Commit f1d90f3
committed
feat(ci): add staabm/phpstan-dba to type-check raw SQL (#1100)
Wires phpstan-dba into the existing PHPStan gate so column renames,
schema drift, and statement-syntax bugs in `Database::query(...)` calls
fail static analysis instead of waiting for runtime. The CI job spins up
schema-only MariaDB, renders `web/install/includes/sql/struc.sql` the
same way `docker/db-init/00-render-schema.sh` does locally, and points
the bootstrap at it. `DBA_REQUIRE=1` keeps the gate from silently
disabling itself on a creds drift.
The project's `:prefix_<table>` placeholder convention is handled by
`SbppPrefixAwareReflector` (resolves `:prefix` -> `sb` before the SQL
hits MariaDB) and `SbppSyntaxErrorInQueryMethodRule` (replacement for
phpstan-dba's built-in rule, which short-circuits on placeholder
counting and would skip every query in this codebase). Bound values
live in follow-up `bind()` calls out of scope, so we stub `:name` and
`?` placeholders with neutral literals and validate structure only —
table/column existence and SQL syntax — which is the bug class the
issue calls out.
Surfaced and fixed one shipped bug along the way: `Log.php`'s
`case "date":` arm was building `... AND l.created :valueOther`,
missing the comparison operator, so the admin log page threw
SQLSTATE 42000 whenever someone filtered by date. The new rule
flags it as a syntax error; the fix is a one-character `<`.
Disable locally with `PHPSTAN_DBA_DISABLE=1`. Bootstrap also
soft-fails if the DB is unreachable so a fresh checkout without
`./sbpp.sh up` keeps working.1 parent c7793c4 commit f1d90f3
11 files changed
Lines changed: 875 additions & 7 deletions
File tree
- .github/workflows
- docker
- web
- includes
- phpstan
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
22 | 43 | | |
23 | 44 | | |
24 | 45 | | |
25 | 46 | | |
26 | 47 | | |
27 | 48 | | |
28 | 49 | | |
29 | | - | |
| 50 | + | |
30 | 51 | | |
31 | 52 | | |
32 | 53 | | |
| |||
44 | 65 | | |
45 | 66 | | |
46 | 67 | | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
47 | 93 | | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
48 | 106 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
70 | 99 | | |
71 | 100 | | |
72 | 101 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
83 | 83 | | |
84 | 84 | | |
85 | 85 | | |
86 | | - | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
87 | 99 | | |
88 | 100 | | |
89 | 101 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
37 | 40 | | |
38 | 41 | | |
39 | | - | |
| 42 | + | |
| 43 | + | |
40 | 44 | | |
41 | 45 | | |
42 | 46 | | |
| |||
0 commit comments