From e75a1f5ab36faf43602db58807099b5b83710aab Mon Sep 17 00:00:00 2001 From: Boone Gorges Date: Sun, 10 Jan 2016 03:25:15 +0000 Subject: [PATCH] Avoid invalid SQL when building ORDER BY clause using long search strings. The introduction of negative search terms in 4.4 [34934] introduced the possibility that the ORDER BY clause of a search query could be assembled in such a way as to create invalid syntax. The current changeset fixes this by ensuring that the ORDER BY clause corresponding to the search terms is excluded when it would otherwise be empty. Props salvoaranzulla. Fixes #35361. git-svn-id: https://develop.svn.wordpress.org/trunk@36251 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-includes/query.php | 7 +++++-- tests/phpunit/tests/query/search.php | 12 ++++++++++++ 2 files changed, 17 insertions(+), 2 deletions(-) diff --git a/src/wp-includes/query.php b/src/wp-includes/query.php index d53ec42788..3703428d95 100644 --- a/src/wp-includes/query.php +++ b/src/wp-includes/query.php @@ -2268,7 +2268,7 @@ class WP_Query { $like = '%' . $wpdb->esc_like( $q['s'] ) . '%'; } - $search_orderby = '(CASE '; + $search_orderby = ''; // sentence match in 'post_title' if ( $like ) { @@ -2289,7 +2289,10 @@ class WP_Query { if ( $like ) { $search_orderby .= $wpdb->prepare( "WHEN $wpdb->posts.post_content LIKE %s THEN 4 ", $like ); } - $search_orderby .= 'ELSE 5 END)'; + + if ( $search_orderby ) { + $search_orderby = '(CASE ' . $search_orderby . 'ELSE 5 END)'; + } } else { // single word or sentence search $search_orderby = reset( $q['search_orderby_title'] ) . ' DESC'; diff --git a/tests/phpunit/tests/query/search.php b/tests/phpunit/tests/query/search.php index caf862c0d6..5fe6d5e62a 100644 --- a/tests/phpunit/tests/query/search.php +++ b/tests/phpunit/tests/query/search.php @@ -125,4 +125,16 @@ class Tests_Query_Search extends WP_UnitTestCase { $this->assertEqualSets( array( $p3 ), $q->posts ); } + + /** + * @ticket 35361 + */ + public function test_search_orderby_should_be_empty_when_search_string_is_longer_than_6_words_and_exclusion_operator_is_used() { + $q = new WP_Query( array( + 's' => 'foo1 foo2 foo3 foo4 foo5 foo6 foo7 -bar', + 'fields' => 'ids', + ) ); + + $this->assertNotRegExp( '|ORDER BY \(CASE[^\)]+\)|', $q->request ); + } }