adamsaghy commented on code in PR #3226:
URL: https://github.com/apache/fineract/pull/3226#discussion_r1235551082


##########
fineract-provider/src/main/java/org/apache/fineract/infrastructure/dataqueries/service/ReadWriteNonCoreDataServiceImpl.java:
##########
@@ -214,6 +214,185 @@ public List<JsonObject> queryDataTable(String datatable, 
final String columnFilt
 
         return results;
     }
+    @Override
+    public Page<JsonObject> 
queryDataTableSearch(PagedRequest<DatatableSearchRequest> searchRequest) {
+
+        Objects.requireNonNull(searchRequest, "Search Request Should not be 
Empty");
+        Optional<DatatableSearchRequest> request = searchRequest.getRequest();
+        List<String> resultColumns = 
request.map(DatatableSearchRequest::getResultColumns).orElse(Collections.emptyList());
+        List<ColumnFilter> columnFilters = 
request.map(DatatableSearchRequest::getColumnFilters).orElse(Collections.emptyList());
+        String datatable = 
request.map(DatatableSearchRequest::getDatatable).orElse(null);
+        Pageable pageable = searchRequest.toPageable();
+
+        
this.context.authenticatedUser().validateHasDatatableReadPermission(datatable);
+
+        List<JsonObject> results = new ArrayList<>();
+        AtomicInteger totalElements = new AtomicInteger(0);
+        if (CollectionUtils.isNotEmpty(columnFilters) && 
CollectionUtils.isNotEmpty(resultColumns)) {
+
+            String resultColumn = 
resultColumns.stream().collect(Collectors.joining(","));
+
+            validateSqlInjectionForDynamicQuery(columnFilters, datatable, 
resultColumn);
+
+            List<ResultsetColumnHeaderData> resultsetColumnHeaderData = 
genericDataService.fillResultsetColumnHeaders(datatable);
+
+            if (CollectionUtils.isNotEmpty(resultsetColumnHeaderData)) {
+
+                Map<String, String> dataTableColumnMap = 
resultsetColumnHeaderData.stream()
+                        
.collect(Collectors.toMap(ResultsetColumnHeaderData::getColumnName, 
ResultsetColumnHeaderData::getColumnType));
+                columnFilters.forEach(column -> {
+                    validateRequestParamsSearch(column.getColumnName(), 
column.getColumnValue(), column.getColumnOperation(), resultColumn,
+                            dataTableColumnMap);
+                });
+
+                AtomicInteger count = new AtomicInteger(0);
+
+                // Attach the selection
+                StringBuilder sqlBuilder = new StringBuilder();
+                if (databaseTypeResolver.isPostgreSQL()) {
+                    sqlBuilder.append("SELECT 
").append(escapeFieldNames(resultColumn)).append(" FROM ")
+                            .append(sqlGenerator.escape(datatable));
+                } else if (databaseTypeResolver.isMySQL()) {
+                    sqlBuilder.append("SELECT ").append(resultColumn).append(" 
FROM ").append(datatable);
+                } else {
+                    throw new IllegalStateException("Database type is not 
supported");
+                }
+
+                // Build base query with filters but without the selection
+                String baseFilterQuery = 
buildBaseQueryWithFilters(columnFilters, dataTableColumnMap, count);
+
+                // Attach the count selection
+                StringBuilder countQueryBuilder = new StringBuilder();
+                countQueryBuilder.append(" SELECT COUNT(*) FROM 
").append(datatable);
+
+                // Attach the WHERE clause
+                if (baseFilterQuery.length() > 0) {
+                    sqlBuilder.append(" WHERE ").append(baseFilterQuery);
+                    countQueryBuilder.append(" WHERE 
").append(baseFilterQuery);
+                }
+
+                // Attach the ORDER
+                attachOrdering(sqlBuilder, pageable.getSort());
+                // Attach the PAGINATION
+                applyPagination(sqlBuilder, pageable);
+
+                SqlRowSet rowSet = 
jdbcTemplate.queryForRowSet(sqlBuilder.toString());
+
+                // Execute the count Query
+                
totalElements.set(jdbcTemplate.queryForObject(countQueryBuilder.toString(), 
Integer.class));
+                String[] resultColumnNames = resultColumn.split(",");
+
+                while (rowSet.next()) {
+                    extractResults(rowSet, resultColumnNames, results);
+                }
+
+            }
+        }
+        return PageableExecutionUtils.getPage(results, pageable, () -> 
totalElements.get());
+
+    }
+
+    private void applyPagination(StringBuilder query, Pageable pageable) {
+        if (pageable.isPaged()) {
+            query.append(sqlGenerator.limit(pageable.getPageSize(), (int) 
pageable.getOffset()));
+        } else {
+            query.append(sqlGenerator.limit(pageable.getPageSize()));
+        }
+
+    }
+
+    private void attachOrdering(StringBuilder query, Sort sort) {
+        if (sort.isSorted()) {
+            query.append(buildOrderByClause(sort.toList()));
+        }
+    }
+
+    private String buildOrderByClause(List<Order> orders) {
+        return orders.stream().map(order -> String.join(" ", 
order.getProperty(), order.getDirection().name()))
+                .collect(Collectors.joining(", "));
+    }
+
+    private String buildBaseQueryWithFilters(List<ColumnFilter> columnFilters, 
Map<String, String> dataTableColumnMap,
+            AtomicInteger count) {
+        StringBuilder queryColumnBuilder = new StringBuilder();
+        columnFilters.forEach(column -> {
+
+            String columnName;
+            Object valueFilter;
+            String columnType;
+
+            if (databaseTypeResolver.isPostgreSQL()) {
+                columnName = escapeFieldNames(column.getColumnName());
+                columnType = dataTableColumnMap.get(columnName);
+                valueFilter = callFilteredPgSqlSearch(column.getColumnValue(), 
columnType);
+            } else {
+                columnName = column.getColumnName();
+                columnType = dataTableColumnMap.get(columnName);
+                valueFilter = callFilteredMysqlSearch(column.getColumnValue(), 
columnType);
+            }
+
+            if ("EQUALS".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%s' ", 
columnName, "=", valueFilter));
+            } else if 
("NOTEQUALS".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%s' ", 
columnName, "<>", valueFilter));
+            } else if 
("CONTAINS".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%%%s%%' ", 
columnName, "LIKE", valueFilter));
+            } else if 
("NOTCONTAINS".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%%%s%%' ", 
columnName, "NOT LIKE", valueFilter));
+            } else if ("GTE".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%s' ", 
columnName, ">=", valueFilter));
+            } else if ("LTE".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%s' ", 
columnName, "<=", valueFilter));
+            } else if ("GT".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%s' ", 
column.getColumnName(), ">", valueFilter));
+            } else if ("LT".equalsIgnoreCase(column.getColumnOperation())) {
+                queryColumnBuilder.append(String.format(" %s %s '%s' ", 
columnName, "<", valueFilter));
+            }
+            if (count.get() < columnFilters.size() - 1) {
+                queryColumnBuilder.append(" AND ");
+                count.getAndIncrement();
+            }
+        });
+        return queryColumnBuilder.toString();

Review Comment:
   No need to convert to string... it will be appended to a StringBuilder 
anyway..



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to