? sites/default/files
? sites/default/settings.php
Index: includes/cache.inc
===================================================================
RCS file: /cvs/drupal/drupal/includes/cache.inc,v
retrieving revision 1.17
diff -u -p -r1.17 cache.inc
--- includes/cache.inc	29 Jan 2008 11:36:06 -0000	1.17
+++ includes/cache.inc	6 Feb 2008 07:39:29 -0000
@@ -106,9 +106,17 @@ function cache_set($cid, $data, $table =
     $serialized = 1;
   }
   $created = time();
-  db_query("UPDATE {". $table ."} SET data = %b, created = %d, expire = %d, headers = '%s', serialized = %d WHERE cid = '%s'", $data, $created, $expire, $headers, $serialized, $cid);
+  $values = array(
+    array('field' => 'data', 'placeholder' => '%b', 'data' => $data),
+    array('field' => 'created', 'placeholder' => '%d', 'data' => $created),
+    array('field' => 'expire', 'placeholder' => '%d', 'data' => $expire),
+    array('field' => 'headers', 'placeholder' => "'%s'", 'data' => $headers),
+    array('field' => 'serialized', 'placeholder' => '%d', 'data' => $serialized),
+  );
+  db_query_update($table, $values, "cid = '%s'", $cid);
   if (!db_affected_rows()) {
-    @db_query("INSERT INTO {". $table ."} (cid, data, created, expire, headers, serialized) VALUES ('%s', %b, %d, %d, '%s', %d)", $cid, $data, $created, $expire, $headers, $serialized);
+    $values[] = array('field' => 'cid', 'placeholder' => "'%s'", 'data' => $cid);
+    db_query_insert($table, $values);
   }
 }
 
Index: includes/common.inc
===================================================================
RCS file: /cvs/drupal/drupal/includes/common.inc,v
retrieving revision 1.756
diff -u -p -r1.756 common.inc
--- includes/common.inc	30 Jan 2008 23:07:41 -0000	1.756
+++ includes/common.inc	6 Feb 2008 07:39:31 -0000
@@ -3219,7 +3219,7 @@ function drupal_schema_fields_sql($table
  *   The object to write. This is a reference, as defaults according to
  *   the schema may be filled in on the object, as well as ID on the serial
  *   type(s). Both array an object types may be passed.
- * @param $update
+ * @param primary_keys
  *   If this is an update, specify the primary keys' field names. It is the
  *   caller's responsibility to know if a record for this object already
  *   exists in the database. If there is only 1 key, you may pass a simple string.
@@ -3230,19 +3230,15 @@ function drupal_schema_fields_sql($table
  *   the $table. For example, $object->nid will be populated after inserting
  *   a new node.
  */
-function drupal_write_record($table, &$object, $update = array()) {
-  // Standardize $update to an array.
-  if (is_string($update)) {
-    $update = array($update);
+function drupal_write_record($table, &$object, $primary_keys = array()) {
+  // Standardize $primary_keys to an array.
+  if (!is_array($primary_keys)) {
+    $primary_keys = array($primary_keys);
   }
 
   // Convert to an object if needed.
-  if (is_array($object)) {
+  if ($array = is_array($object)) {
     $object = (object) $object;
-    $array = TRUE;
-  }
-  else {
-    $array = FALSE;
   }
 
   $schema = drupal_get_schema($table);
@@ -3250,18 +3246,19 @@ function drupal_write_record($table, &$o
     return FALSE;
   }
 
-  $fields = $defs = $values = $serials = $placeholders = array();
+  $values = array();
+  $serials = array();
 
   // Go through our schema, build SQL, and when inserting, fill in defaults for
   // fields that are not set.
   foreach ($schema['fields'] as $field => $info) {
     // Special case -- skip serial types if we are updating.
-    if ($info['type'] == 'serial' && count($update)) {
+    if ($info['type'] == 'serial' && count($primary_keys)) {
       continue;
     }
 
     // For inserts, populate defaults from Schema if not already provided
-    if (!isset($object->$field) && !count($update) && isset($info['default'])) {
+    if (!isset($object->$field) && !count($primary_keys) && isset($info['default'])) {
       $object->$field = $info['default'];
     }
 
@@ -3274,44 +3271,40 @@ function drupal_write_record($table, &$o
 
     // Build arrays for the fields, placeholders, and values in our query.
     if (isset($object->$field)) {
-      $fields[] = $field;
-      $placeholders[] = db_type_placeholder($info['type']);
+      $value['field'] = $field;
+      $value['placeholder'] = db_type_placeholder($info['type']);
 
       if (empty($info['serialize'])) {
-        $values[] = $object->$field;
+        $value['data'] = $object->$field;
       }
       else {
-        $values[] = serialize($object->$field);
+        $value['data'] = serialize($object->$field);
       }
+
+      $values[] = $value;
     }
   }
 
-  // Build the SQL.
-  $query = '';
-  if (!count($update)) {
-    $query = "INSERT INTO {". $table ."} (". implode(', ', $fields) .') VALUES ('. implode(', ', $placeholders) .')';
+  // Execute the SQL.
+  if (!count($primary_keys)) {
+    $result = db_query_insert($table, $values);
     $return = SAVED_NEW;
   }
   else {
-    $query = '';
-    foreach ($fields as $id => $field) {
-      if ($query) {
-        $query .= ', ';
+    foreach ($primary_keys as $key => $value){
+      // $primary_key is NOT in key-value pair format.
+      if (!isset($schema['fields'][$key]) && isset($schema['fields'][$value])) {
+        $key = $value;
+        $value = $object->$key;
       }
-      $query .= $field .' = '. $placeholders[$id];
-    }
-
-    foreach ($update as $key){
       $conditions[] = "$key = ". db_type_placeholder($schema['fields'][$key]['type']);
-      $values[] = $object->$key;
+      $args[] = $value;
     }
-
-    $query = "UPDATE {". $table ."} SET $query WHERE ". implode(' AND ', $conditions);
+    $result = db_query_update($table, $values, implode(' AND ', $conditions), $args);
     $return = SAVED_UPDATED;
   }
 
-  // Execute the SQL.
-  if (db_query($query, $values)) {
+  if ($result) {
     if ($serials) {
       // Get last insert ids and fill them in.
       foreach ($serials as $field) {
@@ -3331,6 +3324,47 @@ function drupal_write_record($table, &$o
 }
 
 /**
+ * Drop a record from the database based upon the schema.
+ *
+ * @param $table
+ *   The name of the table; this must exist in schema API.
+ * @param $object
+ *   The object to drop. This is a reference, as defaults according to
+ *   the schema may be filled in on the object, as well as ID on the serial
+ *   type(s). Both array an object types may be passed.
+ * @param primary_keys
+ *   Specify the primary keys' field names. If there is only 1 key, you may
+ *   pass a simple string.
+ * @return (boolean) Failure to write a record will return FALSE. Otherwise,
+ *   TRUE is returned.
+ */
+function drupal_drop_record($table, $object, $primary_keys = array()) {
+  // Standardize $primary_keys to an array.
+  if (!is_array($primary_keys)) {
+    $primary_keys = array($primary_keys);
+  }
+
+  // Convert to an object if needed.
+  if ($array = is_array($object)) {
+    $object = (object) $object;
+  }
+
+  $schema = drupal_get_schema($table);
+  if (empty($schema)) {
+    return FALSE;
+  }
+
+  // Execute the request.
+  foreach ($primary_keys as $key){
+    $conditions[] = "$key = ". db_type_placeholder($schema['fields'][$key]['type']);
+    $args[] = $object->$key;
+  }
+  db_query_delete($table, implode(' AND ', $conditions), $args);
+
+  return SAVED_DELETED;
+}
+
+/**
  * @} End of "ingroup schemaapi".
  */
 
Index: includes/database.mysql-common.inc
===================================================================
RCS file: /cvs/drupal/drupal/includes/database.mysql-common.inc,v
retrieving revision 1.17
diff -u -p -r1.17 database.mysql-common.inc
--- includes/database.mysql-common.inc	30 Jan 2008 14:34:29 -0000	1.17
+++ includes/database.mysql-common.inc	6 Feb 2008 07:39:32 -0000
@@ -43,6 +43,134 @@ function db_query($query) {
 }
 
 /**
+ * Insert a row of record into database.
+ *
+ * @param $table
+ *   Table to insert.
+ * @param $values
+ *   An array containing the insert values. Each element of the array
+ *   should be an associatie array with the following keys:
+ *   - "field": The database field represented in the table column.
+ *   - "placeholder": The placeholder of the table column, using printf()
+ *     syntax. Valid %-modifiers are: %d, %f, %s and %b.
+ *   - "data": The data to insert into the table column.
+ * @return
+ *   A database query result resource, or FALSE if the query was not
+ *   executed correctly.
+ */
+function db_query_insert($table, $values) {
+  $fields = array();
+  $placeholders = array();
+  $data = array();
+  foreach ($values as $value) {
+    $fields[] = $value['field'];
+    $placeholders[] = $value['placeholder'];
+    $data[] = $value['data'];
+  }
+
+  if (!count($fields)) {
+    return FALSE;
+  }
+
+  $query = "INSERT INTO {". $table ."} (". implode(', ', $fields) .") VALUES (". implode(', ', $placeholders) .")";
+  return db_query($query, $data);
+}
+
+/**
+ * Update a row of record in database.
+ *
+ * @param $table
+ *   Table to update.
+ * @param $values
+ *   An array containing the update values. Each element of the array
+ *   should be an associatie array with the following keys:
+ *   - "field": The database field represented in the table column.
+ *   - "placeholder": The placeholder of the table column, using printf()
+ *     syntax. Valid %-modifiers are: %d, %f, %s and %b.
+ *   - "data": The data to insert into the table column.
+ * @param $where_clause
+ *   A string containing an update condition query (where clause).
+ * @param ...
+ *   A variable number of arguments which are substituted into the query
+ *   WHERE condition, using printf() syntax. Instead of a variable number
+ *   of query arguments, you may also pass a single array containing the
+ *   query arguments.
+ *
+ *   Valid %-modifiers are: %d, %f and %s.
+ *
+ *   NOTE: using this syntax will cast NULL and FALSE values to decimal 0,
+ *   and TRUE values to decimal 1.
+ *
+ * @return
+ *   A database query result resource, or FALSE if the query was not
+ *   executed correctly.
+ */
+function db_query_update($table, $values, $where_clause = NULL) {
+  $args = func_get_args();
+  $args = array_slice($args, 3);
+  if (isset($args[0]) and is_array($args[0])) { // 'All arguments in one array' syntax
+    $args = $args[0];
+  }
+
+  $fields = array();
+  $data = array();
+  foreach ($values as $value) {
+    $fields[] = $value['field'] .' = '. $value['placeholder'];
+    $data[] = $value['data'];
+  }
+
+  if (!count($fields)) {
+    return FALSE;
+  }
+
+  $query = "UPDATE {". $table ."} SET ". implode(', ', $fields);
+  if ($where_clause) {
+    $query .= " WHERE ". $where_clause;
+    $data = array_merge($data, $args);
+  }
+  return db_query($query, $data);
+}
+
+/**
+ * Delete a row of record from database.
+ *
+ * @param $table
+ *   Table to delete.
+ * @param $where_clause
+ *   A string containing an update condition query (where clause).
+ * @param ...
+ *   A variable number of arguments which are substituted into the query
+ *   WHERE condition, using printf() syntax. Instead of a variable number
+ *   of query arguments, you may also pass a single array containing the
+ *   query arguments.
+ *
+ *   Valid %-modifiers are: %d, %f and %s.
+ *
+ *   NOTE: using this syntax will cast NULL and FALSE values to decimal 0,
+ *   and TRUE values to decimal 1.
+ *
+ * @return
+ *   A database query result resource, or FALSE if the query was not
+ *   executed correctly.
+ */
+function db_query_delete($table, $where_clause = NULL) {
+  $args = func_get_args();
+  $args = array_slice($args, 2);
+  if (isset($args[0]) and is_array($args[0])) { // 'All arguments in one array' syntax
+    $args = $args[0];
+  }
+
+  $data = array();
+
+  $query = "DELETE FROM {". $table ."}";
+  if ($where_clause) {
+    $query .= " WHERE ". $where_clause;
+    $data = $args;
+  }
+  return db_query($query, $data);
+}
+
+/**
  * @ingroup schemaapi
  * @{
  */
Index: includes/database.pgsql.inc
===================================================================
RCS file: /cvs/drupal/drupal/includes/database.pgsql.inc,v
retrieving revision 1.68
diff -u -p -r1.68 database.pgsql.inc
--- includes/database.pgsql.inc	4 Jan 2008 09:31:48 -0000	1.68
+++ includes/database.pgsql.inc	6 Feb 2008 07:39:33 -0000
@@ -220,6 +220,134 @@ function db_error() {
 }
 
 /**
+ * Insert a row of record into database.
+ *
+ * @param $table
+ *   Table to insert.
+ * @param $values
+ *   An array containing the insert values. Each element of the array
+ *   should be an associatie array with the following keys:
+ *   - "field": The database field represented in the table column.
+ *   - "placeholder": The placeholder of the table column, using printf()
+ *     syntax. Valid %-modifiers are: %d, %f, %s and %b.
+ *   - "data": The data to insert into the table column.
+ * @return
+ *   A database query result resource, or FALSE if the query was not
+ *   executed correctly.
+ */
+function db_query_insert($table, $values) {
+  $fields = array();
+  $placeholders = array();
+  $data = array();
+  foreach ($values as $value) {
+    $fields[] = $value['field'];
+    $placeholders[] = $value['placeholder'];
+    $data[] = $value['data'];
+  }
+
+  if (!count($fields)) {
+    return FALSE;
+  }
+
+  $query = "INSERT INTO {". $table ."} (". implode(', ', $fields) .") VALUES (". implode(', ', $placeholders) .")";
+  return db_query($query, $data);
+}
+
+/**
+ * Update a row of record in database.
+ *
+ * @param $table
+ *   Table to update.
+ * @param $values
+ *   An array containing the update values. Each element of the array
+ *   should be an associatie array with the following keys:
+ *   - "field": The database field represented in the table column.
+ *   - "placeholder": The placeholder of the table column, using printf()
+ *     syntax. Valid %-modifiers are: %d, %f, %s and %b.
+ *   - "data": The data to insert into the table column.
+ * @param $where_clause
+ *   A string containing an update condition query (where clause).
+ * @param ...
+ *   A variable number of arguments which are substituted into the query
+ *   WHERE condition, using printf() syntax. Instead of a variable number
+ *   of query arguments, you may also pass a single array containing the
+ *   query arguments.
+ *
+ *   Valid %-modifiers are: %d, %f and %s.
+ *
+ *   NOTE: using this syntax will cast NULL and FALSE values to decimal 0,
+ *   and TRUE values to decimal 1.
+ *
+ * @return
+ *   A database query result resource, or FALSE if the query was not
+ *   executed correctly.
+ */
+function db_query_update($table, $values, $where_clause = NULL) {
+  $args = func_get_args();
+  $args = array_slice($args, 3);
+  if (isset($args[0]) and is_array($args[0])) { // 'All arguments in one array' syntax
+    $args = $args[0];
+  }
+
+  $fields = array();
+  $data = array();
+  foreach ($values as $value) {
+    $fields[] = $value['field'] .' = '. $value['placeholder'];
+    $data[] = $value['data'];
+  }
+
+  if (!count($fields)) {
+    return FALSE;
+  }
+
+  $query = "UPDATE {". $table ."} SET ". implode(', ', $fields);
+  if ($where_clause) {
+    $query .= " WHERE ". $where_clause;
+    $data = array_merge($data, $args);
+  }
+  return db_query($query, $data);
+}
+
+/**
+ * Delete a row of record from database.
+ *
+ * @param $table
+ *   Table to delete.
+ * @param $where_clause
+ *   A string containing an update condition query (where clause).
+ * @param ...
+ *   A variable number of arguments which are substituted into the query
+ *   WHERE condition, using printf() syntax. Instead of a variable number
+ *   of query arguments, you may also pass a single array containing the
+ *   query arguments.
+ *
+ *   Valid %-modifiers are: %d, %f and %s.
+ *
+ *   NOTE: using this syntax will cast NULL and FALSE values to decimal 0,
+ *   and TRUE values to decimal 1.
+ *
+ * @return
+ *   A database query result resource, or FALSE if the query was not
+ *   executed correctly.
+ */
+function db_query_delete($table, $where_clause = NULL) {
+  $args = func_get_args();
+  $args = array_slice($args, 2);
+  if (isset($args[0]) and is_array($args[0])) { // 'All arguments in one array' syntax
+    $args = $args[0];
+  }
+
+  $data = array();
+
+  $query = "DELETE FROM {". $table ."}";
+  if ($where_clause) {
+    $query .= " WHERE ". $where_clause;
+    $data = $args;
+  }
+  return db_query($query, $data);
+}
+
+/**
  * Returns the last insert id. This function is thread safe.
  *
  * @param $table
