• Resolved Horacio Figarella

    (@hfigarella)


    Hi LazyCoders team,

    Found in 1.7.63, and still present in SVN trunk:
    src/Controller/v3/Lazytask_ProjectController.php

    Two methods guard their input like this:

    php<br><br>// getProjectMembers(), line 379<br><br>if ($projectsId == '') {<br><br>// getProjectInvitedMembers(), line 3131<br><br>if ($projectsId == '') { return &#091;]; }<br><br>

    Since PHP 8, &#091;] == '' is **false**, so an empty array gets past the guard. The code then runs implode(', ', array_fill(0, 0, '%s')), which gives '', and the query ends in WHERE projectMembers.project_id IN (). That is a MySQL syntax error, logged as WordPress database error You have an error in your SQL syntax ... near ')'. We saw it about 10 times a day in our PHP error log before patching.

    getNoOfTasksByProject() (line 3177) already handles this correctly with a second check:

    php<br><br>if ($projectsId == '') { return &#091;]; }<br><br>if (is_array($projectsId) && sizeof($projectsId) == 0) { return &#091;]; }<br><br>

    **Suggested fix:** the same guard in the other two methods, or simply:

    php<br><br>if (empty($projectsId)) { return &#091;]; }<br><br>

    (empty() covers '', null and &#091;]. A project id of 0/'0' is not a valid id here anyway.)

    We've been running the empty() version on 12 sites (PHP 8.4 and 8.5) since 2026-09-18 with no side effects. It would be great to have it upstream so we can drop our local patch.

    Environment: WordPress 7.2-alpha (nightly), PHP 8.4.25 / 8.5.11, LazyTasks 1.7.63 plus premium, timetracker and whiteboard add-ons.

    Thanks!
Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Contributor Noor Khan

    (@nmkhan)

    Hi,

    Thank you for this. It’s one of the most useful reports we’ve received: exact file and line numbers, the root cause, a suggested fix, and a week of testing on 12 sites. That made it quick to act on.

    You’re right about the cause. Since PHP 8, [] == '' evaluates to false, so an empty array got past the guard in getProjectMembers() and getProjectInvitedMembers(), and the query ended with IN ().

    The fix is in LazyTasks 1.7.67, which goes out today. We also checked the rest of the codebase for the same pattern. Other lookups that build an IN() list from an array of IDs (projects, members, users, companies, and tasks) now use the same empty-input guard, so this error shouldn’t come up anywhere else.

    After you update, you can remove your local patch. If anything similar shows up in your logs on PHP 8.4 or 8.5, please send it over and we’ll look into it.

    Would you be okay with us thanking you in the community post? We can keep it anonymous if you’d rather.

    Thanks again, and happy tasking!
    The LazyCoders Team

    Thread Starter Horacio Figarella

    (@hfigarella)

    Thanks for the quick fix in 1.7.67! Yes, you’re welcome to mention me by name (Horacio Figarella). Happy to keep reporting anything else we find on PHP 8.4/8.5.

    Plugin Contributor Noor Khan

    (@nmkhan)

    Thanks so much. We will greatly appreciate if you leave a review for us.

Viewing 3 replies - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.