<?php
// ===========================================================================================
//
// db-eval.php
//
// Description: Testprogram for eval() using code stored in a database table.
//
//
// Author: Mikael Roos
//

// -------------------------------------------------------------------------------------------
//
// SQL code to create/insert the table in which we store the PHP code to be evaluated
//
/*
--
-- SQL to create the database table
--
 CREATE TABLE Phpcode (
	id INT NOT NULL PRIMARY KEY,
	code VARCHAR(500) NOT NULL
);

INSERT INTO Phpcode (id, code)
VALUES 
(1 , '$counter++;'), 
(2 , '$counter += 1;'), 
(3 , '$counter++; if($counter >1) { $counter = 9; }');
*/


// -------------------------------------------------------------------------------------------
//
// Display nice message about this test-page for eval
//
require_once('common.php');
echo $header;
echo <<<EOD
<p>Example code to show how eval() works, both from variable and from database.</p>
<p>Read the PHP manual for details: <a href='http://php.net/manual/en/function.eval.php'>http://php.net/manual/en/function.eval.php</a></p>
<code>
<pre>
--
-- SQL to create the database table
--
 CREATE TABLE Phpcode (
	id INT NOT NULL PRIMARY KEY,
	code VARCHAR(500) NOT NULL
);

INSERT INTO Phpcode (id, code)
VALUES 
(1 , '\$counter++;'), 
(2 , '\$counter += 1;'), 
(3 , '\$counter++; if(\$counter >1) { \$counter = 9; }');
</pre>
</code>
<p>Lets try out the example.</p>
EOD;


// -------------------------------------------------------------------------------------------
//
// First try to execute the same thing from a string.
//
// Since nowdox is not available (need PHP 5.3.0) I will instead prepend each $ with a \ 
// to prevent it from being evaluated. It works fine. But nowdoc would be better.
// 
// http://php.net/manual/en/language.types.string.php (nowdoc, heredoc)
// http://php.net/manual/en/function.eval.php
//
$code1 = "\$counter++;";
$code2 = '$counter += 1;';

$code3 = <<<EOD
\$counter++;
if(\$counter >1) {
	\$counter = 9;
}
EOD;


// ----------------------------------------------------------------------------
//
// Evaluate the code segments using eval()
//
// http://php.net/manual/en/function.eval.php
//
echo "<p>eval() using variables. The following code should result in a line saying: 0129</p>";
$counter = 0;
echo $counter;

eval($code1);
echo $counter;

eval($code2);
echo $counter;

eval($code3);
echo $counter;


// ----------------------------------------------------------------------------
//
// Connect to the database to retrieve and evaluate the code segments
//
// http://php.net/manual/en/function.eval.php
//

// Connect to database
require_once('config.php');
$mysqli = new mysqli(DB_HOST, DB_USER, DB_PASSWORD, DB_DATABASE);
!mysqli_connect_error() or die("Connect failed: ".mysqli_connect_error()."<br>");

// Perform query
$query = "SELECT * FROM Phpcode;";
$res = $mysqli->query($query) 
			or die("Could not query database, query =<br/><pre>{$query}</pre><br/>{$mysqli->error}");

// Use resultset
echo "<p>eval() using database. The following code should result in a line saying: 0129</p>";
$counter = 0;
echo $counter;
while($row = $res->fetch_object()) {	
	eval($row->code);
	echo $counter;
}

$res->close(); 
$mysqli->close(); 


// ----------------------------------------------------------------------------
//
// Good work
//
echo "<p>I am so great :)</p>";
echo $footer;
exit;

?>