ) . '

Check failure on line 1515 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found :

Check failure on line 1515 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found interpolated variable {$post_type} at " AND items.post_type='{$post_type}' "

Check failure on line 1515 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found ?

Check failure on line 1515 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found $post_type
ORDER BY topic.menu_order ASC,
items.menu_order ASC;
',
Expand Down Expand Up @@ -2145,11 +2145,11 @@
ON user.ID = posts.post_author
WHERE posts.post_type = %s
AND posts.post_status = %s
{$course_query}

Check failure on line 2148 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found interpolated variable {$course_query} at {$course_query}

{$date_query}

Check failure on line 2149 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found interpolated variable {$date_query} at {$date_query}

AND (user.display_name LIKE %s OR user.user_email = %s OR user.user_login LIKE %s)
GROUP BY post_author
{$order_query}

Check failure on line 2152 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found interpolated variable {$order_query} at {$order_query}

LIMIT %d, %d
",
'tutor_enrolled',
Expand Down Expand Up @@ -2204,8 +2204,8 @@
ON user.ID = posts.post_author
WHERE posts.post_type = %s
AND posts.post_status = %s
{$course_query}

Check failure on line 2207 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found interpolated variable {$course_query} at {$course_query}

{$date_query}

Check failure on line 2208 in classes/Utils.php

View workflow job for this annotation

GitHub Actions / WPCS

Use placeholders and $wpdb->prepare(); found interpolated variable {$date_query} at {$date_query}

AND (user.display_name LIKE %s OR user.user_email = %s OR user.user_login LIKE %s)
GROUP BY user.ID
",
Expand Down Expand Up @@ -4023,12 +4023,13 @@
$where_clause = '_reviews.comment_post_ID = %d';
}

$limit_offset = $count_only ? '' : ' LIMIT ' . (int) $limit . ' OFFSET ' . (int) $start;
$status_in = array_map( 'esc_sql', (array) $status_in );
$status_in = '"' . implode( '","', $status_in ) . '"';
$include_user_id = is_array( $include_user_id ) ? $include_user_id : array( $include_user_id );
$include_user_id = array_map( 'absint', $include_user_id );
$include_user_id = implode( ',', $include_user_id );
$start = absint( $start );
$limit = absint( $limit );
$limit_offset = $count_only ? '' : " LIMIT {$limit} OFFSET {$start} ";
$status_in = array_values( array_filter( array_map( 'sanitize_key', (array) $status_in ) ) );
$status_in_str = count( $status_in ) ? QueryHelper::prepare_in_clause( $status_in ) : "''";
$include_user_id = array_values( array_filter( array_map( 'absint', (array) $include_user_id ) ) );
$user_id_in_str = count( $include_user_id ) ? QueryHelper::prepare_in_clause( $include_user_id ) : '0';

$select_columns = $count_only ? ' COUNT(DISTINCT _reviews.comment_ID) ' :
'_reviews.comment_ID,
Expand All @@ -4052,7 +4053,7 @@
ON _reviews.user_id = _reviewer.ID
WHERE {$where_clause}
AND _reviews.comment_type = 'tutor_course_rating'
AND (_reviews.comment_approved IN ({$status_in}) OR _reviews.user_id IN ({$include_user_id}))
AND (_reviews.comment_approved IN ({$status_in_str}) OR _reviews.user_id IN ({$user_id_in_str}))
AND _rev_meta.meta_key = 'tutor_rating'
ORDER BY _reviews.comment_ID DESC {$limit_offset}",
$object_id
Expand Down Expand Up @@ -4639,6 +4640,8 @@
// Sanitize args before process.
$args = Input::sanitize_array( $args );

$params = array( $search_term );

if ( ! $user_id && ! $asker_id && null === $question_id && empty( $args['course_id'] ) ) {
return $count_only ? 0 : array();
}
Expand All @@ -4648,7 +4651,7 @@
* User query.
*/
if ( $asker_id ) {
$question_clause .= ' AND _question.user_id=' . (int) $asker_id;
$question_clause .= ' AND _question.user_id=' . absint( $asker_id );
}

if ( ! $user_id ) {
Expand All @@ -4657,31 +4660,32 @@

if ( isset( $args['course_id'] ) ) {
// Get qa for specific course.
$args['course_id'] = intval( $args['course_id'] );
$args['course_id'] = absint( $args['course_id'] );
$in_course_id_query .= ' AND _question.comment_post_ID=' . $args['course_id'] . ' ';

} elseif ( ! $asker_id && null === $question_id && ! $this->has_user_role( 'administrator', $user_id ) && current_user_can( tutor()->instructor_role ) ) {
// If current user is simple instructor (non admin), then get qa from their courses only.
$my_course_ids = $this->get_course_id_by( 'instructor', $user_id );
$in_ids = count( $my_course_ids ) ? implode( ',', $my_course_ids ) : '0';
$my_course_ids = array_filter( array_map( 'absint', (array) $this->get_course_id_by( 'instructor', $user_id ) ) );
$in_ids = count( $my_course_ids ) ? QueryHelper::prepare_in_clause( $my_course_ids ) : '0';
$in_course_id_query .= " AND _question.comment_post_ID IN($in_ids) ";
}

// Add more filters to the query.
if ( isset( $args['course-id'] ) && is_numeric( $args['course-id'] ) ) {
$filter_clause .= ' AND _course.ID=' . $args['course-id'];
$filter_clause .= ' AND _course.ID=' . absint( $args['course-id'] );
}

if ( isset( $args['date'] ) ) {
$date = esc_sql( $args['date'] );
$filter_clause .= ' AND DATE(_question.comment_date)=\'' . $date . '\'';
if ( ! empty( $args['date'] ) ) {
$formatted_date = tutor_get_formated_date( 'Y-m-d', $args['date'] );
if ( '' !== $formatted_date ) {
$filter_clause .= ' AND DATE(_question.comment_date) = CAST(%s AS DATE)';
$params[] = $formatted_date;
}
}

if ( isset( $args['order'] ) ) {
$order = strtolower( $args['order'] );
if ( 'asc' === $order || 'desc' === $order ) {
$order_condition = ' ORDER BY _question.comment_ID ' . $order . ' ';
}
$order = QueryHelper::get_valid_sort_order( $args['order'] );
$order_condition = " ORDER BY _question.comment_ID {$order} ";
}

// Meta query.
Expand Down Expand Up @@ -4739,7 +4743,9 @@
WHERE answers_t.comment_parent = _question.comment_ID
) AS answer_count";

$limit_offset = $count_only ? '' : ' LIMIT ' . (int) $limit . ' OFFSET ' . (int) $start;
$start = absint( $start );
$limit = absint( $limit );
$limit_offset = $count_only ? '' : " LIMIT {$limit} OFFSET {$start} ";

$query = $wpdb->prepare(
"SELECT {$columns_select}
Expand All @@ -4762,7 +4768,7 @@
{$filter_clause}
{$order_condition}
{$limit_offset}",
$search_term
$params
);
if ( $count_only ) {
return $wpdb->get_var( $query );
Expand All @@ -4779,7 +4785,7 @@

// Assign meta data.
if ( count( $question_ids ) ) {
$q_ids = implode( ',', $question_ids );
$q_ids = QueryHelper::prepare_in_clause( array_map( 'absint', $question_ids ) );
$meta_array = $wpdb->get_results(
"SELECT comment_id, meta_key, meta_value
FROM {$wpdb->commentmeta}
Expand Down
30 changes: 22 additions & 8 deletions models/OrderModel.php
Original file line number Diff line number Diff line change
Expand Up @@ -1028,7 +1028,6 @@ public function get_order_count( $where = array(), string $search_term = '' ) {
public function get_user_orders( $time_period = null, $start_date = null, $end_date = null, $order_status = '', int $user_id = 0, $limit = 10, int $offset = 0, $order = 'DESC', $args = array() ) {
$user_id = tutor_utils()->get_user_id( $user_id );
$order = QueryHelper::get_valid_sort_order( $order );
$order_status = esc_sql( $order_status );
$order_type_clause = '';

$response = array(
Expand All @@ -1038,12 +1037,19 @@ public function get_user_orders( $time_period = null, $start_date = null, $end_d

global $wpdb;

$params = array( $user_id );
$time_period_clause = '';
$date_range_clause = '';
$order_status_clause = ( empty( $order_status ) || 'all' === $order_status ) ? '' : "AND o.order_status = '{$order_status}'";
$order_status_clause = '';

if ( $start_date && $end_date ) {
$date_range_clause = $wpdb->prepare( 'AND DATE(created_at_gmt) BETWEEN %s AND %s', $start_date, $end_date );
$formatted_start = tutor_get_formated_date( 'Y-m-d', $start_date );
$formatted_end = tutor_get_formated_date( 'Y-m-d', $end_date );
if ( '' !== $formatted_start && '' !== $formatted_end ) {
$date_range_clause = 'AND DATE(created_at_gmt) BETWEEN CAST(%s AS DATE) AND CAST(%s AS DATE)';
$params[] = $formatted_start;
$params[] = $formatted_end;
}
} elseif ( $time_period ) {
if ( 'today' === $time_period ) {
$time_period_clause = 'AND DATE(o.created_at_gmt) = CURDATE()';
Expand All @@ -1054,16 +1060,26 @@ public function get_user_orders( $time_period = null, $start_date = null, $end_d
}
}

if ( ! empty( $order_status ) && 'all' !== $order_status ) {
$order_status_clause = 'AND o.order_status = %s';
$params[] = sanitize_key( $order_status );
}

if ( ! empty( $args['order_type'] ) ) {
$order_type_clause = ' AND ' . QueryHelper::prepare_where_clause( array( 'o.order_type' => esc_sql( $args['order_type'] ) ) );
$order_type_clause = ' AND ' . QueryHelper::prepare_where_clause( array( 'o.order_type' => sanitize_key( $args['order_type'] ) ) );
}

$limit = absint( $limit );
$offset = absint( $offset );
$params[] = $limit;
$params[] = $offset;

//phpcs:disable
$query = $wpdb->prepare(
"SELECT
SQL_CALC_FOUND_ROWS
o.*
FROM $this->table_name AS o
FROM {$this->table_name} AS o
WHERE o.user_id = %d
{$order_type_clause}
{$time_period_clause}
Expand All @@ -1072,9 +1088,7 @@ public function get_user_orders( $time_period = null, $start_date = null, $end_d
ORDER BY o.id {$order}
LIMIT %d OFFSET %d
",
$user_id,
$limit,
$offset
$params
);

$results = $wpdb->get_results( $query );
Expand Down
Loading