Empty array in getProjectMembers() causes SQL error IN ()
-
Hi LazyCoders team,
Found in 1.7.63, and still present in SVN trunk:src/Controller/v3/Lazytask_ProjectController.php
Two methods guard their input like this:php<br><br>// getProjectMembers(), line 379<br><br>if ($projectsId == '') {<br><br>// getProjectInvitedMembers(), line 3131<br><br>if ($projectsId == '') { return []; }<br><br>
Since PHP 8,[] == ''is **false**, so an empty array gets past the guard. The code then runsimplode(', ', array_fill(0, 0, '%s')), which gives'', and the query ends inWHERE projectMembers.project_id IN (). That is a MySQL syntax error, logged asWordPress database error You have an error in your SQL syntax ... near ')'. We saw it about 10 times a day in our PHP error log before patching.getNoOfTasksByProject()(line 3177) already handles this correctly with a second check:php<br><br>if ($projectsId == '') { return []; }<br><br>if (is_array($projectsId) && sizeof($projectsId) == 0) { return []; }<br><br>
**Suggested fix:** the same guard in the other two methods, or simply:php<br><br>if (empty($projectsId)) { return []; }<br><br>
(empty()covers'',nulland[]. A project id of0/'0'is not a valid id here anyway.)
We've been running theempty()version on 12 sites (PHP 8.4 and 8.5) since 2026-09-18 with no side effects. It would be great to have it upstream so we can drop our local patch.
Environment: WordPress 7.2-alpha (nightly), PHP 8.4.25 / 8.5.11, LazyTasks 1.7.63 plus premium, timetracker and whiteboard add-ons.
Thanks!
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
You must be logged in to reply to this topic.