]> git.evergreen-ils.org Git - Evergreen.git/blob - Open-ILS/src/c-apps/oils_cstore.c
searchJOIN() was segfaulting when the FROM clause was of
[Evergreen.git] / Open-ILS / src / c-apps / oils_cstore.c
1 #include "opensrf/osrf_application.h"
2 #include "opensrf/osrf_settings.h"
3 #include "opensrf/osrf_message.h"
4 #include "opensrf/utils.h"
5 #include "opensrf/osrf_json.h"
6 #include "opensrf/log.h"
7 #include "openils/oils_utils.h"
8 #include <dbi/dbi.h>
9
10 #include <time.h>
11 #include <stdlib.h>
12 #include <string.h>
13 #include <unistd.h>
14
15 #ifdef RSTORE
16 #  define MODULENAME "open-ils.reporter-store"
17 #else
18 #  ifdef PCRUD
19 #    define MODULENAME "open-ils.pcrud"
20 #  else
21 #    define MODULENAME "open-ils.cstore"
22 #  endif
23 #endif
24
25 #define SUBSELECT       4
26 #define DISABLE_I18N    2
27 #define SELECT_DISTINCT 1
28 #define AND_OP_JOIN     0
29 #define OR_OP_JOIN      1
30
31 int osrfAppChildInit();
32 int osrfAppInitialize();
33 void osrfAppChildExit();
34
35 static int verifyObjectClass ( osrfMethodContext*, const jsonObject* );
36
37 int beginTransaction ( osrfMethodContext* );
38 int commitTransaction ( osrfMethodContext* );
39 int rollbackTransaction ( osrfMethodContext* );
40
41 int setSavepoint ( osrfMethodContext* );
42 int releaseSavepoint ( osrfMethodContext* );
43 int rollbackSavepoint ( osrfMethodContext* );
44
45 int doJSONSearch ( osrfMethodContext* );
46
47 int dispatchCRUDMethod ( osrfMethodContext* );
48 static jsonObject* doCreate ( osrfMethodContext*, int* );
49 static jsonObject* doRetrieve ( osrfMethodContext*, int* );
50 static jsonObject* doUpdate ( osrfMethodContext*, int* );
51 static jsonObject* doDelete ( osrfMethodContext*, int* );
52 static jsonObject* doFieldmapperSearch ( osrfMethodContext*, osrfHash*,
53         const jsonObject*, int* );
54 static jsonObject* oilsMakeFieldmapperFromResult( dbi_result, osrfHash* );
55 static jsonObject* oilsMakeJSONFromResult( dbi_result );
56
57 static char* searchWriteSimplePredicate ( const char*, osrfHash*,
58         const char*, const char*, const char* );
59 static char* searchSimplePredicate ( const char*, const char*, osrfHash*, const jsonObject* );
60 static char* searchFunctionPredicate ( const char*, osrfHash*, const jsonObject*, const char* );
61 static char* searchFieldTransform ( const char*, osrfHash*, const jsonObject*);
62 static char* searchFieldTransformPredicate ( const char*, osrfHash*, jsonObject*, const char* );
63 static char* searchBETWEENPredicate ( const char*, osrfHash*, jsonObject* );
64 static char* searchINPredicate ( const char*, osrfHash*,
65                                                                  jsonObject*, const char*, osrfMethodContext* );
66 static char* searchPredicate ( const char*, osrfHash*, jsonObject*, osrfMethodContext* );
67 static char* searchJOIN ( const jsonObject*, osrfHash* );
68 static char* searchWHERE ( const jsonObject*, osrfHash*, int, osrfMethodContext* );
69 static char* buildSELECT ( jsonObject*, jsonObject*, osrfHash*, osrfMethodContext* );
70
71 char* SELECT ( osrfMethodContext*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, int );
72
73 void userDataFree( void* );
74 static void sessionDataFree( char*, void* );
75 static char* getSourceDefinition( osrfHash* );
76 static int str_is_true( const char* str );
77 static int obj_is_true( const jsonObject* obj );
78
79 #ifdef PCRUD
80 static jsonObject* verifyUserPCRUD( osrfMethodContext* );
81 static int verifyObjectPCRUD( osrfMethodContext*, const jsonObject* );
82 #endif
83
84 static dbi_conn writehandle; /* our MASTER db connection */
85 static dbi_conn dbhandle; /* our CURRENT db connection */
86 //static osrfHash * readHandles;
87 static jsonObject* jsonNULL = NULL; // 
88 static int max_flesh_depth = 100;
89
90 /* called when this process is about to exit */
91 void osrfAppChildExit() {
92     osrfLogDebug(OSRF_LOG_MARK, "Child is exiting, disconnecting from database...");
93
94     int same = 0;
95     if (writehandle == dbhandle) same = 1;
96     if (writehandle) {
97         dbi_conn_query(writehandle, "ROLLBACK;");
98         dbi_conn_close(writehandle);
99         writehandle = NULL;
100     }
101     if (dbhandle && !same)
102         dbi_conn_close(dbhandle);
103
104     // XXX add cleanup of readHandles whenever that gets used
105
106     return;
107 }
108
109 int osrfAppInitialize() {
110
111     osrfLogInfo(OSRF_LOG_MARK, "Initializing the CStore Server...");
112     osrfLogInfo(OSRF_LOG_MARK, "Finding XML file...");
113
114     if (!oilsIDLInit( osrf_settings_host_value("/IDL") )) return 1; /* return non-zero to indicate error */
115
116     growing_buffer* method_name = buffer_init(64);
117 #ifndef PCRUD
118     // Generic search thingy
119     buffer_add(method_name, MODULENAME);
120         buffer_add(method_name, ".json_query");
121         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
122                                                    "doJSONSearch", "", 1, OSRF_METHOD_STREAMING );
123 #endif
124
125     // first we register all the transaction and savepoint methods
126     buffer_reset(method_name);
127         OSRF_BUFFER_ADD(method_name, MODULENAME);
128         OSRF_BUFFER_ADD(method_name, ".transaction.begin");
129         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
130                                                    "beginTransaction", "", 0, 0 );
131
132     buffer_reset(method_name);
133         OSRF_BUFFER_ADD(method_name, MODULENAME);
134         OSRF_BUFFER_ADD(method_name, ".transaction.commit");
135         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
136                                                    "commitTransaction", "", 0, 0 );
137
138     buffer_reset(method_name);
139         OSRF_BUFFER_ADD(method_name, MODULENAME);
140         OSRF_BUFFER_ADD(method_name, ".transaction.rollback");
141         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
142                                                    "rollbackTransaction", "", 0, 0 );
143
144     buffer_reset(method_name);
145         OSRF_BUFFER_ADD(method_name, MODULENAME);
146         OSRF_BUFFER_ADD(method_name, ".savepoint.set");
147         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
148                                                    "setSavepoint", "", 1, 0 );
149
150     buffer_reset(method_name);
151         OSRF_BUFFER_ADD(method_name, MODULENAME);
152         OSRF_BUFFER_ADD(method_name, ".savepoint.release");
153         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
154                                                    "releaseSavepoint", "", 1, 0 );
155
156     buffer_reset(method_name);
157         OSRF_BUFFER_ADD(method_name, MODULENAME);
158         OSRF_BUFFER_ADD(method_name, ".savepoint.rollback");
159         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
160                                                    "rollbackSavepoint", "", 1, 0 );
161
162     buffer_free(method_name);
163
164         static const char* global_method[] = {
165                 "create",
166                 "retrieve",
167                 "update",
168                 "delete",
169                 "search",
170                 "id_list"
171         };
172         const int global_method_count
173                 = sizeof( global_method ) / sizeof ( global_method[0] );
174         
175     int c_index = 0; 
176     char* classname;
177     osrfStringArray* classes = osrfHashKeys( oilsIDL() );
178     osrfLogDebug(OSRF_LOG_MARK, "%d classes loaded", classes->size );
179     osrfLogDebug(OSRF_LOG_MARK,
180                 "At least %d methods will be generated", classes->size * global_method_count);
181
182     while ( (classname = osrfStringArrayGetString(classes, c_index++)) ) {
183         osrfLogInfo(OSRF_LOG_MARK, "Generating class methods for %s", classname);
184
185         osrfHash* idlClass = osrfHashGet(oilsIDL(), classname);
186
187         if (!osrfStringArrayContains( osrfHashGet(idlClass, "controller"), MODULENAME )) {
188             osrfLogInfo(OSRF_LOG_MARK, "%s is not listed as a controller for %s, moving on", MODULENAME, classname);
189             continue;
190         }
191
192                 if ( str_is_true( osrfHashGet(idlClass, "virtual") ) ) {
193                         osrfLogDebug(OSRF_LOG_MARK, "Class %s is virtual, skipping", classname );
194                         continue;
195                 }
196
197         // Look up some other attributes of the current class
198         const char* idlClass_fieldmapper = osrfHashGet(idlClass, "fieldmapper");
199                 const char* readonly = osrfHashGet(idlClass, "readonly");
200 #ifdef PCRUD
201         osrfHash* idlClass_permacrud = osrfHashGet(idlClass, "permacrud");
202 #endif
203
204         int i;
205         for( i = 0; i < global_method_count; ++i ) {
206             const char* method_type = global_method[ i ];
207             osrfLogDebug(OSRF_LOG_MARK,
208                 "Using files to build %s class methods for %s", method_type, classname);
209
210             if (!idlClass_fieldmapper) continue;
211
212 #ifdef PCRUD
213             if (!idlClass_permacrud) continue;
214
215             const char* tmp_method = method_type;
216             if ( *tmp_method == 'i' || *tmp_method == 's') {
217                 tmp_method = "retrieve";
218             }
219             if (!osrfHashGet( idlClass_permacrud, tmp_method )) continue;
220 #endif
221
222             if (    str_is_true( readonly ) &&
223                     ( *method_type == 'c' || *method_type == 'u' || *method_type == 'd')
224                ) continue;
225
226             osrfHash* method_meta = osrfNewHash();
227             osrfHashSet(method_meta, idlClass, "class");
228
229             method_name =  buffer_init(64);
230 #ifdef PCRUD
231             buffer_fadd(method_name, "%s.%s.%s", MODULENAME, method_type, classname);
232 #else
233             char* st_tmp = NULL;
234             char* part = NULL;
235             char* _fm = strdup( idlClass_fieldmapper );
236             part = strtok_r(_fm, ":", &st_tmp);
237
238             buffer_fadd(method_name, "%s.direct.%s", MODULENAME, part);
239
240             while ((part = strtok_r(NULL, ":", &st_tmp))) {
241                                 OSRF_BUFFER_ADD_CHAR(method_name, '.');
242                                 OSRF_BUFFER_ADD(method_name, part);
243             }
244                         OSRF_BUFFER_ADD_CHAR(method_name, '.');
245                         OSRF_BUFFER_ADD(method_name, method_type);
246             free(_fm);
247 #endif
248
249             char* method = buffer_release(method_name);
250
251             osrfHashSet( method_meta, method, "methodname" );
252             osrfHashSet( method_meta, strdup(method_type), "methodtype" );
253
254             int flags = 0;
255             if (*method_type == 'i' || *method_type == 's') {
256                 flags = flags | OSRF_METHOD_STREAMING;
257             }
258
259             osrfAppRegisterExtendedMethod(
260                     MODULENAME,
261                     method,
262                     "dispatchCRUDMethod",
263                     "",
264                     1,
265                     flags,
266                     (void*)method_meta
267                     );
268
269             free(method);
270         }
271     }
272
273     return 0;
274 }
275
276 static char* getSourceDefinition( osrfHash* class ) {
277
278     char* tabledef = osrfHashGet(class, "tablename");
279
280     if (!tabledef) {
281         growing_buffer* tablebuf = buffer_init(128);
282         tabledef = osrfHashGet(class, "source_definition");
283         if( !tabledef )
284             tabledef = "(null)";
285         buffer_fadd( tablebuf, "(%s)", tabledef );
286         tabledef = buffer_release(tablebuf);
287     } else {
288         tabledef = strdup(tabledef);
289     }
290
291     return tabledef;
292 }
293
294 /**
295  * Connects to the database 
296  */
297 int osrfAppChildInit() {
298
299     osrfLogDebug(OSRF_LOG_MARK, "Attempting to initialize libdbi...");
300     dbi_initialize(NULL);
301     osrfLogDebug(OSRF_LOG_MARK, "... libdbi initialized.");
302
303     char* driver        = osrf_settings_host_value("/apps/%s/app_settings/driver", MODULENAME);
304     char* user  = osrf_settings_host_value("/apps/%s/app_settings/database/user", MODULENAME);
305     char* host  = osrf_settings_host_value("/apps/%s/app_settings/database/host", MODULENAME);
306     char* port  = osrf_settings_host_value("/apps/%s/app_settings/database/port", MODULENAME);
307     char* db    = osrf_settings_host_value("/apps/%s/app_settings/database/db", MODULENAME);
308     char* pw    = osrf_settings_host_value("/apps/%s/app_settings/database/pw", MODULENAME);
309     char* md    = osrf_settings_host_value("/apps/%s/app_settings/max_query_recursion", MODULENAME);
310
311     osrfLogDebug(OSRF_LOG_MARK, "Attempting to load the database driver [%s]...", driver);
312     writehandle = dbi_conn_new(driver);
313
314     if(!writehandle) {
315         osrfLogError(OSRF_LOG_MARK, "Error loading database driver [%s]", driver);
316         return -1;
317     }
318     osrfLogDebug(OSRF_LOG_MARK, "Database driver [%s] seems OK", driver);
319
320     osrfLogInfo(OSRF_LOG_MARK, "%s connecting to database.  host=%s, "
321             "port=%s, user=%s, pw=%s, db=%s", MODULENAME, host, port, user, pw, db );
322
323     if(host) dbi_conn_set_option(writehandle, "host", host );
324     if(port) dbi_conn_set_option_numeric( writehandle, "port", atoi(port) );
325     if(user) dbi_conn_set_option(writehandle, "username", user);
326     if(pw) dbi_conn_set_option(writehandle, "password", pw );
327     if(db) dbi_conn_set_option(writehandle, "dbname", db );
328
329     if(md) max_flesh_depth = atoi(md);
330     if(max_flesh_depth < 0) max_flesh_depth = 1;
331     if(max_flesh_depth > 1000) max_flesh_depth = 1000;
332
333     free(user);
334     free(host);
335     free(port);
336     free(db);
337     free(pw);
338
339     const char* err;
340     if (dbi_conn_connect(writehandle) < 0) {
341         sleep(1);
342         if (dbi_conn_connect(writehandle) < 0) {
343             dbi_conn_error(writehandle, &err);
344             osrfLogError( OSRF_LOG_MARK, "Error connecting to database: %s", err);
345             return -1;
346         }
347     }
348
349     osrfLogInfo(OSRF_LOG_MARK, "%s successfully connected to the database", MODULENAME);
350
351     int attr;
352     unsigned short type;
353     int i = 0; 
354     char* classname;
355     osrfStringArray* classes = osrfHashKeys( oilsIDL() );
356
357     while ( (classname = osrfStringArrayGetString(classes, i++)) ) {
358         osrfHash* class = osrfHashGet( oilsIDL(), classname );
359         osrfHash* fields = osrfHashGet( class, "fields" );
360
361                 if( str_is_true( osrfHashGet(class, "virtual") ) ) {
362                         osrfLogDebug(OSRF_LOG_MARK, "Class %s is virtual, skipping", classname );
363                         continue;
364                 }
365
366         char* tabledef = getSourceDefinition(class);
367
368         growing_buffer* sql_buf = buffer_init(32);
369         buffer_fadd( sql_buf, "SELECT * FROM %s AS x WHERE 1=0;", tabledef );
370
371         free(tabledef);
372
373         char* sql = buffer_release(sql_buf);
374         osrfLogDebug(OSRF_LOG_MARK, "%s Investigatory SQL = %s", MODULENAME, sql);
375
376         dbi_result result = dbi_conn_query(writehandle, sql);
377         free(sql);
378
379         if (result) {
380
381             int columnIndex = 1;
382             const char* columnName;
383             osrfHash* _f;
384             while( (columnName = dbi_result_get_field_name(result, columnIndex++)) ) {
385
386                 osrfLogInternal(OSRF_LOG_MARK, "Looking for column named [%s]...", (char*)columnName);
387
388                 /* fetch the fieldmapper index */
389                 if( (_f = osrfHashGet(fields, (char*)columnName)) ) {
390
391                     osrfLogDebug(OSRF_LOG_MARK, "Found [%s] in IDL hash...", (char*)columnName);
392
393                     /* determine the field type and storage attributes */
394                     type = dbi_result_get_field_type(result, columnName);
395                     attr = dbi_result_get_field_attribs(result, columnName);
396
397                     switch( type ) {
398
399                         case DBI_TYPE_INTEGER :
400
401                             if ( !osrfHashGet(_f, "primitive") )
402                                 osrfHashSet(_f,"number", "primitive");
403
404                             if( attr & DBI_INTEGER_SIZE8 ) 
405                                 osrfHashSet(_f,"INT8", "datatype");
406                             else 
407                                 osrfHashSet(_f,"INT", "datatype");
408                             break;
409
410                         case DBI_TYPE_DECIMAL :
411                             if ( !osrfHashGet(_f, "primitive") )
412                                 osrfHashSet(_f,"number", "primitive");
413
414                             osrfHashSet(_f,"NUMERIC", "datatype");
415                             break;
416
417                         case DBI_TYPE_STRING :
418                             if ( !osrfHashGet(_f, "primitive") )
419                                 osrfHashSet(_f,"string", "primitive");
420                             osrfHashSet(_f,"TEXT", "datatype");
421                             break;
422
423                         case DBI_TYPE_DATETIME :
424                             if ( !osrfHashGet(_f, "primitive") )
425                                 osrfHashSet(_f,"string", "primitive");
426
427                             osrfHashSet(_f,"TIMESTAMP", "datatype");
428                             break;
429
430                         case DBI_TYPE_BINARY :
431                             if ( !osrfHashGet(_f, "primitive") )
432                                 osrfHashSet(_f,"string", "primitive");
433
434                             osrfHashSet(_f,"BYTEA", "datatype");
435                     }
436
437                     osrfLogDebug(
438                             OSRF_LOG_MARK,
439                             "Setting [%s] to primitive [%s] and datatype [%s]...",
440                             (char*)columnName,
441                             osrfHashGet(_f, "primitive"),
442                             osrfHashGet(_f, "datatype")
443                             );
444                 }
445             }
446             dbi_result_free(result);
447         } else {
448             osrfLogDebug(OSRF_LOG_MARK, "No data found for class [%s]...", (char*)classname);
449         }
450     }
451
452     osrfStringArrayFree(classes);
453
454     return 0;
455 }
456
457 void userDataFree( void* blob ) {
458     osrfHashFree( (osrfHash*)blob );
459     return;
460 }
461
462 static void sessionDataFree( char* key, void* item ) {
463     if (!(strcmp(key,"xact_id"))) {
464         if (writehandle)
465             dbi_conn_query(writehandle, "ROLLBACK;");
466         free(item);
467     }
468
469     return;
470 }
471
472 int beginTransaction ( osrfMethodContext* ctx ) {
473         if(osrfMethodVerifyContext( ctx )) {
474                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
475                 return -1;
476         }
477
478 #ifdef PCRUD
479     jsonObject* user = verifyUserPCRUD( ctx );
480     if (!user) return -1;
481     jsonObjectFree(user);
482 #endif
483
484     dbi_result result = dbi_conn_query(writehandle, "START TRANSACTION;");
485     if (!result) {
486         osrfLogError(OSRF_LOG_MARK, "%s: Error starting transaction", MODULENAME );
487         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error starting transaction" );
488         return -1;
489     } else {
490         jsonObject* ret = jsonNewObject(ctx->session->session_id);
491         osrfAppRespondComplete( ctx, ret );
492         jsonObjectFree(ret);
493
494         if (!ctx->session->userData) {
495             ctx->session->userData = osrfNewHash();
496             osrfHashSetCallback((osrfHash*)ctx->session->userData, &sessionDataFree);
497         }
498
499         osrfHashSet( (osrfHash*)ctx->session->userData, strdup( ctx->session->session_id ), "xact_id" );
500         ctx->session->userDataFree = &userDataFree;
501
502     }
503     return 0;
504 }
505
506 int setSavepoint ( osrfMethodContext* ctx ) {
507         if(osrfMethodVerifyContext( ctx )) {
508                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
509                 return -1;
510         }
511
512     int spNamePos = 0;
513 #ifdef PCRUD
514     spNamePos = 1;
515     jsonObject* user = verifyUserPCRUD( ctx );
516     if (!user) return -1;
517     jsonObjectFree(user);
518 #endif
519
520     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
521         osrfAppSessionStatus(
522                 ctx->session,
523                 OSRF_STATUS_INTERNALSERVERERROR,
524                 "osrfMethodException",
525                 ctx->request,
526                 "No active transaction -- required for savepoints"
527                 );
528         return -1;
529     }
530
531     char* spName = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, spNamePos));
532
533     dbi_result result = dbi_conn_queryf(writehandle, "SAVEPOINT \"%s\";", spName);
534     if (!result) {
535         osrfLogError(
536                 OSRF_LOG_MARK,
537                 "%s: Error creating savepoint %s in transaction %s",
538                 MODULENAME,
539                 spName,
540                 osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )
541                 );
542         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error creating savepoint" );
543         free(spName);
544         return -1;
545     } else {
546         jsonObject* ret = jsonNewObject(spName);
547         osrfAppRespondComplete( ctx, ret );
548         jsonObjectFree(ret);
549     }
550     free(spName);
551     return 0;
552 }
553
554 int releaseSavepoint ( osrfMethodContext* ctx ) {
555         if(osrfMethodVerifyContext( ctx )) {
556                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
557                 return -1;
558         }
559
560         int spNamePos = 0;
561 #ifdef PCRUD
562     spNamePos = 1;
563     jsonObject* user = verifyUserPCRUD( ctx );
564     if (!user) return -1;
565     jsonObjectFree(user);
566 #endif
567
568     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
569         osrfAppSessionStatus(
570                 ctx->session,
571                 OSRF_STATUS_INTERNALSERVERERROR,
572                 "osrfMethodException",
573                 ctx->request,
574                 "No active transaction -- required for savepoints"
575                 );
576         return -1;
577     }
578
579     char* spName = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, spNamePos));
580
581     dbi_result result = dbi_conn_queryf(writehandle, "RELEASE SAVEPOINT \"%s\";", spName);
582     if (!result) {
583         osrfLogError(
584                 OSRF_LOG_MARK,
585                 "%s: Error releasing savepoint %s in transaction %s",
586                 MODULENAME,
587                 spName,
588                 osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )
589                 );
590         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error releasing savepoint" );
591         free(spName);
592         return -1;
593     } else {
594         jsonObject* ret = jsonNewObject(spName);
595         osrfAppRespondComplete( ctx, ret );
596         jsonObjectFree(ret);
597     }
598     free(spName);
599     return 0;
600 }
601
602 int rollbackSavepoint ( osrfMethodContext* ctx ) {
603         if(osrfMethodVerifyContext( ctx )) {
604                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
605                 return -1;
606         }
607
608         int spNamePos = 0;
609 #ifdef PCRUD
610     spNamePos = 1;
611     jsonObject* user = verifyUserPCRUD( ctx );
612     if (!user) return -1;
613     jsonObjectFree(user);
614 #endif
615
616     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
617         osrfAppSessionStatus(
618                 ctx->session,
619                 OSRF_STATUS_INTERNALSERVERERROR,
620                 "osrfMethodException",
621                 ctx->request,
622                 "No active transaction -- required for savepoints"
623                 );
624         return -1;
625     }
626
627     char* spName = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, spNamePos));
628
629     dbi_result result = dbi_conn_queryf(writehandle, "ROLLBACK TO SAVEPOINT \"%s\";", spName);
630     if (!result) {
631         osrfLogError(
632                 OSRF_LOG_MARK,
633                 "%s: Error rolling back savepoint %s in transaction %s",
634                 MODULENAME,
635                 spName,
636                 osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )
637                 );
638         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error rolling back savepoint" );
639         free(spName);
640         return -1;
641     } else {
642         jsonObject* ret = jsonNewObject(spName);
643         osrfAppRespondComplete( ctx, ret );
644         jsonObjectFree(ret);
645     }
646     free(spName);
647     return 0;
648 }
649
650 int commitTransaction ( osrfMethodContext* ctx ) {
651         if(osrfMethodVerifyContext( ctx )) {
652                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
653                 return -1;
654         }
655
656 #ifdef PCRUD
657     jsonObject* user = verifyUserPCRUD( ctx );
658     if (!user) return -1;
659     jsonObjectFree(user);
660 #endif
661
662     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
663         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "No active transaction to commit" );
664         return -1;
665     }
666
667     dbi_result result = dbi_conn_query(writehandle, "COMMIT;");
668     if (!result) {
669         osrfLogError(OSRF_LOG_MARK, "%s: Error committing transaction", MODULENAME );
670         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error committing transaction" );
671         return -1;
672     } else {
673         osrfHashRemove(ctx->session->userData, "xact_id");
674         jsonObject* ret = jsonNewObject(ctx->session->session_id);
675         osrfAppRespondComplete( ctx, ret );
676         jsonObjectFree(ret);
677     }
678     return 0;
679 }
680
681 int rollbackTransaction ( osrfMethodContext* ctx ) {
682         if(osrfMethodVerifyContext( ctx )) {
683                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
684                 return -1;
685         }
686
687 #ifdef PCRUD
688     jsonObject* user = verifyUserPCRUD( ctx );
689     if (!user) return -1;
690     jsonObjectFree(user);
691 #endif
692
693     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
694         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "No active transaction to roll back" );
695         return -1;
696     }
697
698     dbi_result result = dbi_conn_query(writehandle, "ROLLBACK;");
699     if (!result) {
700         osrfLogError(OSRF_LOG_MARK, "%s: Error rolling back transaction", MODULENAME );
701         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error rolling back transaction" );
702         return -1;
703     } else {
704         osrfHashRemove(ctx->session->userData, "xact_id");
705         jsonObject* ret = jsonNewObject(ctx->session->session_id);
706         osrfAppRespondComplete( ctx, ret );
707         jsonObjectFree(ret);
708     }
709     return 0;
710 }
711
712 int dispatchCRUDMethod ( osrfMethodContext* ctx ) {
713         if(osrfMethodVerifyContext( ctx )) {
714                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
715                 return -1;
716         }
717
718         osrfHash* meta = (osrfHash*) ctx->method->userData;
719     osrfHash* class_obj = osrfHashGet( meta, "class" );
720
721     int err = 0;
722
723     const char* methodtype = osrfHashGet(meta, "methodtype");
724     jsonObject * obj = NULL;
725
726     if (!strcmp(methodtype, "create")) {
727         obj = doCreate(ctx, &err);
728         osrfAppRespondComplete( ctx, obj );
729     }
730     else if (!strcmp(methodtype, "retrieve")) {
731         obj = doRetrieve(ctx, &err);
732         osrfAppRespondComplete( ctx, obj );
733     }
734     else if (!strcmp(methodtype, "update")) {
735         obj = doUpdate(ctx, &err);
736         osrfAppRespondComplete( ctx, obj );
737     }
738     else if (!strcmp(methodtype, "delete")) {
739         obj = doDelete(ctx, &err);
740         osrfAppRespondComplete( ctx, obj );
741     }
742     else if (!strcmp(methodtype, "search")) {
743
744         jsonObject* _p = jsonObjectClone( ctx->params );
745 #ifdef PCRUD
746         jsonObjectFree(_p);
747         _p = jsonParseString("[]");
748         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 1)));
749         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 2)));
750 #endif
751
752         obj = doFieldmapperSearch(ctx, class_obj, _p, &err);
753
754         jsonObjectFree(_p);
755         if(err) return err;
756
757         jsonObject* cur;
758         jsonIterator* itr = jsonNewIterator( obj );
759         while ((cur = jsonIteratorNext( itr ))) {
760 #ifdef PCRUD
761             if(!verifyObjectPCRUD(ctx, cur)) continue;
762 #endif
763             osrfAppRespond( ctx, cur );
764         }
765         jsonIteratorFree(itr);
766         osrfAppRespondComplete( ctx, NULL );
767
768     } else if (!strcmp(methodtype, "id_list")) {
769
770         jsonObject* _p = jsonObjectClone( ctx->params );
771 #ifdef PCRUD
772         jsonObjectFree(_p);
773         _p = jsonParseString("[]");
774         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 1)));
775         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 2)));
776 #endif
777
778         if (jsonObjectGetIndex( _p, 1 )) {
779             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "select" );
780             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "no_i18n" );
781             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "flesh" );
782             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "flesh_columns" );
783         } else {
784             jsonObjectSetIndex( _p, 1, jsonNewObjectType(JSON_HASH) );
785         }
786
787                 jsonObjectSetKey( jsonObjectGetIndex( _p, 1 ), "no_i18n", jsonNewBoolObject( 1 ) );
788
789         jsonObjectSetKey(
790             jsonObjectGetIndex( _p, 1 ),
791             "select",
792             jsonParseStringFmt(
793                 "{ \"%s\":[\"%s\"] }",
794                 osrfHashGet( class_obj, "classname" ),
795                 osrfHashGet( class_obj, "primarykey" )
796             )
797         );
798
799         obj = doFieldmapperSearch(ctx, class_obj, _p, &err);
800
801         jsonObjectFree(_p);
802         if(err) return err;
803
804         jsonObject* cur;
805         jsonIterator* itr = jsonNewIterator( obj );
806         while ((cur = jsonIteratorNext( itr ))) {
807 #ifdef PCRUD
808             if(!verifyObjectPCRUD(ctx, cur)) continue;
809 #endif
810             osrfAppRespond(
811                     ctx,
812                     oilsFMGetObject( cur, osrfHashGet( class_obj, "primarykey" ) )
813                     );
814         }
815         jsonIteratorFree(itr);
816         osrfAppRespondComplete( ctx, NULL );
817
818     } else {
819         osrfAppRespondComplete( ctx, obj );
820     }
821
822     jsonObjectFree(obj);
823
824     return err;
825 }
826
827 static int verifyObjectClass ( osrfMethodContext* ctx, const jsonObject* param ) {
828
829     int ret = 1;
830     osrfHash* meta = (osrfHash*) ctx->method->userData;
831     osrfHash* class = osrfHashGet( meta, "class" );
832
833     if (!param->classname || (strcmp( osrfHashGet(class, "classname"), param->classname ))) {
834
835         growing_buffer* msg = buffer_init(128);
836         buffer_fadd(
837                 msg,
838                 "%s: %s method for type %s was passed a %s",
839                 MODULENAME,
840                 osrfHashGet(meta, "methodtype"),
841                 osrfHashGet(class, "classname"),
842                 param->classname
843                 );
844
845         char* m = buffer_release(msg);
846         osrfAppSessionStatus( ctx->session, OSRF_STATUS_BADREQUEST, "osrfMethodException", ctx->request, m );
847
848         free(m);
849
850         return 0;
851     }
852
853 #ifdef PCRUD
854     ret = verifyObjectPCRUD( ctx, param );
855 #endif
856
857     return ret;
858 }
859
860 #ifdef PCRUD
861
862 static jsonObject* verifyUserPCRUD( osrfMethodContext* ctx ) {
863     char* auth = jsonObjectToSimpleString( jsonObjectGetIndex( ctx->params, 0 ) );
864     jsonObject* auth_object = jsonNewObject(auth);
865     jsonObject* user = oilsUtilsQuickReq("open-ils.auth","open-ils.auth.session.retrieve", auth_object);
866     jsonObjectFree(auth_object);
867
868     if (!user->classname || strcmp(user->classname, "au")) {
869
870         growing_buffer* msg = buffer_init(128);
871         buffer_fadd(
872             msg,
873             "%s: permacrud received a bad auth token: %s",
874             MODULENAME,
875             auth
876         );
877
878         char* m = buffer_release(msg);
879         osrfAppSessionStatus( ctx->session, OSRF_STATUS_UNAUTHORIZED, "osrfMethodException", ctx->request, m );
880
881         free(m);
882         jsonObjectFree(user);
883         user = jsonNULL;
884     }
885
886     free(auth);
887     return user;
888
889 }
890
891 static int verifyObjectPCRUD (  osrfMethodContext* ctx, const jsonObject* obj ) {
892
893     dbhandle = writehandle;
894
895     osrfHash* meta = (osrfHash*) ctx->method->userData;
896     osrfHash* class = osrfHashGet( meta, "class" );
897     char* method_type = strdup( osrfHashGet(meta, "methodtype") );
898     int fetch = 0;
899
900     if ( ( *method_type == 's' || *method_type == 'i' ) ) {
901         free(method_type);
902         method_type = strdup("retrieve"); // search and id_list are equivelant to retrieve for this
903     } else if ( *method_type == 'u' || *method_type == 'd' ) {
904         fetch = 1; // MUST go to the db for the object for update and delete
905     }
906
907     osrfHash* pcrud = osrfHashGet( osrfHashGet(class, "permacrud"), method_type );
908     free(method_type);
909
910     if (!pcrud) {
911         // No permacrud for this method type on this class
912
913         growing_buffer* msg = buffer_init(128);
914         buffer_fadd(
915             msg,
916             "%s: %s on class %s has no permacrud IDL entry",
917             MODULENAME,
918             osrfHashGet(meta, "methodtype"),
919             osrfHashGet(class, "classname")
920         );
921
922         char* m = buffer_release(msg);
923         osrfAppSessionStatus( ctx->session, OSRF_STATUS_FORBIDDEN, "osrfMethodException", ctx->request, m );
924
925         free(m);
926
927         return 0;
928     }
929
930     jsonObject* user = verifyUserPCRUD( ctx );
931     if (!user) return 0;
932
933     int userid = atoi( oilsFMGetString( user, "id" ) );
934     jsonObjectFree(user);
935
936     osrfStringArray* permission = osrfHashGet(pcrud, "permission");
937     osrfStringArray* local_context = osrfHashGet(pcrud, "local_context");
938     osrfHash* foreign_context = osrfHashGet(pcrud, "foreign_context");
939
940     osrfStringArray* context_org_array = osrfNewStringArray(1);
941
942     int err = 0;
943     char* pkey_value = NULL;
944         if ( str_is_true( osrfHashGet(pcrud, "global_required") ) ) {
945             osrfLogDebug( OSRF_LOG_MARK, "global-level permissions required, fetching top of the org tree" );
946
947         // check for perm at top of org tree
948         jsonObject* _tmp_params = jsonParseString("[{\"parent_ou\":null}]");
949                 jsonObject* _list = doFieldmapperSearch(ctx, osrfHashGet( oilsIDL(), "aou" ), _tmp_params, &err);
950
951         jsonObject* _tree_top = jsonObjectGetIndex(_list, 0);
952
953         if (!_tree_top) {
954             jsonObjectFree(_tmp_params);
955             jsonObjectFree(_list);
956     
957             growing_buffer* msg = buffer_init(128);
958                         OSRF_BUFFER_ADD( msg, MODULENAME );
959                         OSRF_BUFFER_ADD( msg,
960                                 ": Internal error, could not find the top of the org tree (parent_ou = NULL)" );
961     
962             char* m = buffer_release(msg);
963             osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, m );
964             free(m);
965
966             return 0;
967         }
968
969         osrfStringArrayAdd( context_org_array, oilsFMGetString( _tree_top, "id" ) );
970             osrfLogDebug( OSRF_LOG_MARK, "top of the org tree is %s", osrfStringArrayGetString(context_org_array, 0) );
971
972         jsonObjectFree(_tmp_params);
973         jsonObjectFree(_list);
974
975     } else {
976             osrfLogDebug( OSRF_LOG_MARK, "global-level permissions not required, fetching context org ids" );
977             char* pkey = osrfHashGet(class, "primarykey");
978         jsonObject *param = NULL;
979
980         if (obj->classname) {
981             pkey_value = oilsFMGetString( obj, pkey );
982             if (!fetch) param = jsonObjectClone(obj);
983                 osrfLogDebug( OSRF_LOG_MARK, "Object supplied, using primary key value of %s", pkey_value );
984         } else {
985             pkey_value = jsonObjectToSimpleString( obj );
986             fetch = 1;
987                 osrfLogDebug( OSRF_LOG_MARK, "Object not supplied, using primary key value of %s and retrieving from the database", pkey_value );
988         }
989
990         if (fetch) {
991             jsonObject* _tmp_params = jsonParseStringFmt("[{\"%s\":\"%s\"}]", pkey, pkey_value);
992                 jsonObject* _list = doFieldmapperSearch(
993                 ctx,
994                 class,
995                 _tmp_params,
996                 &err
997             );
998     
999             param = jsonObjectClone(jsonObjectGetIndex(_list, 0));
1000     
1001             jsonObjectFree(_tmp_params);
1002             jsonObjectFree(_list);
1003         }
1004
1005         if (!param) {
1006             osrfLogDebug( OSRF_LOG_MARK, "Object not found in the database with primary key %s of %s", pkey, pkey_value );
1007
1008             growing_buffer* msg = buffer_init(128);
1009             buffer_fadd(
1010                 msg,
1011                 "%s: no object found with primary key %s of %s",
1012                 MODULENAME,
1013                 pkey,
1014                 pkey_value
1015             );
1016         
1017             char* m = buffer_release(msg);
1018             osrfAppSessionStatus(
1019                 ctx->session,
1020                 OSRF_STATUS_INTERNALSERVERERROR,
1021                 "osrfMethodException",
1022                 ctx->request,
1023                 m
1024             );
1025         
1026             free(m);
1027             if (pkey_value) free(pkey_value);
1028
1029             return 0;
1030         }
1031
1032         if (local_context->size > 0) {
1033                 osrfLogDebug( OSRF_LOG_MARK, "%d class-local context field(s) specified", local_context->size);
1034             int i = 0;
1035             char* lcontext = NULL;
1036             while ( (lcontext = osrfStringArrayGetString(local_context, i++)) ) {
1037                 osrfStringArrayAdd( context_org_array, oilsFMGetString( param, lcontext ) );
1038                     osrfLogDebug(
1039                     OSRF_LOG_MARK,
1040                     "adding class-local field %s (value: %s) to the context org list",
1041                     lcontext,
1042                     osrfStringArrayGetString(context_org_array, context_org_array->size - 1)
1043                 );
1044             }
1045         }
1046
1047         osrfStringArray* class_list;
1048
1049         if (foreign_context) {
1050             class_list = osrfHashKeys( foreign_context );
1051                 osrfLogDebug( OSRF_LOG_MARK, "%d foreign context classes(s) specified", class_list->size);
1052
1053             if (class_list->size > 0) {
1054     
1055                 int i = 0;
1056                 char* class_name = NULL;
1057                 while ( (class_name = osrfStringArrayGetString(class_list, i++)) ) {
1058                     osrfHash* fcontext = osrfHashGet(foreign_context, class_name);
1059
1060                         osrfLogDebug(
1061                         OSRF_LOG_MARK,
1062                         "%d foreign context fields(s) specified for class %s",
1063                         ((osrfStringArray*)osrfHashGet(fcontext,"context"))->size,
1064                         class_name
1065                     );
1066     
1067                     char* foreign_pkey = osrfHashGet(fcontext, "field");
1068                     char* foreign_pkey_value = oilsFMGetString(param, osrfHashGet(fcontext, "fkey"));
1069
1070                     jsonObject* _tmp_params = jsonParseStringFmt(
1071                         "[{\"%s\":\"%s\"}]",
1072                         foreign_pkey,
1073                         foreign_pkey_value
1074                     );
1075     
1076                         jsonObject* _list = doFieldmapperSearch(
1077                         ctx,
1078                         osrfHashGet( oilsIDL(), class_name ),
1079                         _tmp_params,
1080                         &err
1081                     );
1082
1083                     jsonObject* _fparam = jsonObjectClone(jsonObjectGetIndex(_list, 0));
1084                     jsonObjectFree(_tmp_params);
1085                     jsonObjectFree(_list);
1086  
1087                     osrfStringArray* jump_list = osrfHashGet(fcontext, "jump");
1088
1089                     if (_fparam && jump_list) {
1090                         char* flink = NULL;
1091                         int k = 0;
1092                         while ( (flink = osrfStringArrayGetString(jump_list, k++)) && _fparam ) {
1093                             free(foreign_pkey_value);
1094
1095                             osrfHash* foreign_link_hash = oilsIDLFindPath( "/%s/links/%s", _fparam->classname, flink );
1096
1097                             foreign_pkey_value = oilsFMGetString(_fparam, flink);
1098                             foreign_pkey = osrfHashGet( foreign_link_hash, "key" );
1099
1100                             _tmp_params = jsonParseStringFmt(
1101                                 "[{\"%s\":\"%s\"}]",
1102                                 foreign_pkey,
1103                                 foreign_pkey_value
1104                             );
1105
1106                                 _list = doFieldmapperSearch(
1107                                 ctx,
1108                                 osrfHashGet( oilsIDL(), osrfHashGet( foreign_link_hash, "class" ) ),
1109                                 _tmp_params,
1110                                 &err
1111                             );
1112
1113                             _fparam = jsonObjectClone(jsonObjectGetIndex(_list, 0));
1114                             jsonObjectFree(_tmp_params);
1115                             jsonObjectFree(_list);
1116                         }
1117                     }
1118
1119            
1120                     if (!_fparam) {
1121
1122                         growing_buffer* msg = buffer_init(128);
1123                         buffer_fadd(
1124                             msg,
1125                             "%s: no object found with primary key %s of %s",
1126                             MODULENAME,
1127                             foreign_pkey,
1128                             foreign_pkey_value
1129                         );
1130                 
1131                         char* m = buffer_release(msg);
1132                         osrfAppSessionStatus(
1133                             ctx->session,
1134                             OSRF_STATUS_INTERNALSERVERERROR,
1135                             "osrfMethodException",
1136                             ctx->request,
1137                             m
1138                         );
1139
1140                         free(m);
1141                         osrfStringArrayFree(class_list);
1142                         free(foreign_pkey_value);
1143                         jsonObjectFree(param);
1144
1145                         return 0;
1146                     }
1147         
1148                     free(foreign_pkey_value);
1149     
1150                     int j = 0;
1151                     char* foreign_field = NULL;
1152                     while ( (foreign_field = osrfStringArrayGetString(osrfHashGet(fcontext,"context"), j++)) ) {
1153                         osrfStringArrayAdd( context_org_array, oilsFMGetString( _fparam, foreign_field ) );
1154                             osrfLogDebug(
1155                             OSRF_LOG_MARK,
1156                             "adding foreign class %s field %s (value: %s) to the context org list",
1157                             class_name,
1158                             foreign_field,
1159                             osrfStringArrayGetString(context_org_array, context_org_array->size - 1)
1160                         );
1161                     }
1162
1163                     jsonObjectFree(_fparam);
1164                 }
1165     
1166                 osrfStringArrayFree(class_list);
1167             }
1168         }
1169
1170         jsonObjectFree(param);
1171     }
1172
1173     char* context_org = NULL;
1174     char* perm = NULL;
1175     int OK = 0;
1176
1177     if (permission->size == 0) {
1178             osrfLogDebug( OSRF_LOG_MARK, "No permission specified for this action, passing through" );
1179         OK = 1;
1180     }
1181     
1182     int i = 0;
1183     while ( (perm = osrfStringArrayGetString(permission, i++)) ) {
1184         int j = 0;
1185         while ( (context_org = osrfStringArrayGetString(context_org_array, j++)) ) {
1186             dbi_result result;
1187
1188             if (pkey_value) {
1189                     osrfLogDebug(
1190                     OSRF_LOG_MARK,
1191                     "Checking object permission [%s] for user %d on object %s (class %s) at org %d",
1192                     perm,
1193                     userid,
1194                     pkey_value,
1195                     osrfHashGet(class, "classname"),
1196                     atoi(context_org)
1197                 );
1198
1199                 result = dbi_conn_queryf(
1200                     writehandle,
1201                     "SELECT permission.usr_has_object_perm(%d, '%s', '%s', '%s', %d) AS has_perm;",
1202                     userid,
1203                     perm,
1204                     osrfHashGet(class, "classname"),
1205                     pkey_value,
1206                     atoi(context_org)
1207                 );
1208
1209                 if (result) {
1210                     osrfLogDebug(
1211                         OSRF_LOG_MARK,
1212                         "Recieved a result for object permission [%s] for user %d on object %s (class %s) at org %d",
1213                         perm,
1214                         userid,
1215                         pkey_value,
1216                         osrfHashGet(class, "classname"),
1217                         atoi(context_org)
1218                     );
1219
1220                     if (dbi_result_first_row(result)) {
1221                         jsonObject* return_val = oilsMakeJSONFromResult( result );
1222                         char* has_perm = jsonObjectToSimpleString( jsonObjectGetKeyConst(return_val, "has_perm") );
1223
1224                             osrfLogDebug(
1225                             OSRF_LOG_MARK,
1226                             "Status of object permission [%s] for user %d on object %s (class %s) at org %d is %s",
1227                             perm,
1228                             userid,
1229                             pkey_value,
1230                             osrfHashGet(class, "classname"),
1231                             atoi(context_org),
1232                             has_perm
1233                         );
1234
1235                         if ( *has_perm == 't' ) OK = 1;
1236                         free(has_perm); 
1237                         jsonObjectFree(return_val);
1238                     }
1239
1240                     dbi_result_free(result); 
1241                     if (OK) break;
1242                 }
1243             }
1244
1245                 osrfLogDebug( OSRF_LOG_MARK, "Checking non-object permission [%s] for user %d at org %d", perm, userid, atoi(context_org) );
1246             result = dbi_conn_queryf(
1247                 writehandle,
1248                 "SELECT permission.usr_has_perm(%d, '%s', %d) AS has_perm;",
1249                 userid,
1250                 perm,
1251                 atoi(context_org)
1252             );
1253
1254             if (result) {
1255                     osrfLogDebug( OSRF_LOG_MARK, "Recieved a result for permission [%s] for user %d at org %d", perm, userid, atoi(context_org) );
1256                 if (dbi_result_first_row(result)) {
1257                     jsonObject* return_val = oilsMakeJSONFromResult( result );
1258                     char* has_perm = jsonObjectToSimpleString( jsonObjectGetKeyConst(return_val, "has_perm") );
1259                         osrfLogDebug( OSRF_LOG_MARK, "Status of permission [%s] for user %d at org %d is [%s]", perm, userid, atoi(context_org), has_perm );
1260                     if ( *has_perm == 't' ) OK = 1;
1261                     free(has_perm); 
1262                     jsonObjectFree(return_val);
1263                 }
1264
1265                 dbi_result_free(result); 
1266                 if (OK) break;
1267             }
1268
1269         }
1270         if (OK) break;
1271     }
1272
1273     if (pkey_value) free(pkey_value);
1274     osrfStringArrayFree(context_org_array);
1275
1276     return OK;
1277 }
1278 #endif
1279
1280
1281 static jsonObject* doCreate(osrfMethodContext* ctx, int* err ) {
1282
1283         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
1284 #ifdef PCRUD
1285         jsonObject* target = jsonObjectGetIndex( ctx->params, 1 );
1286         jsonObject* options = jsonObjectGetIndex( ctx->params, 2 );
1287 #else
1288         jsonObject* target = jsonObjectGetIndex( ctx->params, 0 );
1289         jsonObject* options = jsonObjectGetIndex( ctx->params, 1 );
1290 #endif
1291
1292         if (!verifyObjectClass(ctx, target)) {
1293                 *err = -1;
1294                 return jsonNULL;
1295         }
1296
1297         osrfLogDebug( OSRF_LOG_MARK, "Object seems to be of the correct type" );
1298
1299         if (!ctx->session || !ctx->session->userData || !osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
1300                 osrfLogError( OSRF_LOG_MARK, "No active transaction -- required for CREATE" );
1301
1302                 osrfAppSessionStatus(
1303                         ctx->session,
1304                         OSRF_STATUS_BADREQUEST,
1305                         "osrfMethodException",
1306                         ctx->request,
1307                         "No active transaction -- required for CREATE"
1308                 );
1309                 *err = -1;
1310                 return jsonNULL;
1311         }
1312
1313         // The following test is harmless but redundant.  If a class is
1314         // readonly, we don't register a create method for it.
1315         if( str_is_true( osrfHashGet( meta, "readonly" ) ) ) {
1316                 osrfAppSessionStatus(
1317                         ctx->session,
1318                         OSRF_STATUS_BADREQUEST,
1319                         "osrfMethodException",
1320                         ctx->request,
1321                         "Cannot INSERT readonly class"
1322                 );
1323                 *err = -1;
1324                 return jsonNULL;
1325         }
1326
1327
1328         char* trans_id = osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" );
1329
1330         // Set the last_xact_id
1331         int index = oilsIDL_ntop( target->classname, "last_xact_id" );
1332         if (index > -1) {
1333                 osrfLogDebug(OSRF_LOG_MARK, "Setting last_xact_id to %s on %s at position %d", trans_id, target->classname, index);
1334                 jsonObjectSetIndex(target, index, jsonNewObject(trans_id));
1335         }       
1336
1337         osrfLogDebug( OSRF_LOG_MARK, "There is a transaction running..." );
1338
1339         dbhandle = writehandle;
1340
1341         osrfHash* fields = osrfHashGet(meta, "fields");
1342         char* pkey = osrfHashGet(meta, "primarykey");
1343         char* seq = osrfHashGet(meta, "sequence");
1344
1345         growing_buffer* table_buf = buffer_init(128);
1346         growing_buffer* col_buf = buffer_init(128);
1347         growing_buffer* val_buf = buffer_init(128);
1348
1349         OSRF_BUFFER_ADD(table_buf, "INSERT INTO ");
1350         OSRF_BUFFER_ADD(table_buf, osrfHashGet(meta, "tablename"));
1351         OSRF_BUFFER_ADD_CHAR( col_buf, '(' );
1352         buffer_add(val_buf,"VALUES (");
1353
1354
1355         int i = 0;
1356         int first = 1;
1357         char* field_name;
1358         osrfStringArray* field_list = osrfHashKeys( fields );
1359         while ( (field_name = osrfStringArrayGetString(field_list, i++)) ) {
1360
1361                 osrfHash* field = osrfHashGet( fields, field_name );
1362
1363                 if( str_is_true( osrfHashGet( field, "virtual" ) ) )
1364                         continue;
1365
1366                 const jsonObject* field_object = oilsFMGetObject( target, field_name );
1367
1368                 char* value;
1369                 if (field_object && field_object->classname) {
1370                         value = oilsFMGetString(
1371                                 field_object,
1372                                 (char*)oilsIDLFindPath("/%s/primarykey", field_object->classname)
1373                         );
1374                 } else {
1375                         value = jsonObjectToSimpleString( field_object );
1376                 }
1377
1378
1379                 if (first) {
1380                         first = 0;
1381                 } else {
1382                         OSRF_BUFFER_ADD_CHAR( col_buf, ',' );
1383                         OSRF_BUFFER_ADD_CHAR( val_buf, ',' );
1384                 }
1385
1386                 buffer_add(col_buf, field_name);
1387
1388                 if (!field_object || field_object->type == JSON_NULL) {
1389                         buffer_add( val_buf, "DEFAULT" );
1390                         
1391                 } else if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1392                         if ( !strcmp(osrfHashGet(field, "datatype"), "INT8") ) {
1393                                 buffer_fadd( val_buf, "%lld", atoll(value) );
1394                                 
1395                         } else if ( !strcmp(osrfHashGet(field, "datatype"), "INT") ) {
1396                                 buffer_fadd( val_buf, "%d", atoi(value) );
1397                                 
1398                         } else if ( !strcmp(osrfHashGet(field, "datatype"), "NUMERIC") ) {
1399                                 buffer_fadd( val_buf, "%f", atof(value) );
1400                         }
1401                 } else {
1402                         if ( dbi_conn_quote_string(writehandle, &value) ) {
1403                                 OSRF_BUFFER_ADD( val_buf, value );
1404
1405                         } else {
1406                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting string [%s]", MODULENAME, value);
1407                                 osrfAppSessionStatus(
1408                                         ctx->session,
1409                                         OSRF_STATUS_INTERNALSERVERERROR,
1410                                         "osrfMethodException",
1411                                         ctx->request,
1412                                         "Error quoting string -- please see the error log for more details"
1413                                 );
1414                                 free(value);
1415                                 buffer_free(table_buf);
1416                                 buffer_free(col_buf);
1417                                 buffer_free(val_buf);
1418                                 *err = -1;
1419                                 return jsonNULL;
1420                         }
1421                 }
1422
1423                 free(value);
1424                 
1425         }
1426
1427
1428         OSRF_BUFFER_ADD_CHAR( col_buf, ')' );
1429         OSRF_BUFFER_ADD_CHAR( val_buf, ')' );
1430
1431         char* table_str = buffer_release(table_buf);
1432         char* col_str   = buffer_release(col_buf);
1433         char* val_str   = buffer_release(val_buf);
1434         growing_buffer* sql = buffer_init(128);
1435         buffer_fadd( sql, "%s %s %s;", table_str, col_str, val_str );
1436         free(table_str);
1437         free(col_str);
1438         free(val_str);
1439
1440         char* query = buffer_release(sql);
1441
1442         osrfLogDebug(OSRF_LOG_MARK, "%s: Insert SQL [%s]", MODULENAME, query);
1443
1444         
1445         dbi_result result = dbi_conn_query(writehandle, query);
1446
1447         jsonObject* obj = NULL;
1448
1449         if (!result) {
1450                 obj = jsonNewObject(NULL);
1451                 osrfLogError(
1452                         OSRF_LOG_MARK,
1453                         "%s ERROR inserting %s object using query [%s]",
1454                         MODULENAME,
1455                         osrfHashGet(meta, "fieldmapper"),
1456                         query
1457                 );
1458                 osrfAppSessionStatus(
1459                         ctx->session,
1460                         OSRF_STATUS_INTERNALSERVERERROR,
1461                         "osrfMethodException",
1462                         ctx->request,
1463                         "INSERT error -- please see the error log for more details"
1464                 );
1465                 *err = -1;
1466         } else {
1467
1468                 char* id = oilsFMGetString(target, pkey);
1469                 if (!id) {
1470                         unsigned long long new_id = dbi_conn_sequence_last(writehandle, seq);
1471                         growing_buffer* _id = buffer_init(10);
1472                         buffer_fadd(_id, "%lld", new_id);
1473                         id = buffer_release(_id);
1474                 }
1475
1476                 // Find quietness specification, if present
1477                 char* quiet_str = NULL;
1478                 if ( options ) {
1479                         const jsonObject* quiet_obj = jsonObjectGetKeyConst( options, "quiet" );
1480                         if( quiet_obj )
1481                                 quiet_str = jsonObjectToSimpleString( quiet_obj );
1482                 }
1483
1484                 if( str_is_true( quiet_str ) ) {  // if quietness is specified
1485                         obj = jsonNewObject(id);
1486                 }
1487                 else {
1488
1489                         jsonObject* fake_params = jsonNewObjectType(JSON_ARRAY);
1490                         jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH));
1491
1492                         jsonObjectSetKey(
1493                                 jsonObjectGetIndex(fake_params, 0),
1494                                 pkey,
1495                                 jsonNewObject(id)
1496                         );
1497
1498                         jsonObject* list = doFieldmapperSearch( ctx,meta, fake_params, err);
1499
1500                         if(*err) {
1501                                 jsonObjectFree( fake_params );
1502                                 obj = jsonNULL;
1503                         } else {
1504                                 obj = jsonObjectClone( jsonObjectGetIndex(list, 0) );
1505                         }
1506
1507                         jsonObjectFree( list );
1508                         jsonObjectFree( fake_params );
1509                 }
1510
1511                 if(quiet_str) free(quiet_str);
1512                 free(id);
1513         }
1514
1515         free(query);
1516
1517         return obj;
1518
1519 }
1520
1521
1522 static jsonObject* doRetrieve(osrfMethodContext* ctx, int* err ) {
1523
1524     int id_pos = 0;
1525     int order_pos = 1;
1526
1527 #ifdef PCRUD
1528     id_pos = 1;
1529     order_pos = 2;
1530 #endif
1531
1532         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
1533
1534         char* id = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, id_pos));
1535         jsonObject* order_hash = jsonObjectGetIndex(ctx->params, order_pos);
1536
1537         osrfLogDebug(
1538                 OSRF_LOG_MARK,
1539                 "%s retrieving %s object with primary key value of %s",
1540                 MODULENAME,
1541                 osrfHashGet(meta, "fieldmapper"),
1542                 id
1543         );
1544         free(id);
1545
1546         jsonObject* fake_params = jsonNewObjectType(JSON_ARRAY);
1547         jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH));
1548
1549         jsonObjectSetKey(
1550                 jsonObjectGetIndex(fake_params, 0),
1551                 osrfHashGet(meta, "primarykey"),
1552                 jsonObjectClone(jsonObjectGetIndex(ctx->params, id_pos))
1553         );
1554
1555
1556         if (order_hash) jsonObjectPush(fake_params, jsonObjectClone(order_hash) );
1557
1558         jsonObject* list = doFieldmapperSearch( ctx,meta, fake_params, err);
1559
1560         if(*err) {
1561                 jsonObjectFree( fake_params );
1562                 return jsonNULL;
1563         }
1564
1565         jsonObject* obj = jsonObjectClone( jsonObjectGetIndex(list, 0) );
1566
1567         jsonObjectFree( list );
1568         jsonObjectFree( fake_params );
1569
1570 #ifdef PCRUD
1571         if(!verifyObjectPCRUD(ctx, obj)) {
1572         jsonObjectFree(obj);
1573         *err = -1;
1574
1575         growing_buffer* msg = buffer_init(128);
1576                 OSRF_BUFFER_ADD( msg, MODULENAME );
1577                 OSRF_BUFFER_ADD( msg, ": Insufficient permissions to retrieve object" );
1578
1579         char* m = buffer_release(msg);
1580         osrfAppSessionStatus( ctx->session, OSRF_STATUS_NOTALLOWED, "osrfMethodException", ctx->request, m );
1581
1582         free(m);
1583
1584                 return jsonNULL;
1585         }
1586 #endif
1587
1588         return obj;
1589 }
1590
1591 static char* jsonNumberToDBString ( osrfHash* field, const jsonObject* value ) {
1592         growing_buffer* val_buf = buffer_init(32);
1593
1594         if ( !strncmp(osrfHashGet(field, "datatype"), "INT", (size_t)3) ) {
1595                 if (value->type == JSON_NUMBER) buffer_fadd( val_buf, "%ld", (long)jsonObjectGetNumber(value) );
1596                 else {
1597                         char* val_str = jsonObjectToSimpleString(value);
1598                         buffer_fadd( val_buf, "%ld", atol(val_str) );
1599                         free(val_str);
1600                 }
1601
1602         } else if ( !strcmp(osrfHashGet(field, "datatype"), "NUMERIC") ) {
1603                 if (value->type == JSON_NUMBER) buffer_fadd( val_buf, "%f",  jsonObjectGetNumber(value) );
1604                 else {
1605                         char* val_str = jsonObjectToSimpleString(value);
1606                         buffer_fadd( val_buf, "%f", atof(val_str) );
1607                         free(val_str);
1608                 }
1609         }
1610
1611         return buffer_release(val_buf);
1612 }
1613
1614 static char* searchINPredicate (const char* class, osrfHash* field,
1615                 jsonObject* node, const char* op, osrfMethodContext* ctx ) {
1616         growing_buffer* sql_buf = buffer_init(32);
1617         
1618         buffer_fadd(
1619                 sql_buf,
1620                 "\"%s\".%s ",
1621                 class,
1622                 osrfHashGet(field, "name")
1623         );
1624
1625         if (!op) {
1626                 buffer_add(sql_buf, "IN (");
1627         } else if (!(strcasecmp(op,"not in"))) {
1628                 buffer_add(sql_buf, "NOT IN (");
1629         } else {
1630                 buffer_add(sql_buf, "IN (");
1631         }
1632
1633     if (node->type == JSON_HASH) {
1634         // subquery predicate
1635         char* subpred = SELECT(
1636             ctx,
1637             jsonObjectGetKey( node, "select" ),
1638             jsonObjectGetKey( node, "from" ),
1639             jsonObjectGetKey( node, "where" ),
1640             jsonObjectGetKey( node, "having" ),
1641             jsonObjectGetKey( node, "order_by" ),
1642             jsonObjectGetKey( node, "limit" ),
1643             jsonObjectGetKey( node, "offset" ),
1644             SUBSELECT
1645         );
1646
1647         buffer_add(sql_buf, subpred);
1648         free(subpred);
1649
1650     } else if (node->type == JSON_ARRAY) {
1651         // litteral value list
1652         int in_item_index = 0;
1653         int in_item_first = 1;
1654         jsonObject* in_item;
1655         while ( (in_item = jsonObjectGetIndex(node, in_item_index++)) ) {
1656     
1657                 if (in_item_first)
1658                         in_item_first = 0;
1659                 else
1660                         buffer_add(sql_buf, ", ");
1661     
1662                 if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1663                         char* val = jsonNumberToDBString( field, in_item );
1664                         OSRF_BUFFER_ADD( sql_buf, val );
1665                         free(val);
1666     
1667                 } else {
1668                         char* key_string = jsonObjectToSimpleString(in_item);
1669                         if ( dbi_conn_quote_string(dbhandle, &key_string) ) {
1670                                 OSRF_BUFFER_ADD( sql_buf, key_string );
1671                                 free(key_string);
1672                         } else {
1673                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, key_string);
1674                                 free(key_string);
1675                                 buffer_free(sql_buf);
1676                                 return NULL;
1677                         }
1678                 }
1679         }
1680     }
1681     
1682         OSRF_BUFFER_ADD_CHAR( sql_buf, ')' );
1683
1684         return buffer_release(sql_buf);
1685 }
1686
1687 // Receive a JSON_ARRAY representing a function call.  The first
1688 // entry in the array is the function name.  The rest are parameters.
1689 static char* searchValueTransform( const jsonObject* array ) {
1690         growing_buffer* sql_buf = buffer_init(32);
1691
1692         char* val = NULL;
1693         jsonObject* func_item;
1694         
1695         // Get the function name
1696         if( array->size > 0 ) {
1697                 func_item = jsonObjectGetIndex( array, 0 );
1698                 val = jsonObjectToSimpleString( func_item );
1699                 OSRF_BUFFER_ADD( sql_buf, val );
1700                 OSRF_BUFFER_ADD( sql_buf, "( " );
1701                 free(val);
1702         }
1703         
1704         // Get the parameters
1705         int func_item_index = 1;   // We already grabbed the zeroth entry
1706         while ( (func_item = jsonObjectGetIndex(array, func_item_index++)) ) {
1707
1708                 // Add a separator comma, if we need one
1709                 if( func_item_index > 2 )
1710                         buffer_add( sql_buf, ", " );
1711
1712                 // Add the current parameter
1713                 if (func_item->type == JSON_NULL) {
1714                         buffer_add( sql_buf, "NULL" );
1715                 } else {
1716                         val = jsonObjectToSimpleString(func_item);
1717                         if ( dbi_conn_quote_string(dbhandle, &val) ) {
1718                                 OSRF_BUFFER_ADD( sql_buf, val );
1719                                 free(val);
1720                         } else {
1721                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, val);
1722                                 buffer_free(sql_buf);
1723                                 free(val);
1724                                 return NULL;
1725                         }
1726                 }
1727         }
1728
1729         buffer_add( sql_buf, " )" );
1730
1731         return buffer_release(sql_buf);
1732 }
1733
1734 static char* searchFunctionPredicate (const char* class, osrfHash* field,
1735                 const jsonObject* node, const char* node_key) {
1736         growing_buffer* sql_buf = buffer_init(32);
1737
1738         char* val = searchValueTransform(node);
1739         
1740         buffer_fadd(
1741                 sql_buf,
1742                 "\"%s\".%s %s %s",
1743                 class,
1744                 osrfHashGet(field, "name"),
1745                 node_key,
1746                 val
1747         );
1748
1749         free(val);
1750
1751         return buffer_release(sql_buf);
1752 }
1753
1754 // class is a class name
1755 // field is a field definition as stored in the IDL
1756 // node comes from the method parameter, and represents an entry in the SELECT list
1757 static char* searchFieldTransform (const char* class, osrfHash* field, const jsonObject* node) {
1758         growing_buffer* sql_buf = buffer_init(32);
1759         
1760         char* field_transform = jsonObjectToSimpleString( jsonObjectGetKeyConst( node, "transform" ) );
1761         char* transform_subcolumn = jsonObjectToSimpleString( jsonObjectGetKeyConst( node, "result_field" ) );
1762
1763         if(transform_subcolumn)
1764                 OSRF_BUFFER_ADD_CHAR( sql_buf, '(' );    // enclose transform in parentheses
1765
1766         if (field_transform) {
1767                 buffer_fadd( sql_buf, "%s(\"%s\".%s", field_transform, class, osrfHashGet(field, "name"));
1768             const jsonObject* array = jsonObjectGetKeyConst( node, "params" );
1769
1770         if (array) {
1771                 int func_item_index = 0;
1772                 jsonObject* func_item;
1773                 while ( (func_item = jsonObjectGetIndex(array, func_item_index++)) ) {
1774
1775                         char* val = jsonObjectToSimpleString(func_item);
1776
1777                     if ( !val ) {
1778                             buffer_add( sql_buf, ",NULL" );
1779                     } else if ( dbi_conn_quote_string(dbhandle, &val) ) {
1780                                         OSRF_BUFFER_ADD_CHAR( sql_buf, ',' );
1781                                         OSRF_BUFFER_ADD( sql_buf, val );
1782                         } else {
1783                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, val);
1784                                         free(transform_subcolumn);
1785                                         free(field_transform);
1786                                         free(val);
1787                                 buffer_free(sql_buf);
1788                                 return NULL;
1789                 }
1790                                 free(val);
1791                         }
1792         }
1793
1794                 buffer_add( sql_buf, " )" );
1795
1796         } else {
1797                 buffer_fadd( sql_buf, "\"%s\".%s", class, osrfHashGet(field, "name"));
1798         }
1799
1800     if (transform_subcolumn)
1801         buffer_fadd( sql_buf, ").\"%s\"", transform_subcolumn );
1802  
1803         if (field_transform) free(field_transform);
1804         if (transform_subcolumn) free(transform_subcolumn);
1805
1806         return buffer_release(sql_buf);
1807 }
1808
1809 static char* searchFieldTransformPredicate (const char* class, osrfHash* field, jsonObject* node, const char* node_key) {
1810         char* field_transform = searchFieldTransform( class, field, node );
1811         char* value = NULL;
1812
1813         if (!jsonObjectGetKeyConst( node, "value" )) {
1814                 value = searchWHERE( node, osrfHashGet( oilsIDL(), class ), AND_OP_JOIN, NULL );
1815         } else if (jsonObjectGetKeyConst( node, "value" )->type == JSON_ARRAY) {
1816                 value = searchValueTransform(jsonObjectGetKeyConst( node, "value" ));
1817         } else if (jsonObjectGetKeyConst( node, "value" )->type == JSON_HASH) {
1818                 value = searchWHERE( jsonObjectGetKeyConst( node, "value" ), osrfHashGet( oilsIDL(), class ), AND_OP_JOIN, NULL );
1819         } else if (jsonObjectGetKeyConst( node, "value" )->type != JSON_NULL) {
1820                 if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1821                         value = jsonNumberToDBString( field, jsonObjectGetKeyConst( node, "value" ) );
1822                 } else {
1823                         value = jsonObjectToSimpleString(jsonObjectGetKeyConst( node, "value" ));
1824                         if ( !dbi_conn_quote_string(dbhandle, &value) ) {
1825                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, value);
1826                                 free(value);
1827                                 free(field_transform);
1828                                 return NULL;
1829                         }
1830                 }
1831         }
1832
1833         growing_buffer* sql_buf = buffer_init(32);
1834         
1835         buffer_fadd(
1836                 sql_buf,
1837                 "%s %s %s",
1838                 field_transform,
1839                 node_key,
1840                 value
1841         );
1842
1843         free(value);
1844         free(field_transform);
1845
1846         return buffer_release(sql_buf);
1847 }
1848
1849 static char* searchSimplePredicate (const char* orig_op, const char* class,
1850                 osrfHash* field, const jsonObject* node) {
1851
1852         char* val = NULL;
1853
1854         if (node->type != JSON_NULL) {
1855                 if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1856                         val = jsonNumberToDBString( field, node );
1857                 } else {
1858                         val = jsonObjectToSimpleString(node);
1859                 }
1860         }
1861
1862         char* pred = searchWriteSimplePredicate( class, field, osrfHashGet(field, "name"), orig_op, val );
1863
1864         if (val) free(val);
1865
1866         return pred;
1867 }
1868
1869 static char* searchWriteSimplePredicate ( const char* class, osrfHash* field,
1870         const char* left, const char* orig_op, const char* right ) {
1871
1872         char* val = NULL;
1873         char* op = NULL;
1874         if (right == NULL) {
1875                 val = strdup("NULL");
1876
1877                 if (strcmp( orig_op, "=" ))
1878                         op = strdup("IS NOT");
1879                 else
1880                         op = strdup("IS");
1881
1882         } else if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1883                 val = strdup(right);
1884                 op = strdup(orig_op);
1885
1886         } else {
1887                 val = strdup(right);
1888                 if ( !dbi_conn_quote_string(dbhandle, &val) ) {
1889                         osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, val);
1890                         free(val);
1891                         return NULL;
1892                 }
1893                 op = strdup(orig_op);
1894         }
1895
1896         growing_buffer* sql_buf = buffer_init(16);
1897         buffer_fadd( sql_buf, "\"%s\".%s %s %s", class, left, op, val );
1898         free(val);
1899         free(op);
1900
1901         return buffer_release(sql_buf);
1902 }
1903
1904 static char* searchBETWEENPredicate (const char* class, osrfHash* field, jsonObject* node) {
1905
1906         char* x_string;
1907         char* y_string;
1908
1909         if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1910                 x_string = jsonNumberToDBString(field, jsonObjectGetIndex(node,0));
1911                 y_string = jsonNumberToDBString(field, jsonObjectGetIndex(node,1));
1912
1913         } else {
1914                 x_string = jsonObjectToSimpleString(jsonObjectGetIndex(node,0));
1915                 y_string = jsonObjectToSimpleString(jsonObjectGetIndex(node,1));
1916                 if ( !(dbi_conn_quote_string(dbhandle, &x_string) && dbi_conn_quote_string(dbhandle, &y_string)) ) {
1917                         osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key strings [%s] and [%s]", MODULENAME, x_string, y_string);
1918                         free(x_string);
1919                         free(y_string);
1920                         return NULL;
1921                 }
1922         }
1923
1924         growing_buffer* sql_buf = buffer_init(32);
1925         buffer_fadd( sql_buf, "%s BETWEEN %s AND %s", osrfHashGet(field, "name"), x_string, y_string );
1926         free(x_string);
1927         free(y_string);
1928
1929         return buffer_release(sql_buf);
1930 }
1931
1932 static char* searchPredicate ( const char* class, osrfHash* field, 
1933                                                            jsonObject* node, osrfMethodContext* ctx ) {
1934
1935         char* pred = NULL;
1936         if (node->type == JSON_ARRAY) { // equality IN search
1937                 pred = searchINPredicate( class, field, node, NULL, ctx );
1938         } else if (node->type == JSON_HASH) { // non-equality search
1939                 jsonObject* pred_node;
1940                 jsonIterator* pred_itr = jsonNewIterator( node );
1941                 while ( (pred_node = jsonIteratorNext( pred_itr )) ) {
1942                         if ( !(strcasecmp( pred_itr->key,"between" )) )
1943                                 pred = searchBETWEENPredicate( class, field, pred_node );
1944                         else if ( !(strcasecmp( pred_itr->key,"in" )) || !(strcasecmp( pred_itr->key,"not in" )) )
1945                                 pred = searchINPredicate( class, field, pred_node, pred_itr->key, ctx );
1946                         else if ( pred_node->type == JSON_ARRAY )
1947                                 pred = searchFunctionPredicate( class, field, pred_node, pred_itr->key );
1948                         else if ( pred_node->type == JSON_HASH )
1949                                 pred = searchFieldTransformPredicate( class, field, pred_node, pred_itr->key );
1950                         else 
1951                                 pred = searchSimplePredicate( pred_itr->key, class, field, pred_node );
1952
1953                         break;
1954                 }
1955         jsonIteratorFree(pred_itr);
1956         } else if (node->type == JSON_NULL) { // IS NULL search
1957                 growing_buffer* _p = buffer_init(64);
1958                 buffer_fadd(
1959                         _p,
1960                         "\"%s\".%s IS NULL",
1961                         class,
1962                         osrfHashGet(field, "name")
1963                 );
1964                 pred = buffer_release(_p);
1965         } else { // equality search
1966                 pred = searchSimplePredicate( "=", class, field, node );
1967         }
1968
1969         return pred;
1970
1971 }
1972
1973
1974 /*
1975
1976 join : {
1977         acn : {
1978                 field : record,
1979                 fkey : id
1980                 type : left
1981                 filter_op : or
1982                 filter : { ... },
1983                 join : {
1984                         acp : {
1985                                 field : call_number,
1986                                 fkey : id,
1987                                 filter : { ... },
1988                         },
1989                 },
1990         },
1991         mrd : {
1992                 field : record,
1993                 type : inner
1994                 fkey : id,
1995                 filter : { ... },
1996         }
1997 }
1998
1999 */
2000
2001 static char* searchJOIN ( const jsonObject* join_hash, osrfHash* leftmeta ) {
2002
2003         const jsonObject* working_hash;
2004         jsonObject* freeable_hash = NULL;
2005
2006         if (join_hash->type == JSON_STRING) {
2007                 // create a wrapper around a copy of the original
2008                 char* _tmp = jsonObjectToSimpleString( join_hash );
2009                 freeable_hash = jsonNewObjectType(JSON_HASH);
2010                 jsonObjectSetKey(freeable_hash, _tmp, NULL);
2011                 free(_tmp);
2012                 working_hash = freeable_hash;
2013         }
2014         else {
2015                 if( join_hash->type != JSON_HASH ) {
2016                         osrfLogError(
2017                                 OSRF_LOG_MARK,
2018                                 "%s: JOIN failed; expected JSON object type not found",
2019                                 MODULENAME
2020                         );
2021                         return NULL;
2022                 }
2023                 working_hash = join_hash;
2024         }
2025
2026         growing_buffer* join_buf = buffer_init(128);
2027         const char* leftclass = osrfHashGet(leftmeta, "classname");
2028
2029         jsonObject* snode = NULL;
2030         jsonIterator* search_itr = jsonNewIterator( working_hash );
2031         
2032         while ( (snode = jsonIteratorNext( search_itr )) ) {
2033                 osrfHash* idlClass = osrfHashGet( oilsIDL(), search_itr->key );
2034
2035                 const char* class = osrfHashGet(idlClass, "classname");
2036
2037                 char* fkey = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "fkey" ) );
2038                 char* field = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "field" ) );
2039
2040                 if (field && !fkey) {
2041                         fkey = (char*)oilsIDLFindPath("/%s/links/%s/key", class, field);
2042                         if (!fkey) {
2043                                 osrfLogError(
2044                                         OSRF_LOG_MARK,
2045                                         "%s: JOIN failed.  No link defined from %s.%s to %s",
2046                                         MODULENAME,
2047                                         class,
2048                                         field,
2049                                         leftclass
2050                                 );
2051                                 buffer_free(join_buf);
2052                                 if(freeable_hash)
2053                                         jsonObjectFree(freeable_hash);
2054                                 free(field);
2055                                 jsonIteratorFree(search_itr);
2056                                 return NULL;
2057                         }
2058                         fkey = strdup( fkey );
2059
2060                 } else if (!field && fkey) {
2061                         field = (char*)oilsIDLFindPath("/%s/links/%s/key", leftclass, fkey );
2062                         if (!field) {
2063                                 osrfLogError(
2064                                         OSRF_LOG_MARK,
2065                                         "%s: JOIN failed.  No link defined from %s.%s to %s",
2066                                         MODULENAME,
2067                                         leftclass,
2068                                         fkey,
2069                                         class
2070                                 );
2071                                 buffer_free(join_buf);
2072                                 if(freeable_hash)
2073                                         jsonObjectFree(freeable_hash);
2074                                 free(fkey);
2075                                 jsonIteratorFree(search_itr);
2076                                 return NULL;
2077                         }
2078                         field = strdup( field );
2079
2080                 } else if (!field && !fkey) {
2081                         osrfHash* _links = oilsIDLFindPath("/%s/links", leftclass);
2082
2083                         int i = 0;
2084                         const char* tmp_fkey;
2085                         osrfStringArray* keys = osrfHashKeys( _links );
2086                         while ( (tmp_fkey = osrfStringArrayGetString(keys, i++)) ) {
2087                                 if ( !strcmp( (char*)oilsIDLFindPath("/%s/links/%s/class", leftclass, tmp_fkey), class) ) {
2088                                         field = strdup( (char*)oilsIDLFindPath("/%s/links/%s/key", leftclass, tmp_fkey) );
2089                                         fkey = strdup(tmp_fkey);
2090                                         break;
2091                                 }
2092                         }
2093                         osrfStringArrayFree(keys);
2094
2095                         if (!field && !fkey) {
2096                                 _links = oilsIDLFindPath("/%s/links", class);
2097
2098                                 i = 0;
2099                                 const char* tmp_fld;
2100                                 keys = osrfHashKeys( _links );
2101                                 while ( (tmp_fld = osrfStringArrayGetString(keys, i++)) ) {
2102                                         if ( !strcmp( (char*)oilsIDLFindPath("/%s/links/%s/class", class, tmp_fld), class) ) {
2103                                                 fkey = strdup( (char*)oilsIDLFindPath("/%s/links/%s/key", class, tmp_fld) );
2104                                                 field = strdup( tmp_fld );
2105                                                 break;
2106                                         }
2107                                 }
2108                                 osrfStringArrayFree(keys);
2109                         }
2110
2111                         if (!field && !fkey) {
2112                                 osrfLogError(
2113                                         OSRF_LOG_MARK,
2114                                         "%s: JOIN failed.  No link defined between %s and %s",
2115                                         MODULENAME,
2116                                         leftclass,
2117                                         class
2118                                 );
2119                                 buffer_free(join_buf);
2120                                 if(freeable_hash)
2121                                         jsonObjectFree(freeable_hash);
2122                                 jsonIteratorFree(search_itr);
2123                                 return NULL;
2124                         }
2125
2126                 }
2127
2128                 char* type = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "type" ) );
2129                 if (type) {
2130                         if ( !strcasecmp(type,"left") ) {
2131                                 buffer_add(join_buf, " LEFT JOIN");
2132                         } else if ( !strcasecmp(type,"right") ) {
2133                                 buffer_add(join_buf, " RIGHT JOIN");
2134                         } else if ( !strcasecmp(type,"full") ) {
2135                                 buffer_add(join_buf, " FULL JOIN");
2136                         } else {
2137                                 buffer_add(join_buf, " INNER JOIN");
2138                         }
2139                 } else {
2140                         buffer_add(join_buf, " INNER JOIN");
2141                 }
2142                 free(type);
2143
2144                 char* table = getSourceDefinition(idlClass);
2145                 buffer_fadd(join_buf, " %s AS \"%s\" ON ( \"%s\".%s = \"%s\".%s",
2146                                         table, class, class, field, leftclass, fkey);
2147                 free(table);
2148
2149                 const jsonObject* filter = jsonObjectGetKeyConst( snode, "filter" );
2150                 if (filter) {
2151                         char* filter_op = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "filter_op" ) );
2152                         if (filter_op) {
2153                                 if (!strcasecmp("or",filter_op)) {
2154                                         buffer_add( join_buf, " OR " );
2155                                 } else {
2156                                         buffer_add( join_buf, " AND " );
2157                                 }
2158                         } else {
2159                                 buffer_add( join_buf, " AND " );
2160                         }
2161
2162                         char* jpred = searchWHERE( filter, idlClass, AND_OP_JOIN, NULL );
2163                         OSRF_BUFFER_ADD_CHAR( join_buf, ' ' );
2164                         OSRF_BUFFER_ADD( join_buf, jpred );
2165                         free(jpred);
2166                         free(filter_op);
2167                 }
2168
2169                 buffer_add(join_buf, " ) ");
2170                 
2171                 const jsonObject* join_filter = jsonObjectGetKeyConst( snode, "join" );
2172                 if (join_filter) {
2173                         char* jpred = searchJOIN( join_filter, idlClass );
2174                         OSRF_BUFFER_ADD_CHAR( join_buf, ' ' );
2175                         OSRF_BUFFER_ADD( join_buf, jpred );
2176                         free(jpred);
2177                 }
2178
2179                 free(fkey);
2180                 free(field);
2181         }
2182
2183         if(freeable_hash)
2184                 jsonObjectFree(freeable_hash);
2185         jsonIteratorFree(search_itr);
2186
2187         return buffer_release(join_buf);
2188 }
2189
2190 /*
2191
2192 { +class : { -or|-and : { field : { op : value }, ... } ... }, ... }
2193 { +class : { -or|-and : [ { field : { op : value }, ... }, ...] ... }, ... }
2194 [ { +class : { -or|-and : [ { field : { op : value }, ... }, ...] ... }, ... }, ... ]
2195
2196 */
2197
2198 static char* searchWHERE ( const jsonObject* search_hash, osrfHash* meta, int opjoin_type, osrfMethodContext* ctx ) {
2199
2200         osrfLogDebug(
2201         OSRF_LOG_MARK,
2202         "%s: Entering searchWHERE; search_hash addr = %p, meta addr = %p, opjoin_type = %d, ctx addr = %p",
2203         MODULENAME,
2204         search_hash,
2205         meta,
2206         opjoin_type,
2207         ctx
2208     );
2209
2210         growing_buffer* sql_buf = buffer_init(128);
2211
2212         jsonObject* node = NULL;
2213
2214     int first = 1;
2215     if ( search_hash->type == JSON_ARRAY ) {
2216             osrfLogDebug(OSRF_LOG_MARK, "%s: In WHERE clause, condition type is JSON_ARRAY", MODULENAME);
2217         jsonIterator* search_itr = jsonNewIterator( search_hash );
2218         while ( (node = jsonIteratorNext( search_itr )) ) {
2219             if (first) {
2220                 first = 0;
2221             } else {
2222                 if (opjoin_type == OR_OP_JOIN) buffer_add(sql_buf, " OR ");
2223                 else buffer_add(sql_buf, " AND ");
2224             }
2225
2226             char* subpred = searchWHERE( node, meta, opjoin_type, ctx );
2227             buffer_fadd(sql_buf, "( %s )", subpred);
2228             free(subpred);
2229         }
2230         jsonIteratorFree(search_itr);
2231
2232     } else if ( search_hash->type == JSON_HASH ) {
2233             osrfLogDebug(OSRF_LOG_MARK, "%s: In WHERE clause, condition type is JSON_HASH", MODULENAME);
2234         jsonIterator* search_itr = jsonNewIterator( search_hash );
2235         while ( (node = jsonIteratorNext( search_itr )) ) {
2236
2237             if (first) {
2238                 first = 0;
2239             } else {
2240                 if (opjoin_type == OR_OP_JOIN) buffer_add(sql_buf, " OR ");
2241                 else buffer_add(sql_buf, " AND ");
2242             }
2243
2244             if ( !strncmp("+",search_itr->key,1) ) {
2245                 if ( node->type == JSON_STRING ) {
2246                     char* subpred = jsonObjectToSimpleString( node );
2247                     buffer_fadd(sql_buf, " \"%s\".%s ", search_itr->key + 1, subpred);
2248                     free(subpred);
2249                 } else {
2250                     char* subpred = searchWHERE( node, osrfHashGet( oilsIDL(), search_itr->key + 1 ), AND_OP_JOIN, ctx );
2251                     buffer_fadd(sql_buf, "( %s )", subpred);
2252                     free(subpred);
2253                 }
2254             } else if ( !strcasecmp("-or",search_itr->key) ) {
2255                 char* subpred = searchWHERE( node, meta, OR_OP_JOIN, ctx );
2256                 buffer_fadd(sql_buf, "( %s )", subpred);
2257                 free(subpred);
2258             } else if ( !strcasecmp("-and",search_itr->key) ) {
2259                 char* subpred = searchWHERE( node, meta, AND_OP_JOIN, ctx );
2260                 buffer_fadd(sql_buf, "( %s )", subpred);
2261                 free(subpred);
2262             } else if ( !strcasecmp("-exists",search_itr->key) ) {
2263                 char* subpred = SELECT(
2264                     ctx,
2265                     jsonObjectGetKey( node, "select" ),
2266                     jsonObjectGetKey( node, "from" ),
2267                     jsonObjectGetKey( node, "where" ),
2268                     jsonObjectGetKey( node, "having" ),
2269                     jsonObjectGetKey( node, "order_by" ),
2270                     jsonObjectGetKey( node, "limit" ),
2271                     jsonObjectGetKey( node, "offset" ),
2272                     SUBSELECT
2273                 );
2274
2275                 buffer_fadd(sql_buf, "EXISTS ( %s )", subpred);
2276                 free(subpred);
2277             } else if ( !strcasecmp("-not-exists",search_itr->key) ) {
2278                 char* subpred = SELECT(
2279                     ctx,
2280                     jsonObjectGetKey( node, "select" ),
2281                     jsonObjectGetKey( node, "from" ),
2282                     jsonObjectGetKey( node, "where" ),
2283                     jsonObjectGetKey( node, "having" ),
2284                     jsonObjectGetKey( node, "order_by" ),
2285                     jsonObjectGetKey( node, "limit" ),
2286                     jsonObjectGetKey( node, "offset" ),
2287                     SUBSELECT
2288                 );
2289
2290                 buffer_fadd(sql_buf, "NOT EXISTS ( %s )", subpred);
2291                 free(subpred);
2292             } else {
2293
2294                 char* class = osrfHashGet(meta, "classname");
2295                 osrfHash* fields = osrfHashGet(meta, "fields");
2296                 osrfHash* field = osrfHashGet( fields, search_itr->key );
2297
2298
2299                 if (!field) {
2300                     char* table = getSourceDefinition(meta);
2301                     osrfLogError(
2302                         OSRF_LOG_MARK,
2303                         "%s: Attempt to reference non-existent column %s on %s (%s)",
2304                         MODULENAME,
2305                         search_itr->key,
2306                         table,
2307                         class
2308                     );
2309                     buffer_free(sql_buf);
2310                     free(table);
2311                                         jsonIteratorFree(search_itr);
2312                                         return NULL;
2313                 }
2314
2315                 char* subpred = searchPredicate( class, field, node, ctx );
2316                 buffer_add( sql_buf, subpred );
2317                 free(subpred);
2318             }
2319         }
2320             jsonIteratorFree(search_itr);
2321
2322     } else {
2323         // ERROR ... only hash and array allowed at this level
2324         char* predicate_string = jsonObjectToJSON( search_hash );
2325         osrfLogError(
2326             OSRF_LOG_MARK,
2327             "%s: Invalid predicate structure: %s",
2328             MODULENAME,
2329             predicate_string
2330         );
2331         buffer_free(sql_buf);
2332         free(predicate_string);
2333         return NULL;
2334     }
2335
2336
2337         return buffer_release(sql_buf);
2338 }
2339
2340 char* SELECT (
2341                 /* method context */ osrfMethodContext* ctx,
2342                 
2343                 /* SELECT   */ jsonObject* selhash,
2344                 /* FROM     */ jsonObject* join_hash,
2345                 /* WHERE    */ jsonObject* search_hash,
2346                 /* HAVING   */ jsonObject* having_hash,
2347                 /* ORDER BY */ jsonObject* order_hash,
2348                 /* LIMIT    */ jsonObject* limit,
2349                 /* OFFSET   */ jsonObject* offset,
2350                 /* flags    */ int flags
2351 ) {
2352         const char* locale = osrf_message_get_last_locale();
2353
2354         // in case we don't get a select list
2355         jsonObject* defaultselhash = NULL;
2356
2357         // general tmp objects
2358         const jsonObject* tmp_const;
2359         jsonObject* selclass = NULL;
2360         jsonObject* selfield = NULL;
2361         jsonObject* snode = NULL;
2362         jsonObject* onode = NULL;
2363
2364         char* string = NULL;
2365         int from_function = 0;
2366         int first = 1;
2367         int gfirst = 1;
2368         //int hfirst = 1;
2369
2370         // the core search class
2371         char* core_class = NULL;
2372
2373         // metadata about the core search class
2374         osrfHash* core_meta = NULL;
2375
2376         // punt if there's no core class
2377         if (!join_hash || ( join_hash->type == JSON_HASH && !join_hash->size ))
2378                 return NULL;
2379
2380         // get the core class -- the only key of the top level FROM clause, or a string
2381         if (join_hash->type == JSON_HASH) {
2382                 jsonIterator* tmp_itr = jsonNewIterator( join_hash );
2383                 snode = jsonIteratorNext( tmp_itr );
2384                 
2385                 core_class = strdup( tmp_itr->key );
2386                 join_hash = snode;
2387                 
2388                 jsonObject* extra = jsonIteratorNext( tmp_itr );
2389
2390                 jsonIteratorFree( tmp_itr );
2391                 snode = NULL;
2392                 
2393                 // There shouldn't be more than one entry in join_hash
2394                 if( extra )
2395                         return NULL;    // Malformed join_hash; extra entry
2396
2397         } else if (join_hash->type == JSON_ARRAY) {
2398                 from_function = 1;
2399                 core_class = jsonObjectToSimpleString( jsonObjectGetIndex(join_hash, 0) );
2400                 selhash = NULL;
2401
2402         } else if (join_hash->type == JSON_STRING) {
2403                 core_class = jsonObjectToSimpleString( join_hash );
2404                 join_hash = NULL;
2405         }
2406         else
2407                 return NULL;
2408
2409         // punt if we don't know about the core class (and it's not a function)
2410         if (!from_function && !(core_meta = osrfHashGet( oilsIDL(), core_class ))) {
2411                 free(core_class);
2412                 return NULL;
2413         }
2414
2415         // if the select list is empty, or the core class field list is '*',
2416         // build the default select list ...
2417         if (!selhash) {
2418                 selhash = defaultselhash = jsonNewObjectType(JSON_HASH);
2419                 jsonObjectSetKey( selhash, core_class, jsonNewObjectType(JSON_ARRAY) );
2420         } else if ( (tmp_const = jsonObjectGetKeyConst( selhash, core_class )) && tmp_const->type == JSON_STRING ) {
2421                 char* _x = jsonObjectToSimpleString( tmp_const );
2422                 if (!strncmp( "*", _x, 1 )) {
2423                         jsonObjectRemoveKey( selhash, core_class );
2424                         jsonObjectSetKey( selhash, core_class, jsonNewObjectType(JSON_ARRAY) );
2425                 }
2426                 free(_x);
2427         }
2428
2429         // the query buffer
2430         growing_buffer* sql_buf = buffer_init(128);
2431
2432         // temp buffer for the SELECT list
2433         growing_buffer* select_buf = buffer_init(128);
2434         growing_buffer* order_buf = buffer_init(128);
2435         growing_buffer* group_buf = buffer_init(128);
2436         growing_buffer* having_buf = buffer_init(128);
2437
2438         // Build a select list
2439         if(from_function)   // From a function we select everything
2440                 OSRF_BUFFER_ADD_CHAR( select_buf, '*' );
2441         else {
2442
2443                 // If we need to build a default list, do so
2444                 jsonObject* _tmp = jsonObjectGetKey( selhash, core_class );
2445                 if ( _tmp && !_tmp->size ) {
2446
2447                         int i = 0;
2448                         char* field;
2449                         osrfHash* core_fields = osrfHashGet( core_meta, "fields" );
2450
2451                 osrfStringArray* keys = osrfHashKeys( core_fields );
2452                         while ( (field = osrfStringArrayGetString(keys, i++)) ) {
2453                                 if( ! str_is_true( osrfHashGet( osrfHashGet( core_fields, field ), "virtual" ) ) )
2454                                         jsonObjectPush( _tmp, jsonNewObject( field ) );   // not virtual; use it
2455                 }
2456                         osrfStringArrayFree(keys);
2457                 }
2458         
2459                 // Now build the actual select list
2460             int sel_pos = 1;
2461             jsonObject* is_agg = jsonObjectFindPath(selhash, "//aggregate");
2462             first = 1;
2463             gfirst = 1;
2464             jsonIterator* selclass_itr = jsonNewIterator( selhash );
2465             while ( (selclass = jsonIteratorNext( selclass_itr )) ) {    // For each class
2466
2467                     // round trip through the idl, just to be safe
2468                         const char* cname = selclass_itr->key;
2469                         osrfHash* idlClass = osrfHashGet( oilsIDL(), cname );
2470                     if (!idlClass)
2471                                 // No such class.  Skip it.
2472                                 continue;
2473
2474                     // Make sure the target relation is in the join tree.
2475                         
2476                         // At this point join_hash is a step down from the join_hash we
2477                         // received as a parameter.  If the original was a JSON_STRING,
2478                         // then json_hash is now NULL.  If the original was a JSON_HASH,
2479                         // then json_hash is now the first (and only) entry in it,
2480                         // denoting the core class.  We've already excluded the
2481                         // possibility that the original was a JSON_ARRAY, because in
2482                         // that case from_function would be non-NULL, and we wouldn't
2483                         // be here.
2484
2485                     if ( strcmp( core_class, cname )) {
2486                             if (!join_hash) 
2487                                         // There's only one class in the FROM clause,
2488                                         // and this isn't it.  Skip it.
2489                                         continue;
2490
2491                                 if (join_hash->type == JSON_STRING) {
2492                                     string = jsonObjectToSimpleString(join_hash);
2493                                         int different = strcmp( string, cname );
2494                                     free(string);
2495                                         if ( different )
2496                                                 // There's only one class in the FROM clause,
2497                                                 // and this isn't it.  Skip it.
2498                                                 continue;
2499                                 } else {
2500                                     jsonObject* found = jsonObjectFindPath(join_hash, "//%s", cname);
2501                                         unsigned long size = found->size;
2502                                         jsonObjectFree( found );
2503                                         if ( 0 == size )
2504                                                 // No such class anywhere in the join tree.  Skip it.
2505                                                 continue;
2506                                 }
2507                     }
2508
2509                         // Look up some attributes of the current class, so that we 
2510                         // don't have to look them up again for each field
2511                         osrfHash* class_field_set = osrfHashGet( idlClass, "fields" );
2512                         char* class_pkey = osrfHashGet( idlClass, "primarykey" );
2513                         char* class_tname = osrfHashGet( idlClass, "tablename" );
2514                         
2515                     // stitch together the column list ...
2516                     jsonIterator* select_itr = jsonNewIterator( selclass );
2517                     while ( (selfield = jsonIteratorNext( select_itr )) ) {   // for each SELECT column
2518
2519                                 // If we need a separator comma, add one
2520                                 if (first) {
2521                                         first = 0;
2522                                 } else {
2523                                         OSRF_BUFFER_ADD_CHAR( select_buf, ',' );
2524                                 }
2525
2526                             // ... if it's a string, just toss it on the pile
2527                             if (selfield->type == JSON_STRING) {
2528
2529                                     // again, just to be safe
2530                                         const char* _requested_col = selfield->value.s;
2531                                     osrfHash* field = osrfHashGet( class_field_set, _requested_col );
2532                                     if (!field) continue;               // No such field in current class; skip it
2533
2534                                         const char* col_name = osrfHashGet(field, "name");
2535
2536                     if (locale) {
2537                             const char* i18n;
2538                                     if (flags & DISABLE_I18N)
2539                             i18n = NULL;
2540                                                 else
2541                                                         i18n = osrfHashGet(field, "i18n");
2542
2543                                                 if( str_is_true( i18n ) ) {
2544                             buffer_fadd( select_buf,
2545                                                                 " oils_i18n_xlate('%s', '%s', '%s', '%s', \"%s\".%s::TEXT, '%s') AS \"%s\"",
2546                                                                 class_tname, cname, col_name, class_pkey, cname, class_pkey, locale, col_name );
2547                         } else {
2548                                             buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, col_name, col_name );
2549                         }
2550                     } else {
2551                                         buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, col_name, col_name );
2552                     }
2553                                         
2554                             // ... but it could be an object, in which case we check for a Field Transform
2555                             } else {
2556
2557                                     char* _column = jsonObjectToSimpleString( jsonObjectGetKeyConst( selfield, "column" ) );
2558
2559                                     // Get the field definition from the IDL
2560                                     osrfHash* field = osrfHashGet( class_field_set, _column );
2561                                     if (!field) continue;         // No such field defined in IDL.  Skip it.
2562
2563                                         // Decide what to use as a column alias
2564                                         char* _alias;
2565                                         if ((tmp_const = jsonObjectGetKeyConst( selfield, "alias" ))) {
2566                                                 _alias = jsonObjectToSimpleString( tmp_const );
2567                                                 free(_column);
2568                                         } else {         // Use column name as its own alias
2569                                                 _alias = _column;
2570                                         }
2571                                         _column = NULL;   // To emphasize that we're through with _column
2572
2573                                         if (jsonObjectGetKeyConst( selfield, "transform" )) {
2574                                                 char* transform_str = searchFieldTransform(cname, field, selfield);
2575                                                 buffer_fadd(select_buf, " %s AS \"%s\"", transform_str, _alias);
2576                                                 free(transform_str);
2577                                         } else {
2578
2579                                                 const char* fname = osrfHashGet(field, "name");
2580
2581                         if (locale) {
2582                                     const char* i18n;
2583                                         if (flags & DISABLE_I18N)
2584                                 i18n = NULL;
2585                                                         else
2586                                                                 i18n = osrfHashGet(field, "i18n");
2587
2588                                                         if( str_is_true( i18n ) ) {
2589                                 buffer_fadd( select_buf,
2590                                                                         " oils_i18n_xlate('%s', '%s', '%s', '%s', \"%s\".%s::TEXT, '%s') AS \"%s\"",
2591                                                                         class_tname, cname, fname, class_pkey, cname, class_pkey, locale, _alias);
2592                             } else {
2593                                                     buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, fname, _alias);
2594                             }
2595                         } else {
2596                                                 buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, fname, _alias);
2597                         }
2598                                     }
2599
2600                                     free(_alias);
2601                             }
2602
2603                             if (is_agg->size || (flags & SELECT_DISTINCT)) {
2604
2605                                         const jsonObject* aggregate_obj = jsonObjectGetKey( selfield, "aggregate" );
2606                                     if ( ! obj_is_true( aggregate_obj ) ) {
2607                                             if (gfirst) {
2608                                                     gfirst = 0;
2609                                             } else {
2610                                                         OSRF_BUFFER_ADD_CHAR( group_buf, ',' );
2611                                             }
2612
2613                                             buffer_fadd(group_buf, " %d", sel_pos);
2614                                         /*
2615                                     } else if (is_agg = jsonObjectGetKey( selfield, "having" )) {
2616                                             if (gfirst) {
2617                                                     gfirst = 0;
2618                                             } else {
2619                                                         OSRF_BUFFER_ADD_CHAR( group_buf, ',' );
2620                                             }
2621
2622                                             _column = searchFieldTransform(cname, field, selfield);
2623                                                 OSRF_BUFFER_ADD_CHAR(group_buf, ' ');
2624                                                 OSRF_BUFFER_ADD(group_buf, _column);
2625                                             _column = searchFieldTransform(cname, field, selfield);
2626                                         */
2627                                     }
2628                             }
2629
2630                             sel_pos++;
2631                     } // end while -- iterating across SELECT columns
2632
2633             jsonIteratorFree(select_itr);
2634             } // end while -- iterating across classes
2635
2636         jsonIteratorFree(selclass_itr);
2637
2638             if (is_agg) jsonObjectFree(is_agg);
2639     }
2640
2641
2642         char* col_list = buffer_release(select_buf);
2643         char* table = NULL;
2644         if (from_function) table = searchValueTransform(join_hash);
2645         else table = getSourceDefinition(core_meta);
2646
2647         // Put it all together
2648         buffer_fadd(sql_buf, "SELECT %s FROM %s AS \"%s\" ", col_list, table, core_class );
2649         free(col_list);
2650         free(table);
2651
2652     if (!from_function) {
2653             // Now, walk the join tree and add that clause
2654             if ( join_hash ) {
2655                     char* join_clause = searchJOIN( join_hash, core_meta );
2656                     buffer_add(sql_buf, join_clause);
2657                     free(join_clause);
2658             }
2659
2660                 // Build a WHERE clause, if there is one
2661             if ( search_hash ) {
2662                     buffer_add(sql_buf, " WHERE ");
2663
2664                     // and it's on the WHERE clause
2665                     char* pred = searchWHERE( search_hash, core_meta, AND_OP_JOIN, ctx );
2666
2667                     if (pred) {
2668                                 buffer_add(sql_buf, pred);
2669                                 free(pred);
2670                         } else {
2671                                 if (ctx) {
2672                                 osrfAppSessionStatus(
2673                                         ctx->session,
2674                                         OSRF_STATUS_INTERNALSERVERERROR,
2675                                         "osrfMethodException",
2676                                         ctx->request,
2677                                         "Severe query error in WHERE predicate -- see error log for more details"
2678                                 );
2679                             }
2680                             free(core_class);
2681                             buffer_free(having_buf);
2682                             buffer_free(group_buf);
2683                             buffer_free(order_buf);
2684                             buffer_free(sql_buf);
2685                             if (defaultselhash) jsonObjectFree(defaultselhash);
2686                             return NULL;
2687                     }
2688         }
2689
2690                 // Build a HAVING clause, if there is one
2691             if ( having_hash ) {
2692                     buffer_add(sql_buf, " HAVING ");
2693
2694                     // and it's on the the WHERE clause
2695                     char* pred = searchWHERE( having_hash, core_meta, AND_OP_JOIN, ctx );
2696
2697                     if (pred) {
2698                                 buffer_add(sql_buf, pred);
2699                                 free(pred);
2700                         } else {
2701                                 if (ctx) {
2702                                 osrfAppSessionStatus(
2703                                         ctx->session,
2704                                         OSRF_STATUS_INTERNALSERVERERROR,
2705                                         "osrfMethodException",
2706                                         ctx->request,
2707                                         "Severe query error in HAVING predicate -- see error log for more details"
2708                                 );
2709                             }
2710                             free(core_class);
2711                             buffer_free(having_buf);
2712                             buffer_free(group_buf);
2713                             buffer_free(order_buf);
2714                             buffer_free(sql_buf);
2715                             if (defaultselhash) jsonObjectFree(defaultselhash);
2716                             return NULL;
2717                     }
2718             }
2719
2720                 // Build an ORDER BY clause, if there is one
2721             first = 1;
2722             jsonIterator* class_itr = jsonNewIterator( order_hash );
2723             while ( (snode = jsonIteratorNext( class_itr )) ) {
2724
2725                     if (!jsonObjectGetKeyConst(selhash,class_itr->key))
2726                             continue;
2727
2728                     if ( snode->type == JSON_HASH ) {
2729
2730                         jsonIterator* order_itr = jsonNewIterator( snode );
2731                             while ( (onode = jsonIteratorNext( order_itr )) ) {
2732
2733                                     if (!oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ))
2734                                             continue;
2735
2736                                     char* direction = NULL;
2737                                     if ( onode->type == JSON_HASH ) {
2738                                             if ( jsonObjectGetKeyConst( onode, "transform" ) ) {
2739                                                     string = searchFieldTransform(
2740                                                             class_itr->key,
2741                                                             oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ),
2742                                                             onode
2743                                                     );
2744                                             } else {
2745                                                     growing_buffer* field_buf = buffer_init(16);
2746                                                     buffer_fadd(field_buf, "\"%s\".%s", class_itr->key, order_itr->key);
2747                                                     string = buffer_release(field_buf);
2748                                             }
2749
2750                                             if ( (tmp_const = jsonObjectGetKeyConst( onode, "direction" )) ) {
2751                                                     direction = jsonObjectToSimpleString(tmp_const);
2752                                                     if (!strncasecmp(direction, "d", 1)) {
2753                                                             free(direction);
2754                                                             direction = " DESC";
2755                                                     } else {
2756                                                             free(direction);
2757                                                             direction = " ASC";
2758                                                     }
2759                                             }
2760
2761                                     } else {
2762                                             string = strdup(order_itr->key);
2763                                             direction = jsonObjectToSimpleString(onode);
2764                                             if (!strncasecmp(direction, "d", 1)) {
2765                                                     free(direction);
2766                                                     direction = " DESC";
2767                                             } else {
2768                                                     free(direction);
2769                                                     direction = " ASC";
2770                                             }
2771                                     }
2772
2773                                     if (first) {
2774                                             first = 0;
2775                                     } else {
2776                                             buffer_add(order_buf, ", ");
2777                                     }
2778
2779                                     buffer_add(order_buf, string);
2780                                     free(string);
2781
2782                                     if (direction) {
2783                                             buffer_add(order_buf, direction);
2784                                     }
2785
2786                             } // end while
2787                 // jsonIteratorFree(order_itr);
2788
2789                     } else if ( snode->type == JSON_ARRAY ) {
2790
2791                         jsonIterator* order_itr = jsonNewIterator( snode );
2792                             while ( (onode = jsonIteratorNext( order_itr )) ) {
2793
2794                                     char* _f = jsonObjectToSimpleString( onode );
2795
2796                                     if (!oilsIDLFindPath( "/%s/fields/%s", class_itr->key, _f))
2797                                             continue;
2798
2799                                     if (first) {
2800                                             first = 0;
2801                                     } else {
2802                                             buffer_add(order_buf, ", ");
2803                                     }
2804
2805                                     buffer_add(order_buf, _f);
2806                                     free(_f);
2807
2808                             } // end while
2809                 // jsonIteratorFree(order_itr);
2810
2811
2812                     // IT'S THE OOOOOOOOOOOLD STYLE!
2813                     } else {
2814                             osrfLogError(OSRF_LOG_MARK, "%s: Possible SQL injection attempt; direct order by is not allowed", MODULENAME);
2815                             if (ctx) {
2816                                 osrfAppSessionStatus(
2817                                         ctx->session,
2818                                         OSRF_STATUS_INTERNALSERVERERROR,
2819                                         "osrfMethodException",
2820                                         ctx->request,
2821                                         "Severe query error -- see error log for more details"
2822                                 );
2823                             }
2824
2825                             free(core_class);
2826                             buffer_free(having_buf);
2827                             buffer_free(group_buf);
2828                             buffer_free(order_buf);
2829                             buffer_free(sql_buf);
2830                             if (defaultselhash) jsonObjectFree(defaultselhash);
2831                             jsonIteratorFree(class_itr);
2832                             return NULL;
2833                     }
2834
2835             } // end while
2836                 // jsonIteratorFree(class_itr);
2837         }
2838
2839
2840         string = buffer_release(group_buf);
2841
2842         if (strlen(string)) {
2843                 OSRF_BUFFER_ADD( sql_buf, " GROUP BY " );
2844                 OSRF_BUFFER_ADD( sql_buf, string );
2845         }
2846
2847         free(string);
2848
2849         string = buffer_release(having_buf);
2850  
2851         if (strlen(string)) {
2852                 OSRF_BUFFER_ADD( sql_buf, " HAVING " );
2853                 OSRF_BUFFER_ADD( sql_buf, string );
2854         }
2855
2856         free(string);
2857
2858         string = buffer_release(order_buf);
2859
2860         if (strlen(string)) {
2861                 OSRF_BUFFER_ADD( sql_buf, " ORDER BY " );
2862                 OSRF_BUFFER_ADD( sql_buf, string );
2863         }
2864
2865         free(string);
2866
2867         if ( limit ){
2868                 string = jsonObjectToSimpleString(limit);
2869                 buffer_fadd( sql_buf, " LIMIT %d", atoi(string) );
2870                 free(string);
2871         }
2872
2873         if (offset) {
2874                 string = jsonObjectToSimpleString(offset);
2875                 buffer_fadd( sql_buf, " OFFSET %d", atoi(string) );
2876                 free(string);
2877         }
2878
2879         if (!(flags & SUBSELECT)) OSRF_BUFFER_ADD_CHAR(sql_buf, ';');
2880
2881         free(core_class);
2882         if (defaultselhash) jsonObjectFree(defaultselhash);
2883
2884         return buffer_release(sql_buf);
2885
2886 }
2887
2888 static char* buildSELECT ( jsonObject* search_hash, jsonObject* order_hash, osrfHash* meta, osrfMethodContext* ctx ) {
2889
2890         const char* locale = osrf_message_get_last_locale();
2891
2892         osrfHash* fields = osrfHashGet(meta, "fields");
2893         char* core_class = osrfHashGet(meta, "classname");
2894
2895         const jsonObject* join_hash = jsonObjectGetKeyConst( order_hash, "join" );
2896
2897         jsonObject* node = NULL;
2898         jsonObject* snode = NULL;
2899         jsonObject* onode = NULL;
2900         const jsonObject* _tmp = NULL;
2901         jsonObject* selhash = NULL;
2902         jsonObject* defaultselhash = NULL;
2903
2904         growing_buffer* sql_buf = buffer_init(128);
2905         growing_buffer* select_buf = buffer_init(128);
2906
2907         if ( !(selhash = jsonObjectGetKey( order_hash, "select" )) ) {
2908                 defaultselhash = jsonNewObjectType(JSON_HASH);
2909                 selhash = defaultselhash;
2910         }
2911         
2912         if ( !jsonObjectGetKeyConst(selhash,core_class) ) {
2913                 jsonObjectSetKey( selhash, core_class, jsonNewObjectType(JSON_ARRAY) );
2914                 jsonObject* flist = jsonObjectGetKey( selhash, core_class );
2915                 
2916                 int i = 0;
2917                 char* field;
2918
2919                 osrfStringArray* keys = osrfHashKeys( fields );
2920                 while ( (field = osrfStringArrayGetString(keys, i++)) ) {
2921                         if( ! str_is_true( osrfHashGet( osrfHashGet( fields, field ), "virtual" ) ) )
2922                                 jsonObjectPush( flist, jsonNewObject( field ) );
2923                 }
2924                 osrfStringArrayFree(keys);
2925         }
2926
2927         int first = 1;
2928         jsonIterator* class_itr = jsonNewIterator( selhash );
2929         while ( (snode = jsonIteratorNext( class_itr )) ) {
2930
2931                 osrfHash* idlClass = osrfHashGet( oilsIDL(), class_itr->key );
2932                 if (!idlClass) continue;
2933                 char* cname = osrfHashGet(idlClass, "classname");
2934
2935                 if (strcmp(core_class,class_itr->key)) {
2936                         if (!join_hash) continue;
2937
2938                         jsonObject* found =  jsonObjectFindPath(join_hash, "//%s", class_itr->key);
2939                         if (!found->size) {
2940                                 jsonObjectFree(found);
2941                                 continue;
2942                         }
2943
2944                         jsonObjectFree(found);
2945                 }
2946
2947                 jsonIterator* select_itr = jsonNewIterator( snode );
2948                 while ( (node = jsonIteratorNext( select_itr )) ) {
2949                         char* item_str = jsonObjectToSimpleString(node);
2950                         osrfHash* field = osrfHashGet( osrfHashGet( idlClass, "fields" ), item_str );
2951                         free(item_str);
2952                         char* fname = osrfHashGet(field, "name");
2953
2954                         if (!field) continue;
2955
2956                         if (first) {
2957                                 first = 0;
2958                         } else {
2959                                 OSRF_BUFFER_ADD_CHAR(select_buf, ',');
2960                         }
2961
2962             if (locale) {
2963                         const char* i18n;
2964                                 const jsonObject* no_i18n_obj = jsonObjectGetKey( order_hash, "no_i18n" );
2965                                 if ( obj_is_true( no_i18n_obj ) )    // Suppress internationalization?
2966                                         i18n = NULL;
2967                                 else
2968                                         i18n = osrfHashGet(field, "i18n");
2969
2970                                 if( str_is_true( i18n ) ) {
2971                         char* pkey = osrfHashGet(idlClass, "primarykey");
2972                         char* tname = osrfHashGet(idlClass, "tablename");
2973
2974                     buffer_fadd(select_buf, " oils_i18n_xlate('%s', '%s', '%s', '%s', \"%s\".%s::TEXT, '%s') AS \"%s\"", tname, cname, fname, pkey, cname, pkey, locale, fname);
2975                 } else {
2976                                 buffer_fadd(select_buf, " \"%s\".%s", cname, fname);
2977                 }
2978             } else {
2979                             buffer_fadd(select_buf, " \"%s\".%s", cname, fname);
2980             }
2981                 }
2982
2983         jsonIteratorFree(select_itr);
2984         }
2985
2986     jsonIteratorFree(class_itr);
2987
2988         char* col_list = buffer_release(select_buf);
2989         char* table = getSourceDefinition(meta);
2990
2991         buffer_fadd(sql_buf, "SELECT %s FROM %s AS \"%s\"", col_list, table, core_class );
2992         free(col_list);
2993         free(table);
2994
2995         if ( join_hash ) {
2996                 char* join_clause = searchJOIN( join_hash, meta );
2997                 OSRF_BUFFER_ADD_CHAR(sql_buf, ' ');
2998                 OSRF_BUFFER_ADD(sql_buf, join_clause);
2999                 free(join_clause);
3000         }
3001
3002         osrfLogDebug(OSRF_LOG_MARK, "%s pre-predicate SQL =  %s",
3003                                  MODULENAME, OSRF_BUFFER_C_STR(sql_buf));
3004
3005         buffer_add(sql_buf, " WHERE ");
3006
3007         char* pred = searchWHERE( search_hash, meta, AND_OP_JOIN, ctx );
3008         if (!pred) {
3009                 osrfAppSessionStatus(
3010                         ctx->session,
3011                         OSRF_STATUS_INTERNALSERVERERROR,
3012                                 "osrfMethodException",
3013                                 ctx->request,
3014                                 "Severe query error -- see error log for more details"
3015                         );
3016                 buffer_free(sql_buf);
3017                 if(defaultselhash) jsonObjectFree(defaultselhash);
3018                 return NULL;
3019         } else {
3020                 buffer_add(sql_buf, pred);
3021                 free(pred);
3022         }
3023
3024         if (order_hash) {
3025                 char* string = NULL;
3026                 if ( (_tmp = jsonObjectGetKeyConst( order_hash, "order_by" )) ){
3027
3028                         growing_buffer* order_buf = buffer_init(128);
3029
3030                         first = 1;
3031                         jsonIterator* class_itr = jsonNewIterator( _tmp );
3032                         while ( (snode = jsonIteratorNext( class_itr )) ) {
3033
3034                                 if (!jsonObjectGetKeyConst(selhash,class_itr->key))
3035                                         continue;
3036
3037                                 if ( snode->type == JSON_HASH ) {
3038
3039                                         jsonIterator* order_itr = jsonNewIterator( snode );
3040                                         while ( (onode = jsonIteratorNext( order_itr )) ) {
3041
3042                                                 if (!oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ))
3043                                                         continue;
3044
3045                                                 char* direction = NULL;
3046                                                 if ( onode->type == JSON_HASH ) {
3047                                                         if ( jsonObjectGetKeyConst( onode, "transform" ) ) {
3048                                                                 string = searchFieldTransform(
3049                                                                         class_itr->key,
3050                                                                         oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ),
3051                                                                         onode
3052                                                                 );
3053                                                         } else {
3054                                                                 growing_buffer* field_buf = buffer_init(16);
3055                                                                 buffer_fadd(field_buf, "\"%s\".%s", class_itr->key, order_itr->key);
3056                                                                 string = buffer_release(field_buf);
3057                                                         }
3058
3059                                                         if ( (_tmp = jsonObjectGetKeyConst( onode, "direction" )) ) {
3060                                                                 direction = jsonObjectToSimpleString(_tmp);
3061                                                                 if (!strncasecmp(direction, "d", 1)) {
3062                                                                         free(direction);
3063                                                                         direction = " DESC";
3064                                                                 } else {
3065                                                                         free(direction);
3066                                                                         direction = " ASC";
3067                                                                 }
3068                                                         }
3069
3070                                                 } else {
3071                                                         string = strdup(order_itr->key);
3072                                                         direction = jsonObjectToSimpleString(onode);
3073                                                         if (!strncasecmp(direction, "d", 1)) {
3074                                                                 free(direction);
3075                                                                 direction = " DESC";
3076                                                         } else {
3077                                                                 free(direction);
3078                                                                 direction = " ASC";
3079                                                         }
3080                                                 }
3081
3082                                                 if (first) {
3083                                                         first = 0;
3084                                                 } else {
3085                                                         buffer_add(order_buf, ", ");
3086                                                 }
3087
3088                                                 buffer_add(order_buf, string);
3089                                                 free(string);
3090
3091                                                 if (direction) {
3092                                                         buffer_add(order_buf, direction);
3093                                                 }
3094
3095                                         }
3096
3097                     jsonIteratorFree(order_itr);
3098
3099                                 } else {
3100                                         string = jsonObjectToSimpleString(snode);
3101                                         buffer_add(order_buf, string);
3102                                         free(string);
3103                                         break;
3104                                 }
3105
3106                         }
3107
3108             jsonIteratorFree(class_itr);
3109
3110                         string = buffer_release(order_buf);
3111
3112                         if (strlen(string)) {
3113                                 OSRF_BUFFER_ADD( sql_buf, " ORDER BY " );
3114                                 OSRF_BUFFER_ADD( sql_buf, string );
3115                         }
3116
3117                         free(string);
3118                 }
3119
3120                 if ( (_tmp = jsonObjectGetKeyConst( order_hash, "limit" )) ){
3121                         string = jsonObjectToSimpleString(_tmp);
3122                         buffer_fadd(
3123                                 sql_buf,
3124                                 " LIMIT %d",
3125                                 atoi(string)
3126                         );
3127                         free(string);
3128                 }
3129
3130                 _tmp = jsonObjectGetKeyConst( order_hash, "offset" );
3131                 if (_tmp) {
3132                         string = jsonObjectToSimpleString(_tmp);
3133                         buffer_fadd(
3134                                 sql_buf,
3135                                 " OFFSET %d",
3136                                 atoi(string)
3137                         );
3138                         free(string);
3139                 }
3140         }
3141
3142         if (defaultselhash) jsonObjectFree(defaultselhash);
3143
3144         OSRF_BUFFER_ADD_CHAR(sql_buf, ';');
3145         return buffer_release(sql_buf);
3146 }
3147
3148 int doJSONSearch ( osrfMethodContext* ctx ) {
3149         if(osrfMethodVerifyContext( ctx )) {
3150                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
3151                 return -1;
3152         }
3153
3154         osrfLogDebug(OSRF_LOG_MARK, "Recieved query request");
3155
3156         int err = 0;
3157
3158         // XXX for now...
3159         dbhandle = writehandle;
3160
3161         jsonObject* hash = jsonObjectGetIndex(ctx->params, 0);
3162
3163         int flags = 0;
3164
3165         if ( obj_is_true( jsonObjectGetKey( hash, "distinct" ) ) )
3166                 flags |= SELECT_DISTINCT;
3167
3168         if ( obj_is_true( jsonObjectGetKey( hash, "no_i18n" ) ) )
3169                 flags |= DISABLE_I18N;
3170
3171         osrfLogDebug(OSRF_LOG_MARK, "Building SQL ...");
3172         char* sql = SELECT(
3173                         ctx,
3174                         jsonObjectGetKey( hash, "select" ),
3175                         jsonObjectGetKey( hash, "from" ),
3176                         jsonObjectGetKey( hash, "where" ),
3177                         jsonObjectGetKey( hash, "having" ),
3178                         jsonObjectGetKey( hash, "order_by" ),
3179                         jsonObjectGetKey( hash, "limit" ),
3180                         jsonObjectGetKey( hash, "offset" ),
3181                         flags
3182         );
3183
3184         if (!sql) {
3185                 err = -1;
3186                 return err;
3187         }
3188         
3189         osrfLogDebug(OSRF_LOG_MARK, "%s SQL =  %s", MODULENAME, sql);
3190         dbi_result result = dbi_conn_query(dbhandle, sql);
3191
3192         if(result) {
3193                 osrfLogDebug(OSRF_LOG_MARK, "Query returned with no errors");
3194
3195                 if (dbi_result_first_row(result)) {
3196                         /* JSONify the result */
3197                         osrfLogDebug(OSRF_LOG_MARK, "Query returned at least one row");
3198
3199                         do {
3200                                 jsonObject* return_val = oilsMakeJSONFromResult( result );
3201                                 osrfAppRespond( ctx, return_val );
3202                 jsonObjectFree( return_val );
3203                         } while (dbi_result_next_row(result));
3204
3205                 } else {
3206                         osrfLogDebug(OSRF_LOG_MARK, "%s returned no results for query %s", MODULENAME, sql);
3207                 }
3208
3209                 osrfAppRespondComplete( ctx, NULL );
3210
3211                 /* clean up the query */
3212                 dbi_result_free(result); 
3213
3214         } else {
3215                 err = -1;
3216                 osrfLogError(OSRF_LOG_MARK, "%s: Error with query [%s]", MODULENAME, sql);
3217                 osrfAppSessionStatus(
3218                         ctx->session,
3219                         OSRF_STATUS_INTERNALSERVERERROR,
3220                         "osrfMethodException",
3221                         ctx->request,
3222                         "Severe query error -- see error log for more details"
3223                 );
3224         }
3225
3226         free(sql);
3227         return err;
3228 }
3229
3230 static jsonObject* doFieldmapperSearch ( osrfMethodContext* ctx, osrfHash* meta,
3231                 const jsonObject* params, int* err ) {
3232
3233         // XXX for now...
3234         dbhandle = writehandle;
3235
3236         osrfHash* links = osrfHashGet(meta, "links");
3237         osrfHash* fields = osrfHashGet(meta, "fields");
3238         char* core_class = osrfHashGet(meta, "classname");
3239         char* pkey = osrfHashGet(meta, "primarykey");
3240
3241         const jsonObject* _tmp;
3242         jsonObject* obj;
3243         jsonObject* search_hash = jsonObjectGetIndex(params, 0);
3244         jsonObject* order_hash = jsonObjectGetIndex(params, 1);
3245
3246         char* sql = buildSELECT( search_hash, order_hash, meta, ctx );
3247         if (!sql) {
3248                 osrfLogDebug(OSRF_LOG_MARK, "Problem building query, returning NULL");
3249                 *err = -1;
3250                 return NULL;
3251         }
3252         
3253         osrfLogDebug(OSRF_LOG_MARK, "%s SQL =  %s", MODULENAME, sql);
3254
3255         dbi_result result = dbi_conn_query(dbhandle, sql);
3256         if( NULL == result ) {
3257                 osrfLogError(OSRF_LOG_MARK, "%s: Error retrieving %s with query [%s]",
3258                         MODULENAME, osrfHashGet(meta, "fieldmapper"), sql);
3259                 osrfAppSessionStatus(
3260                         ctx->session,
3261                         OSRF_STATUS_INTERNALSERVERERROR,
3262                         "osrfMethodException",
3263                         ctx->request,
3264                         "Severe query error -- see error log for more details"
3265                 );
3266                 *err = -1;
3267                 free(sql);
3268                 return jsonNULL;
3269
3270         } else {
3271                 osrfLogDebug(OSRF_LOG_MARK, "Query returned with no errors");
3272         }
3273
3274         jsonObject* res_list = jsonNewObjectType(JSON_ARRAY);
3275         osrfHash* dedup = osrfNewHash();
3276
3277         if (dbi_result_first_row(result)) {
3278                 /* JSONify the result */
3279                 osrfLogDebug(OSRF_LOG_MARK, "Query returned at least one row");
3280                 do {
3281                         obj = oilsMakeFieldmapperFromResult( result, meta );
3282                         char* pkey_val = oilsFMGetString( obj, pkey );
3283                         if ( osrfHashGet( dedup, pkey_val ) ) {
3284                                 jsonObjectFree(obj);
3285                                 free(pkey_val);
3286                         } else {
3287                                 osrfHashSet( dedup, pkey_val, pkey_val );
3288                                 jsonObjectPush(res_list, obj);
3289                         }
3290                 } while (dbi_result_next_row(result));
3291         } else {
3292                 osrfLogDebug(OSRF_LOG_MARK, "%s returned no results for query %s",
3293                         MODULENAME, sql );
3294         }
3295
3296         osrfHashFree(dedup);
3297         /* clean up the query */
3298         dbi_result_free(result);
3299         free(sql);
3300
3301         if (res_list->size && order_hash) {
3302                 _tmp = jsonObjectGetKeyConst( order_hash, "flesh" );
3303                 if (_tmp) {
3304                         int x = (int)jsonObjectGetNumber(_tmp);
3305                         if (x == -1 || x > max_flesh_depth) x = max_flesh_depth;
3306
3307                         const jsonObject* temp_blob;
3308                         if ((temp_blob = jsonObjectGetKeyConst( order_hash, "flesh_fields" )) && x > 0) {
3309
3310                                 jsonObject* flesh_blob = jsonObjectClone( temp_blob );
3311                                 const jsonObject* flesh_fields = jsonObjectGetKeyConst( flesh_blob, core_class );
3312
3313                                 osrfStringArray* link_fields = NULL;
3314
3315                                 if (flesh_fields) {
3316                                         if (flesh_fields->size == 1) {
3317                                                 char* _t = jsonObjectToSimpleString( jsonObjectGetIndex( flesh_fields, 0 ) );
3318                                                 if (!strcmp(_t,"*")) link_fields = osrfHashKeys( links );
3319                                                 free(_t);
3320                                         }
3321
3322                                         if (!link_fields) {
3323                                                 jsonObject* _f;
3324                                                 link_fields = osrfNewStringArray(1);
3325                                                 jsonIterator* _i = jsonNewIterator( flesh_fields );
3326                                                 while ((_f = jsonIteratorNext( _i ))) {
3327                                                         osrfStringArrayAdd( link_fields, jsonObjectToSimpleString( _f ) );
3328                                                 }
3329                         jsonIteratorFree(_i);
3330                                         }
3331                                 }
3332
3333                                 jsonObject* cur;
3334                                 jsonIterator* itr = jsonNewIterator( res_list );
3335                                 while ((cur = jsonIteratorNext( itr ))) {
3336
3337                                         int i = 0;
3338                                         char* link_field;
3339                                         
3340                                         while ( (link_field = osrfStringArrayGetString(link_fields, i++)) ) {
3341
3342                                                 osrfLogDebug(OSRF_LOG_MARK, "Starting to flesh %s", link_field);
3343
3344                                                 osrfHash* kid_link = osrfHashGet(links, link_field);
3345                                                 if (!kid_link) continue;
3346
3347                                                 osrfHash* field = osrfHashGet(fields, link_field);
3348                                                 if (!field) continue;
3349
3350                                                 osrfHash* value_field = field;
3351
3352                                                 osrfHash* kid_idl = osrfHashGet(oilsIDL(), osrfHashGet(kid_link, "class"));
3353                                                 if (!kid_idl) continue;
3354
3355                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "has_many" ))) { // has_many
3356                                                         value_field = osrfHashGet( fields, osrfHashGet(meta, "primarykey") );
3357                                                 }
3358                                                         
3359                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "might_have" ))) { // might_have
3360                                                         value_field = osrfHashGet( fields, osrfHashGet(meta, "primarykey") );
3361                                                 }
3362
3363                                                 osrfStringArray* link_map = osrfHashGet( kid_link, "map" );
3364
3365                                                 if (link_map->size > 0) {
3366                                                         jsonObject* _kid_key = jsonNewObjectType(JSON_ARRAY);
3367                                                         jsonObjectPush(
3368                                                                 _kid_key,
3369                                                                 jsonNewObject( osrfStringArrayGetString( link_map, 0 ) )
3370                                                         );
3371
3372                                                         jsonObjectSetKey(
3373                                                                 flesh_blob,
3374                                                                 osrfHashGet(kid_link, "class"),
3375                                                                 _kid_key
3376                                                         );
3377                                                 };
3378
3379                                                 osrfLogDebug(
3380                                                         OSRF_LOG_MARK,
3381                                                         "Link field: %s, remote class: %s, fkey: %s, reltype: %s",
3382                                                         osrfHashGet(kid_link, "field"),
3383                                                         osrfHashGet(kid_link, "class"),
3384                                                         osrfHashGet(kid_link, "key"),
3385                                                         osrfHashGet(kid_link, "reltype")
3386                                                 );
3387
3388                                                 jsonObject* fake_params = jsonNewObjectType(JSON_ARRAY);
3389                                                 jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH)); // search hash
3390                                                 jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH)); // order/flesh hash
3391
3392                                                 osrfLogDebug(OSRF_LOG_MARK, "Creating dummy params object...");
3393
3394                                                 char* search_key =
3395                                                 jsonObjectToSimpleString(
3396                                                         jsonObjectGetIndex(
3397                                                                 cur,
3398                                                                 atoi( osrfHashGet(value_field, "array_position") )
3399                                                         )
3400                                                 );
3401
3402                                                 if (!search_key) {
3403                                                         osrfLogDebug(OSRF_LOG_MARK, "Nothing to search for!");
3404                                                         continue;
3405                                                 }
3406                                                         
3407                                                 jsonObjectSetKey(
3408                                                         jsonObjectGetIndex(fake_params, 0),
3409                                                         osrfHashGet(kid_link, "key"),
3410                                                         jsonNewObject( search_key )
3411                                                 );
3412
3413                                                 free(search_key);
3414
3415
3416                                                 jsonObjectSetKey(
3417                                                         jsonObjectGetIndex(fake_params, 1),
3418                                                         "flesh",
3419                                                         jsonNewNumberObject( (double)(x - 1 + link_map->size) )
3420                                                 );
3421
3422                                                 if (flesh_blob)
3423                                                         jsonObjectSetKey( jsonObjectGetIndex(fake_params, 1), "flesh_fields", jsonObjectClone(flesh_blob) );
3424
3425                                                 if (jsonObjectGetKeyConst(order_hash, "order_by")) {
3426                                                         jsonObjectSetKey(
3427                                                                 jsonObjectGetIndex(fake_params, 1),
3428                                                                 "order_by",
3429                                                                 jsonObjectClone(jsonObjectGetKeyConst(order_hash, "order_by"))
3430                                                         );
3431                                                 }
3432
3433                                                 if (jsonObjectGetKeyConst(order_hash, "select")) {
3434                                                         jsonObjectSetKey(
3435                                                                 jsonObjectGetIndex(fake_params, 1),
3436                                                                 "select",
3437                                                                 jsonObjectClone(jsonObjectGetKeyConst(order_hash, "select"))
3438                                                         );
3439                                                 }
3440
3441                                                 jsonObject* kids = doFieldmapperSearch(ctx, kid_idl, fake_params, err);
3442
3443                                                 if(*err) {
3444                                                         jsonObjectFree( fake_params );
3445                                                         osrfStringArrayFree(link_fields);
3446                                                         jsonIteratorFree(itr);
3447                                                         jsonObjectFree(res_list);
3448                                                         jsonObjectFree(flesh_blob);
3449                                                         return jsonNULL;
3450                                                 }
3451
3452                                                 osrfLogDebug(OSRF_LOG_MARK, "Search for %s return %d linked objects", osrfHashGet(kid_link, "class"), kids->size);
3453
3454                                                 jsonObject* X = NULL;
3455                                                 if ( link_map->size > 0 && kids->size > 0 ) {
3456                                                         X = kids;
3457                                                         kids = jsonNewObjectType(JSON_ARRAY);
3458
3459                                                         jsonObject* _k_node;
3460                                                         jsonIterator* _k = jsonNewIterator( X );
3461                                                         while ((_k_node = jsonIteratorNext( _k ))) {
3462                                                                 jsonObjectPush(
3463                                                                         kids,
3464                                                                         jsonObjectClone(
3465                                                                                 jsonObjectGetIndex(
3466                                                                                         _k_node,
3467                                                                                         (unsigned long)atoi(
3468                                                                                                 osrfHashGet(
3469                                                                                                         osrfHashGet(
3470                                                                                                                 osrfHashGet(
3471                                                                                                                         osrfHashGet(
3472                                                                                                                                 oilsIDL(),
3473                                                                                                                                 osrfHashGet(kid_link, "class")
3474                                                                                                                         ),
3475                                                                                                                         "fields"
3476                                                                                                                 ),
3477                                                                                                                 osrfStringArrayGetString( link_map, 0 )
3478                                                                                                         ),
3479                                                                                                         "array_position"
3480                                                                                                 )
3481                                                                                         )
3482                                                                                 )
3483                                                                         )
3484                                                                 );
3485                                                         }
3486                                                         jsonIteratorFree(_k);
3487                                                 }
3488
3489                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "has_a" )) || !(strcmp( osrfHashGet(kid_link, "reltype"), "might_have" ))) {
3490                                                         osrfLogDebug(OSRF_LOG_MARK, "Storing fleshed objects in %s", osrfHashGet(kid_link, "field"));
3491                                                         jsonObjectSetIndex(
3492                                                                 cur,
3493                                                                 (unsigned long)atoi( osrfHashGet( field, "array_position" ) ),
3494                                                                 jsonObjectClone( jsonObjectGetIndex(kids, 0) )
3495                                                         );
3496                                                 }
3497
3498                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "has_many" ))) { // has_many
3499                                                         osrfLogDebug(OSRF_LOG_MARK, "Storing fleshed objects in %s", osrfHashGet(kid_link, "field"));
3500                                                         jsonObjectSetIndex(
3501                                                                 cur,
3502                                                                 (unsigned long)atoi( osrfHashGet( field, "array_position" ) ),
3503                                                                 jsonObjectClone( kids )
3504                                                         );
3505                                                 }
3506
3507                                                 if (X) {
3508                                                         jsonObjectFree(kids);
3509                                                         kids = X;
3510                                                 }
3511
3512                                                 jsonObjectFree( kids );
3513                                                 jsonObjectFree( fake_params );
3514
3515                                                 osrfLogDebug(OSRF_LOG_MARK, "Fleshing of %s complete", osrfHashGet(kid_link, "field"));
3516                                                 osrfLogDebug(OSRF_LOG_MARK, "%s", jsonObjectToJSON(cur));
3517
3518                                         }
3519                                 }
3520                                 jsonObjectFree( flesh_blob );
3521                                 osrfStringArrayFree(link_fields);
3522                                 jsonIteratorFree(itr);
3523                         }
3524                 }
3525         }
3526
3527         return res_list;
3528 }
3529
3530
3531 static jsonObject* doUpdate(osrfMethodContext* ctx, int* err ) {
3532
3533         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
3534 #ifdef PCRUD
3535         jsonObject* target = jsonObjectGetIndex( ctx->params, 1 );
3536 #else
3537         jsonObject* target = jsonObjectGetIndex( ctx->params, 0 );
3538 #endif
3539
3540         if (!verifyObjectClass(ctx, target)) {
3541                 *err = -1;
3542                 return jsonNULL;
3543         }
3544
3545         if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
3546                 osrfAppSessionStatus(
3547                         ctx->session,
3548                         OSRF_STATUS_BADREQUEST,
3549                         "osrfMethodException",
3550                         ctx->request,
3551                         "No active transaction -- required for UPDATE"
3552                 );
3553                 *err = -1;
3554                 return jsonNULL;
3555         }
3556
3557         // The following test is harmless but redundant.  If a class is
3558         // readonly, we don't register an update method for it.
3559         if( str_is_true( osrfHashGet( meta, "readonly" ) ) ) {
3560                 osrfAppSessionStatus(
3561                         ctx->session,
3562                         OSRF_STATUS_BADREQUEST,
3563                         "osrfMethodException",
3564                         ctx->request,
3565                         "Cannot UPDATE readonly class"
3566                 );
3567                 *err = -1;
3568                 return jsonNULL;
3569         }
3570
3571         dbhandle = writehandle;
3572
3573         char* trans_id = osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" );
3574
3575         // Set the last_xact_id
3576         int index = oilsIDL_ntop( target->classname, "last_xact_id" );
3577         if (index > -1) {
3578                 osrfLogDebug(OSRF_LOG_MARK, "Setting last_xact_id to %s on %s at position %d", trans_id, target->classname, index);
3579                 jsonObjectSetIndex(target, index, jsonNewObject(trans_id));
3580         }       
3581
3582         char* pkey = osrfHashGet(meta, "primarykey");
3583         osrfHash* fields = osrfHashGet(meta, "fields");
3584
3585         char* id = oilsFMGetString( target, pkey );
3586
3587         osrfLogDebug(
3588                 OSRF_LOG_MARK,
3589                 "%s updating %s object with %s = %s",
3590                 MODULENAME,
3591                 osrfHashGet(meta, "fieldmapper"),
3592                 pkey,
3593                 id
3594         );
3595
3596         growing_buffer* sql = buffer_init(128);
3597         buffer_fadd(sql,"UPDATE %s SET", osrfHashGet(meta, "tablename"));
3598
3599         int i = 0;
3600         int first = 1;
3601         char* field_name;
3602         osrfStringArray* field_list = osrfHashKeys( fields );
3603         while ( (field_name = osrfStringArrayGetString(field_list, i++)) ) {
3604
3605                 osrfHash* field = osrfHashGet( fields, field_name );
3606
3607                 if(!( strcmp( field_name, pkey ) )) continue;
3608                 if( str_is_true( osrfHashGet(osrfHashGet(fields,field_name), "virtual") ) )
3609                         continue;
3610
3611                 const jsonObject* field_object = oilsFMGetObject( target, field_name );
3612
3613                 char* value;
3614                 if (field_object && field_object->classname) {
3615                         value = oilsFMGetString(
3616                                 field_object,
3617                                 (char*)oilsIDLFindPath("/%s/primarykey", field_object->classname)
3618             );
3619                 } else {
3620                         value = jsonObjectToSimpleString( field_object );
3621                 }
3622
3623                 osrfLogDebug( OSRF_LOG_MARK, "Updating %s object with %s = %s", osrfHashGet(meta, "fieldmapper"), field_name, value);
3624
3625                 if (!field_object || field_object->type == JSON_NULL) {
3626                         if ( !(!( strcmp( osrfHashGet(meta, "classname"), "au" ) ) && !( strcmp( field_name, "passwd" ) )) ) { // arg at the special case!
3627                                 if (first) first = 0;
3628                                 else OSRF_BUFFER_ADD_CHAR(sql, ',');
3629                                 buffer_fadd( sql, " %s = NULL", field_name );
3630                         }
3631                         
3632                 } else if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
3633                         if (first) first = 0;
3634                         else OSRF_BUFFER_ADD_CHAR(sql, ',');
3635
3636                         if ( !strncmp(osrfHashGet(field, "datatype"), "INT", (size_t)3) ) {
3637                                 buffer_fadd( sql, " %s = %ld", field_name, atol(value) );
3638                         } else if ( !strcmp(osrfHashGet(field, "datatype"), "NUMERIC") ) {
3639                                 buffer_fadd( sql, " %s = %f", field_name, atof(value) );
3640                         }
3641
3642                         osrfLogDebug( OSRF_LOG_MARK, "%s is of type %s", field_name, osrfHashGet(field, "datatype"));
3643
3644                 } else {
3645                         if ( dbi_conn_quote_string(dbhandle, &value) ) {
3646                                 if (first) first = 0;
3647                                 else OSRF_BUFFER_ADD_CHAR(sql, ',');
3648                                 buffer_fadd( sql, " %s = %s", field_name, value );
3649
3650                         } else {
3651                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting string [%s]", MODULENAME, value);
3652                                 osrfAppSessionStatus(
3653                                         ctx->session,
3654                                         OSRF_STATUS_INTERNALSERVERERROR,
3655                                         "osrfMethodException",
3656                                         ctx->request,
3657                                         "Error quoting string -- please see the error log for more details"
3658                                 );
3659                                 free(value);
3660                                 free(id);
3661                                 buffer_free(sql);
3662                                 *err = -1;
3663                                 return jsonNULL;
3664                         }
3665                 }
3666
3667                 free(value);
3668                 
3669         }
3670
3671         jsonObject* obj = jsonNewObject(id);
3672
3673         if ( strcmp( osrfHashGet( osrfHashGet( osrfHashGet(meta, "fields"), pkey ), "primitive" ), "number" ) )
3674                 dbi_conn_quote_string(dbhandle, &id);
3675
3676         buffer_fadd( sql, " WHERE %s = %s;", pkey, id );
3677
3678         char* query = buffer_release(sql);
3679         osrfLogDebug(OSRF_LOG_MARK, "%s: Update SQL [%s]", MODULENAME, query);
3680
3681         dbi_result result = dbi_conn_query(dbhandle, query);
3682         free(query);
3683
3684         if (!result) {
3685                 jsonObjectFree(obj);
3686                 obj = jsonNewObject(NULL);
3687                 osrfLogError(
3688                         OSRF_LOG_MARK,
3689                         "%s ERROR updating %s object with %s = %s",
3690                         MODULENAME,
3691                         osrfHashGet(meta, "fieldmapper"),
3692                         pkey,
3693                         id
3694                 );
3695         }
3696
3697         free(id);
3698
3699         return obj;
3700 }
3701
3702 static jsonObject* doDelete(osrfMethodContext* ctx, int* err ) {
3703
3704         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
3705
3706         if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
3707                 osrfAppSessionStatus(
3708                         ctx->session,
3709                         OSRF_STATUS_BADREQUEST,
3710                         "osrfMethodException",
3711                         ctx->request,
3712                         "No active transaction -- required for DELETE"
3713                 );
3714                 *err = -1;
3715                 return jsonNULL;
3716         }
3717
3718         // The following test is harmless but redundant.  If a class is
3719         // readonly, we don't register a delete method for it.
3720         if( str_is_true( osrfHashGet( meta, "readonly" ) ) ) {
3721                 osrfAppSessionStatus(
3722                         ctx->session,
3723                         OSRF_STATUS_BADREQUEST,
3724                         "osrfMethodException",
3725                         ctx->request,
3726                         "Cannot DELETE readonly class"
3727                 );
3728                 *err = -1;
3729                 return jsonNULL;
3730         }
3731
3732         dbhandle = writehandle;
3733
3734         jsonObject* obj;
3735
3736         char* pkey = osrfHashGet(meta, "primarykey");
3737
3738         int _obj_pos = 0;
3739 #ifdef PCRUD
3740                 _obj_pos = 1;
3741 #endif
3742
3743         char* id;
3744         if (jsonObjectGetIndex(ctx->params, _obj_pos)->classname) {
3745                 if (!verifyObjectClass(ctx, jsonObjectGetIndex( ctx->params, _obj_pos ))) {
3746                         *err = -1;
3747                         return jsonNULL;
3748                 }
3749
3750                 id = oilsFMGetString( jsonObjectGetIndex(ctx->params, _obj_pos), pkey );
3751         } else {
3752 #ifdef PCRUD
3753         if (!verifyObjectPCRUD( ctx, NULL )) {
3754                         *err = -1;
3755                         return jsonNULL;
3756         }
3757 #endif
3758                 id = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, _obj_pos));
3759         }
3760
3761         osrfLogDebug(
3762                 OSRF_LOG_MARK,
3763                 "%s deleting %s object with %s = %s",
3764                 MODULENAME,
3765                 osrfHashGet(meta, "fieldmapper"),
3766                 pkey,
3767                 id
3768         );
3769
3770         obj = jsonNewObject(id);
3771
3772         if ( strcmp( osrfHashGet( osrfHashGet( osrfHashGet(meta, "fields"), pkey ), "primitive" ), "number" ) )
3773                 dbi_conn_quote_string(writehandle, &id);
3774
3775         dbi_result result = dbi_conn_queryf(writehandle, "DELETE FROM %s WHERE %s = %s;", osrfHashGet(meta, "tablename"), pkey, id);
3776
3777         if (!result) {
3778                 jsonObjectFree(obj);
3779                 obj = jsonNewObject(NULL);
3780                 osrfLogError(
3781                         OSRF_LOG_MARK,
3782                         "%s ERROR deleting %s object with %s = %s",
3783                         MODULENAME,
3784                         osrfHashGet(meta, "fieldmapper"),
3785                         pkey,
3786                         id
3787                 );
3788         }
3789
3790         free(id);
3791
3792         return obj;
3793
3794 }
3795
3796
3797 static jsonObject* oilsMakeFieldmapperFromResult( dbi_result result, osrfHash* meta) {
3798         if(!(result && meta)) return jsonNULL;
3799
3800         jsonObject* object = jsonNewObject(NULL);
3801         jsonObjectSetClass(object, osrfHashGet(meta, "classname"));
3802
3803         osrfHash* fields = osrfHashGet(meta, "fields");
3804
3805         osrfLogInternal(OSRF_LOG_MARK, "Setting object class to %s ", object->classname);
3806
3807         osrfHash* _f;
3808         time_t _tmp_dt;
3809         char dt_string[256];
3810         struct tm gmdt;
3811
3812         int fmIndex;
3813         int columnIndex = 1;
3814         int attr;
3815         unsigned short type;
3816         const char* columnName;
3817
3818         /* cycle through the column list */
3819         while( (columnName = dbi_result_get_field_name(result, columnIndex++)) ) {
3820
3821                 osrfLogInternal(OSRF_LOG_MARK, "Looking for column named [%s]...", (char*)columnName);
3822
3823                 fmIndex = -1; // reset the position
3824                 
3825                 /* determine the field type and storage attributes */
3826                 type = dbi_result_get_field_type(result, columnName);
3827                 attr = dbi_result_get_field_attribs(result, columnName);
3828
3829                 /* fetch the fieldmapper index */
3830                 if( (_f = osrfHashGet(fields, (char*)columnName)) ) {
3831                         
3832                         if ( str_is_true( osrfHashGet(_f, "virtual") ) )
3833                                 continue;
3834                         
3835                         const char* pos = (char*)osrfHashGet(_f, "array_position");
3836                         if ( !pos ) continue;
3837
3838                         fmIndex = atoi( pos );
3839                         osrfLogInternal(OSRF_LOG_MARK, "... Found column at position [%s]...", pos);
3840                 } else {
3841                         continue;
3842                 }
3843
3844                 if (dbi_result_field_is_null(result, columnName)) {
3845                         jsonObjectSetIndex( object, fmIndex, jsonNewObject(NULL) );
3846                 } else {
3847
3848                         switch( type ) {
3849
3850                                 case DBI_TYPE_INTEGER :
3851
3852                                         if( attr & DBI_INTEGER_SIZE8 ) 
3853                                                 jsonObjectSetIndex( object, fmIndex, 
3854                                                         jsonNewNumberObject(dbi_result_get_longlong(result, columnName)));
3855                                         else 
3856                                                 jsonObjectSetIndex( object, fmIndex, 
3857                                                         jsonNewNumberObject(dbi_result_get_int(result, columnName)));
3858
3859                                         break;
3860
3861                                 case DBI_TYPE_DECIMAL :
3862                                         jsonObjectSetIndex( object, fmIndex, 
3863                                                         jsonNewNumberObject(dbi_result_get_double(result, columnName)));
3864                                         break;
3865
3866                                 case DBI_TYPE_STRING :
3867
3868
3869                                         jsonObjectSetIndex(
3870                                                 object,
3871                                                 fmIndex,
3872                                                 jsonNewObject( dbi_result_get_string(result, columnName) )
3873                                         );
3874
3875                                         break;
3876
3877                                 case DBI_TYPE_DATETIME :
3878
3879                                         memset(dt_string, '\0', sizeof(dt_string));
3880                                         memset(&gmdt, '\0', sizeof(gmdt));
3881
3882                                         _tmp_dt = dbi_result_get_datetime(result, columnName);
3883
3884
3885                                         if (!(attr & DBI_DATETIME_DATE)) {
3886                                                 gmtime_r( &_tmp_dt, &gmdt );
3887                                                 strftime(dt_string, sizeof(dt_string), "%T", &gmdt);
3888                                         } else if (!(attr & DBI_DATETIME_TIME)) {
3889                                                 localtime_r( &_tmp_dt, &gmdt );
3890                                                 strftime(dt_string, sizeof(dt_string), "%F", &gmdt);
3891                                         } else {
3892                                                 localtime_r( &_tmp_dt, &gmdt );
3893                                                 strftime(dt_string, sizeof(dt_string), "%FT%T%z", &gmdt);
3894                                         }
3895
3896                                         jsonObjectSetIndex( object, fmIndex, jsonNewObject(dt_string) );
3897
3898                                         break;
3899
3900                                 case DBI_TYPE_BINARY :
3901                                         osrfLogError( OSRF_LOG_MARK, 
3902                                                 "Can't do binary at column %s : index %d", columnName, columnIndex - 1);
3903                         }
3904                 }
3905         }
3906
3907         return object;
3908 }
3909
3910 static jsonObject* oilsMakeJSONFromResult( dbi_result result ) {
3911         if(!result) return jsonNULL;
3912
3913         jsonObject* object = jsonNewObject(NULL);
3914
3915         time_t _tmp_dt;
3916         char dt_string[256];
3917         struct tm gmdt;
3918
3919         int fmIndex;
3920         int columnIndex = 1;
3921         int attr;
3922         unsigned short type;
3923         const char* columnName;
3924
3925         /* cycle through the column list */
3926         while( (columnName = dbi_result_get_field_name(result, columnIndex++)) ) {
3927
3928                 osrfLogInternal(OSRF_LOG_MARK, "Looking for column named [%s]...", (char*)columnName);
3929
3930                 fmIndex = -1; // reset the position
3931                 
3932                 /* determine the field type and storage attributes */
3933                 type = dbi_result_get_field_type(result, columnName);
3934                 attr = dbi_result_get_field_attribs(result, columnName);
3935
3936                 if (dbi_result_field_is_null(result, columnName)) {
3937                         jsonObjectSetKey( object, columnName, jsonNewObject(NULL) );
3938                 } else {
3939
3940                         switch( type ) {
3941
3942                                 case DBI_TYPE_INTEGER :
3943
3944                                         if( attr & DBI_INTEGER_SIZE8 ) 
3945                                                 jsonObjectSetKey( object, columnName, jsonNewNumberObject(dbi_result_get_longlong(result, columnName)) );
3946                                         else 
3947                                                 jsonObjectSetKey( object, columnName, jsonNewNumberObject(dbi_result_get_int(result, columnName)) );
3948                                         break;
3949
3950                                 case DBI_TYPE_DECIMAL :
3951                                         jsonObjectSetKey( object, columnName, jsonNewNumberObject(dbi_result_get_double(result, columnName)) );
3952                                         break;
3953
3954                                 case DBI_TYPE_STRING :
3955                                         jsonObjectSetKey( object, columnName, jsonNewObject(dbi_result_get_string(result, columnName)) );
3956                                         break;
3957
3958                                 case DBI_TYPE_DATETIME :
3959
3960                                         memset(dt_string, '\0', sizeof(dt_string));
3961                                         memset(&gmdt, '\0', sizeof(gmdt));
3962
3963                                         _tmp_dt = dbi_result_get_datetime(result, columnName);
3964
3965
3966                                         if (!(attr & DBI_DATETIME_DATE)) {
3967                                                 gmtime_r( &_tmp_dt, &gmdt );
3968                                                 strftime(dt_string, sizeof(dt_string), "%T", &gmdt);
3969                                         } else if (!(attr & DBI_DATETIME_TIME)) {
3970                                                 localtime_r( &_tmp_dt, &gmdt );
3971                                                 strftime(dt_string, sizeof(dt_string), "%F", &gmdt);
3972                                         } else {
3973                                                 localtime_r( &_tmp_dt, &gmdt );
3974                                                 strftime(dt_string, sizeof(dt_string), "%FT%T%z", &gmdt);
3975                                         }
3976
3977                                         jsonObjectSetKey( object, columnName, jsonNewObject(dt_string) );
3978                                         break;
3979
3980                                 case DBI_TYPE_BINARY :
3981                                         osrfLogError( OSRF_LOG_MARK, 
3982                                                 "Can't do binary at column %s : index %d", columnName, columnIndex - 1);
3983                         }
3984                 }
3985         }
3986
3987         return object;
3988 }
3989
3990 // Interpret a string as true or false
3991 static int str_is_true( const char* str ) {
3992         if( NULL == str || strcasecmp( str, "true" ) )
3993                 return 0;
3994         else
3995                 return 1;
3996 }
3997
3998 // Interpret a jsonObject as true or false
3999 static int obj_is_true( const jsonObject* obj ) {
4000         if( !obj )
4001                 return 0;
4002         else switch( obj->type )
4003         {
4004                 case JSON_BOOL :
4005                         if( obj->value.b )
4006                                 return 1;
4007                         else
4008                                 return 0;
4009                 case JSON_STRING :
4010                         if( strcasecmp( obj->value.s, "true" ) )
4011                                 return 0;
4012                         else
4013                                 return 1;
4014                 case JSON_NUMBER :          // Support 1/0 for perl's sake
4015                         if( jsonObjectGetNumber( obj ) == 1.0 )
4016                                 return 1;
4017                         else
4018                                 return 0;
4019                 default :
4020                         return 0;
4021         }
4022 }