]> git.evergreen-ils.org Git - Evergreen.git/blob - Open-ILS/src/c-apps/oils_cstore.c
In searchJOIN(): added a bit of sanity checking, to prevent
[Evergreen.git] / Open-ILS / src / c-apps / oils_cstore.c
1 #include "opensrf/osrf_application.h"
2 #include "opensrf/osrf_settings.h"
3 #include "opensrf/osrf_message.h"
4 #include "opensrf/utils.h"
5 #include "opensrf/osrf_json.h"
6 #include "opensrf/log.h"
7 #include "openils/oils_utils.h"
8 #include <dbi/dbi.h>
9
10 #include <time.h>
11 #include <stdlib.h>
12 #include <string.h>
13 #include <unistd.h>
14
15 #ifdef RSTORE
16 #  define MODULENAME "open-ils.reporter-store"
17 #else
18 #  ifdef PCRUD
19 #    define MODULENAME "open-ils.pcrud"
20 #  else
21 #    define MODULENAME "open-ils.cstore"
22 #  endif
23 #endif
24
25 #define SUBSELECT       4
26 #define DISABLE_I18N    2
27 #define SELECT_DISTINCT 1
28 #define AND_OP_JOIN     0
29 #define OR_OP_JOIN      1
30
31 int osrfAppChildInit();
32 int osrfAppInitialize();
33 void osrfAppChildExit();
34
35 static int verifyObjectClass ( osrfMethodContext*, const jsonObject* );
36
37 int beginTransaction ( osrfMethodContext* );
38 int commitTransaction ( osrfMethodContext* );
39 int rollbackTransaction ( osrfMethodContext* );
40
41 int setSavepoint ( osrfMethodContext* );
42 int releaseSavepoint ( osrfMethodContext* );
43 int rollbackSavepoint ( osrfMethodContext* );
44
45 int doJSONSearch ( osrfMethodContext* );
46
47 int dispatchCRUDMethod ( osrfMethodContext* );
48 static jsonObject* doCreate ( osrfMethodContext*, int* );
49 static jsonObject* doRetrieve ( osrfMethodContext*, int* );
50 static jsonObject* doUpdate ( osrfMethodContext*, int* );
51 static jsonObject* doDelete ( osrfMethodContext*, int* );
52 static jsonObject* doFieldmapperSearch ( osrfMethodContext*, osrfHash*,
53         const jsonObject*, int* );
54 static jsonObject* oilsMakeFieldmapperFromResult( dbi_result, osrfHash* );
55 static jsonObject* oilsMakeJSONFromResult( dbi_result );
56
57 static char* searchWriteSimplePredicate ( const char*, osrfHash*,
58         const char*, const char*, const char* );
59 static char* searchSimplePredicate ( const char*, const char*, osrfHash*, const jsonObject* );
60 static char* searchFunctionPredicate ( const char*, osrfHash*, const jsonObject*, const char* );
61 static char* searchFieldTransform ( const char*, osrfHash*, const jsonObject*);
62 static char* searchFieldTransformPredicate ( const char*, osrfHash*, jsonObject*, const char* );
63 static char* searchBETWEENPredicate ( const char*, osrfHash*, jsonObject* );
64 static char* searchINPredicate ( const char*, osrfHash*,
65                                                                  jsonObject*, const char*, osrfMethodContext* );
66 static char* searchPredicate ( const char*, osrfHash*, jsonObject*, osrfMethodContext* );
67 static char* searchJOIN ( const jsonObject*, osrfHash* );
68 static char* searchWHERE ( const jsonObject*, osrfHash*, int, osrfMethodContext* );
69 static char* buildSELECT ( jsonObject*, jsonObject*, osrfHash*, osrfMethodContext* );
70
71 char* SELECT ( osrfMethodContext*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, jsonObject*, int );
72
73 void userDataFree( void* );
74 static void sessionDataFree( char*, void* );
75 static char* getSourceDefinition( osrfHash* );
76 static int str_is_true( const char* str );
77 static int obj_is_true( const jsonObject* obj );
78
79 #ifdef PCRUD
80 static jsonObject* verifyUserPCRUD( osrfMethodContext* );
81 static int verifyObjectPCRUD( osrfMethodContext*, const jsonObject* );
82 #endif
83
84 static dbi_conn writehandle; /* our MASTER db connection */
85 static dbi_conn dbhandle; /* our CURRENT db connection */
86 //static osrfHash * readHandles;
87 static jsonObject* jsonNULL = NULL; // 
88 static int max_flesh_depth = 100;
89
90 /* called when this process is about to exit */
91 void osrfAppChildExit() {
92     osrfLogDebug(OSRF_LOG_MARK, "Child is exiting, disconnecting from database...");
93
94     int same = 0;
95     if (writehandle == dbhandle) same = 1;
96     if (writehandle) {
97         dbi_conn_query(writehandle, "ROLLBACK;");
98         dbi_conn_close(writehandle);
99         writehandle = NULL;
100     }
101     if (dbhandle && !same)
102         dbi_conn_close(dbhandle);
103
104     // XXX add cleanup of readHandles whenever that gets used
105
106     return;
107 }
108
109 int osrfAppInitialize() {
110
111     osrfLogInfo(OSRF_LOG_MARK, "Initializing the CStore Server...");
112     osrfLogInfo(OSRF_LOG_MARK, "Finding XML file...");
113
114     if (!oilsIDLInit( osrf_settings_host_value("/IDL") )) return 1; /* return non-zero to indicate error */
115
116     growing_buffer* method_name = buffer_init(64);
117 #ifndef PCRUD
118     // Generic search thingy
119     buffer_add(method_name, MODULENAME);
120         buffer_add(method_name, ".json_query");
121         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
122                                                    "doJSONSearch", "", 1, OSRF_METHOD_STREAMING );
123 #endif
124
125     // first we register all the transaction and savepoint methods
126     buffer_reset(method_name);
127         OSRF_BUFFER_ADD(method_name, MODULENAME);
128         OSRF_BUFFER_ADD(method_name, ".transaction.begin");
129         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
130                                                    "beginTransaction", "", 0, 0 );
131
132     buffer_reset(method_name);
133         OSRF_BUFFER_ADD(method_name, MODULENAME);
134         OSRF_BUFFER_ADD(method_name, ".transaction.commit");
135         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
136                                                    "commitTransaction", "", 0, 0 );
137
138     buffer_reset(method_name);
139         OSRF_BUFFER_ADD(method_name, MODULENAME);
140         OSRF_BUFFER_ADD(method_name, ".transaction.rollback");
141         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
142                                                    "rollbackTransaction", "", 0, 0 );
143
144     buffer_reset(method_name);
145         OSRF_BUFFER_ADD(method_name, MODULENAME);
146         OSRF_BUFFER_ADD(method_name, ".savepoint.set");
147         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
148                                                    "setSavepoint", "", 1, 0 );
149
150     buffer_reset(method_name);
151         OSRF_BUFFER_ADD(method_name, MODULENAME);
152         OSRF_BUFFER_ADD(method_name, ".savepoint.release");
153         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
154                                                    "releaseSavepoint", "", 1, 0 );
155
156     buffer_reset(method_name);
157         OSRF_BUFFER_ADD(method_name, MODULENAME);
158         OSRF_BUFFER_ADD(method_name, ".savepoint.rollback");
159         osrfAppRegisterMethod( MODULENAME, OSRF_BUFFER_C_STR(method_name),
160                                                    "rollbackSavepoint", "", 1, 0 );
161
162     buffer_free(method_name);
163
164         static const char* global_method[] = {
165                 "create",
166                 "retrieve",
167                 "update",
168                 "delete",
169                 "search",
170                 "id_list"
171         };
172         const int global_method_count
173                 = sizeof( global_method ) / sizeof ( global_method[0] );
174         
175     int c_index = 0; 
176     char* classname;
177     osrfStringArray* classes = osrfHashKeys( oilsIDL() );
178     osrfLogDebug(OSRF_LOG_MARK, "%d classes loaded", classes->size );
179     osrfLogDebug(OSRF_LOG_MARK,
180                 "At least %d methods will be generated", classes->size * global_method_count);
181
182     while ( (classname = osrfStringArrayGetString(classes, c_index++)) ) {
183         osrfLogInfo(OSRF_LOG_MARK, "Generating class methods for %s", classname);
184
185         osrfHash* idlClass = osrfHashGet(oilsIDL(), classname);
186
187         if (!osrfStringArrayContains( osrfHashGet(idlClass, "controller"), MODULENAME )) {
188             osrfLogInfo(OSRF_LOG_MARK, "%s is not listed as a controller for %s, moving on", MODULENAME, classname);
189             continue;
190         }
191
192                 if ( str_is_true( osrfHashGet(idlClass, "virtual") ) ) {
193                         osrfLogDebug(OSRF_LOG_MARK, "Class %s is virtual, skipping", classname );
194                         continue;
195                 }
196
197         // Look up some other attributes of the current class
198         const char* idlClass_fieldmapper = osrfHashGet(idlClass, "fieldmapper");
199                 const char* readonly = osrfHashGet(idlClass, "readonly");
200 #ifdef PCRUD
201         osrfHash* idlClass_permacrud = osrfHashGet(idlClass, "permacrud");
202 #endif
203
204         int i;
205         for( i = 0; i < global_method_count; ++i ) {
206             const char* method_type = global_method[ i ];
207             osrfLogDebug(OSRF_LOG_MARK,
208                 "Using files to build %s class methods for %s", method_type, classname);
209
210             if (!idlClass_fieldmapper) continue;
211
212 #ifdef PCRUD
213             if (!idlClass_permacrud) continue;
214
215             const char* tmp_method = method_type;
216             if ( *tmp_method == 'i' || *tmp_method == 's') {
217                 tmp_method = "retrieve";
218             }
219             if (!osrfHashGet( idlClass_permacrud, tmp_method )) continue;
220 #endif
221
222             if (    str_is_true( readonly ) &&
223                     ( *method_type == 'c' || *method_type == 'u' || *method_type == 'd')
224                ) continue;
225
226             osrfHash* method_meta = osrfNewHash();
227             osrfHashSet(method_meta, idlClass, "class");
228
229             method_name =  buffer_init(64);
230 #ifdef PCRUD
231             buffer_fadd(method_name, "%s.%s.%s", MODULENAME, method_type, classname);
232 #else
233             char* st_tmp = NULL;
234             char* part = NULL;
235             char* _fm = strdup( idlClass_fieldmapper );
236             part = strtok_r(_fm, ":", &st_tmp);
237
238             buffer_fadd(method_name, "%s.direct.%s", MODULENAME, part);
239
240             while ((part = strtok_r(NULL, ":", &st_tmp))) {
241                                 OSRF_BUFFER_ADD_CHAR(method_name, '.');
242                                 OSRF_BUFFER_ADD(method_name, part);
243             }
244                         OSRF_BUFFER_ADD_CHAR(method_name, '.');
245                         OSRF_BUFFER_ADD(method_name, method_type);
246             free(_fm);
247 #endif
248
249             char* method = buffer_release(method_name);
250
251             osrfHashSet( method_meta, method, "methodname" );
252             osrfHashSet( method_meta, strdup(method_type), "methodtype" );
253
254             int flags = 0;
255             if (*method_type == 'i' || *method_type == 's') {
256                 flags = flags | OSRF_METHOD_STREAMING;
257             }
258
259             osrfAppRegisterExtendedMethod(
260                     MODULENAME,
261                     method,
262                     "dispatchCRUDMethod",
263                     "",
264                     1,
265                     flags,
266                     (void*)method_meta
267                     );
268
269             free(method);
270         }
271     }
272
273     return 0;
274 }
275
276 static char* getSourceDefinition( osrfHash* class ) {
277
278     char* tabledef = osrfHashGet(class, "tablename");
279
280     if (!tabledef) {
281         growing_buffer* tablebuf = buffer_init(128);
282         tabledef = osrfHashGet(class, "source_definition");
283         if( !tabledef )
284             tabledef = "(null)";
285         buffer_fadd( tablebuf, "(%s)", tabledef );
286         tabledef = buffer_release(tablebuf);
287     } else {
288         tabledef = strdup(tabledef);
289     }
290
291     return tabledef;
292 }
293
294 /**
295  * Connects to the database 
296  */
297 int osrfAppChildInit() {
298
299     osrfLogDebug(OSRF_LOG_MARK, "Attempting to initialize libdbi...");
300     dbi_initialize(NULL);
301     osrfLogDebug(OSRF_LOG_MARK, "... libdbi initialized.");
302
303     char* driver        = osrf_settings_host_value("/apps/%s/app_settings/driver", MODULENAME);
304     char* user  = osrf_settings_host_value("/apps/%s/app_settings/database/user", MODULENAME);
305     char* host  = osrf_settings_host_value("/apps/%s/app_settings/database/host", MODULENAME);
306     char* port  = osrf_settings_host_value("/apps/%s/app_settings/database/port", MODULENAME);
307     char* db    = osrf_settings_host_value("/apps/%s/app_settings/database/db", MODULENAME);
308     char* pw    = osrf_settings_host_value("/apps/%s/app_settings/database/pw", MODULENAME);
309     char* md    = osrf_settings_host_value("/apps/%s/app_settings/max_query_recursion", MODULENAME);
310
311     osrfLogDebug(OSRF_LOG_MARK, "Attempting to load the database driver [%s]...", driver);
312     writehandle = dbi_conn_new(driver);
313
314     if(!writehandle) {
315         osrfLogError(OSRF_LOG_MARK, "Error loading database driver [%s]", driver);
316         return -1;
317     }
318     osrfLogDebug(OSRF_LOG_MARK, "Database driver [%s] seems OK", driver);
319
320     osrfLogInfo(OSRF_LOG_MARK, "%s connecting to database.  host=%s, "
321             "port=%s, user=%s, pw=%s, db=%s", MODULENAME, host, port, user, pw, db );
322
323     if(host) dbi_conn_set_option(writehandle, "host", host );
324     if(port) dbi_conn_set_option_numeric( writehandle, "port", atoi(port) );
325     if(user) dbi_conn_set_option(writehandle, "username", user);
326     if(pw) dbi_conn_set_option(writehandle, "password", pw );
327     if(db) dbi_conn_set_option(writehandle, "dbname", db );
328
329     if(md) max_flesh_depth = atoi(md);
330     if(max_flesh_depth < 0) max_flesh_depth = 1;
331     if(max_flesh_depth > 1000) max_flesh_depth = 1000;
332
333     free(user);
334     free(host);
335     free(port);
336     free(db);
337     free(pw);
338
339     const char* err;
340     if (dbi_conn_connect(writehandle) < 0) {
341         sleep(1);
342         if (dbi_conn_connect(writehandle) < 0) {
343             dbi_conn_error(writehandle, &err);
344             osrfLogError( OSRF_LOG_MARK, "Error connecting to database: %s", err);
345             return -1;
346         }
347     }
348
349     osrfLogInfo(OSRF_LOG_MARK, "%s successfully connected to the database", MODULENAME);
350
351     int attr;
352     unsigned short type;
353     int i = 0; 
354     char* classname;
355     osrfStringArray* classes = osrfHashKeys( oilsIDL() );
356
357     while ( (classname = osrfStringArrayGetString(classes, i++)) ) {
358         osrfHash* class = osrfHashGet( oilsIDL(), classname );
359         osrfHash* fields = osrfHashGet( class, "fields" );
360
361                 if( str_is_true( osrfHashGet(class, "virtual") ) ) {
362                         osrfLogDebug(OSRF_LOG_MARK, "Class %s is virtual, skipping", classname );
363                         continue;
364                 }
365
366         char* tabledef = getSourceDefinition(class);
367
368         growing_buffer* sql_buf = buffer_init(32);
369         buffer_fadd( sql_buf, "SELECT * FROM %s AS x WHERE 1=0;", tabledef );
370
371         free(tabledef);
372
373         char* sql = buffer_release(sql_buf);
374         osrfLogDebug(OSRF_LOG_MARK, "%s Investigatory SQL = %s", MODULENAME, sql);
375
376         dbi_result result = dbi_conn_query(writehandle, sql);
377         free(sql);
378
379         if (result) {
380
381             int columnIndex = 1;
382             const char* columnName;
383             osrfHash* _f;
384             while( (columnName = dbi_result_get_field_name(result, columnIndex++)) ) {
385
386                 osrfLogInternal(OSRF_LOG_MARK, "Looking for column named [%s]...", (char*)columnName);
387
388                 /* fetch the fieldmapper index */
389                 if( (_f = osrfHashGet(fields, (char*)columnName)) ) {
390
391                     osrfLogDebug(OSRF_LOG_MARK, "Found [%s] in IDL hash...", (char*)columnName);
392
393                     /* determine the field type and storage attributes */
394                     type = dbi_result_get_field_type(result, columnName);
395                     attr = dbi_result_get_field_attribs(result, columnName);
396
397                     switch( type ) {
398
399                         case DBI_TYPE_INTEGER :
400
401                             if ( !osrfHashGet(_f, "primitive") )
402                                 osrfHashSet(_f,"number", "primitive");
403
404                             if( attr & DBI_INTEGER_SIZE8 ) 
405                                 osrfHashSet(_f,"INT8", "datatype");
406                             else 
407                                 osrfHashSet(_f,"INT", "datatype");
408                             break;
409
410                         case DBI_TYPE_DECIMAL :
411                             if ( !osrfHashGet(_f, "primitive") )
412                                 osrfHashSet(_f,"number", "primitive");
413
414                             osrfHashSet(_f,"NUMERIC", "datatype");
415                             break;
416
417                         case DBI_TYPE_STRING :
418                             if ( !osrfHashGet(_f, "primitive") )
419                                 osrfHashSet(_f,"string", "primitive");
420                             osrfHashSet(_f,"TEXT", "datatype");
421                             break;
422
423                         case DBI_TYPE_DATETIME :
424                             if ( !osrfHashGet(_f, "primitive") )
425                                 osrfHashSet(_f,"string", "primitive");
426
427                             osrfHashSet(_f,"TIMESTAMP", "datatype");
428                             break;
429
430                         case DBI_TYPE_BINARY :
431                             if ( !osrfHashGet(_f, "primitive") )
432                                 osrfHashSet(_f,"string", "primitive");
433
434                             osrfHashSet(_f,"BYTEA", "datatype");
435                     }
436
437                     osrfLogDebug(
438                             OSRF_LOG_MARK,
439                             "Setting [%s] to primitive [%s] and datatype [%s]...",
440                             (char*)columnName,
441                             osrfHashGet(_f, "primitive"),
442                             osrfHashGet(_f, "datatype")
443                             );
444                 }
445             }
446             dbi_result_free(result);
447         } else {
448             osrfLogDebug(OSRF_LOG_MARK, "No data found for class [%s]...", (char*)classname);
449         }
450     }
451
452     osrfStringArrayFree(classes);
453
454     return 0;
455 }
456
457 void userDataFree( void* blob ) {
458     osrfHashFree( (osrfHash*)blob );
459     return;
460 }
461
462 static void sessionDataFree( char* key, void* item ) {
463     if (!(strcmp(key,"xact_id"))) {
464         if (writehandle)
465             dbi_conn_query(writehandle, "ROLLBACK;");
466         free(item);
467     }
468
469     return;
470 }
471
472 int beginTransaction ( osrfMethodContext* ctx ) {
473         if(osrfMethodVerifyContext( ctx )) {
474                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
475                 return -1;
476         }
477
478 #ifdef PCRUD
479     jsonObject* user = verifyUserPCRUD( ctx );
480     if (!user) return -1;
481     jsonObjectFree(user);
482 #endif
483
484     dbi_result result = dbi_conn_query(writehandle, "START TRANSACTION;");
485     if (!result) {
486         osrfLogError(OSRF_LOG_MARK, "%s: Error starting transaction", MODULENAME );
487         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error starting transaction" );
488         return -1;
489     } else {
490         jsonObject* ret = jsonNewObject(ctx->session->session_id);
491         osrfAppRespondComplete( ctx, ret );
492         jsonObjectFree(ret);
493
494         if (!ctx->session->userData) {
495             ctx->session->userData = osrfNewHash();
496             osrfHashSetCallback((osrfHash*)ctx->session->userData, &sessionDataFree);
497         }
498
499         osrfHashSet( (osrfHash*)ctx->session->userData, strdup( ctx->session->session_id ), "xact_id" );
500         ctx->session->userDataFree = &userDataFree;
501
502     }
503     return 0;
504 }
505
506 int setSavepoint ( osrfMethodContext* ctx ) {
507         if(osrfMethodVerifyContext( ctx )) {
508                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
509                 return -1;
510         }
511
512     int spNamePos = 0;
513 #ifdef PCRUD
514     spNamePos = 1;
515     jsonObject* user = verifyUserPCRUD( ctx );
516     if (!user) return -1;
517     jsonObjectFree(user);
518 #endif
519
520     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
521         osrfAppSessionStatus(
522                 ctx->session,
523                 OSRF_STATUS_INTERNALSERVERERROR,
524                 "osrfMethodException",
525                 ctx->request,
526                 "No active transaction -- required for savepoints"
527                 );
528         return -1;
529     }
530
531     char* spName = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, spNamePos));
532
533     dbi_result result = dbi_conn_queryf(writehandle, "SAVEPOINT \"%s\";", spName);
534     if (!result) {
535         osrfLogError(
536                 OSRF_LOG_MARK,
537                 "%s: Error creating savepoint %s in transaction %s",
538                 MODULENAME,
539                 spName,
540                 osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )
541                 );
542         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error creating savepoint" );
543         free(spName);
544         return -1;
545     } else {
546         jsonObject* ret = jsonNewObject(spName);
547         osrfAppRespondComplete( ctx, ret );
548         jsonObjectFree(ret);
549     }
550     free(spName);
551     return 0;
552 }
553
554 int releaseSavepoint ( osrfMethodContext* ctx ) {
555         if(osrfMethodVerifyContext( ctx )) {
556                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
557                 return -1;
558         }
559
560         int spNamePos = 0;
561 #ifdef PCRUD
562     spNamePos = 1;
563     jsonObject* user = verifyUserPCRUD( ctx );
564     if (!user) return -1;
565     jsonObjectFree(user);
566 #endif
567
568     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
569         osrfAppSessionStatus(
570                 ctx->session,
571                 OSRF_STATUS_INTERNALSERVERERROR,
572                 "osrfMethodException",
573                 ctx->request,
574                 "No active transaction -- required for savepoints"
575                 );
576         return -1;
577     }
578
579     char* spName = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, spNamePos));
580
581     dbi_result result = dbi_conn_queryf(writehandle, "RELEASE SAVEPOINT \"%s\";", spName);
582     if (!result) {
583         osrfLogError(
584                 OSRF_LOG_MARK,
585                 "%s: Error releasing savepoint %s in transaction %s",
586                 MODULENAME,
587                 spName,
588                 osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )
589                 );
590         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error releasing savepoint" );
591         free(spName);
592         return -1;
593     } else {
594         jsonObject* ret = jsonNewObject(spName);
595         osrfAppRespondComplete( ctx, ret );
596         jsonObjectFree(ret);
597     }
598     free(spName);
599     return 0;
600 }
601
602 int rollbackSavepoint ( osrfMethodContext* ctx ) {
603         if(osrfMethodVerifyContext( ctx )) {
604                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
605                 return -1;
606         }
607
608         int spNamePos = 0;
609 #ifdef PCRUD
610     spNamePos = 1;
611     jsonObject* user = verifyUserPCRUD( ctx );
612     if (!user) return -1;
613     jsonObjectFree(user);
614 #endif
615
616     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
617         osrfAppSessionStatus(
618                 ctx->session,
619                 OSRF_STATUS_INTERNALSERVERERROR,
620                 "osrfMethodException",
621                 ctx->request,
622                 "No active transaction -- required for savepoints"
623                 );
624         return -1;
625     }
626
627     char* spName = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, spNamePos));
628
629     dbi_result result = dbi_conn_queryf(writehandle, "ROLLBACK TO SAVEPOINT \"%s\";", spName);
630     if (!result) {
631         osrfLogError(
632                 OSRF_LOG_MARK,
633                 "%s: Error rolling back savepoint %s in transaction %s",
634                 MODULENAME,
635                 spName,
636                 osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )
637                 );
638         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error rolling back savepoint" );
639         free(spName);
640         return -1;
641     } else {
642         jsonObject* ret = jsonNewObject(spName);
643         osrfAppRespondComplete( ctx, ret );
644         jsonObjectFree(ret);
645     }
646     free(spName);
647     return 0;
648 }
649
650 int commitTransaction ( osrfMethodContext* ctx ) {
651         if(osrfMethodVerifyContext( ctx )) {
652                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
653                 return -1;
654         }
655
656 #ifdef PCRUD
657     jsonObject* user = verifyUserPCRUD( ctx );
658     if (!user) return -1;
659     jsonObjectFree(user);
660 #endif
661
662     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
663         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "No active transaction to commit" );
664         return -1;
665     }
666
667     dbi_result result = dbi_conn_query(writehandle, "COMMIT;");
668     if (!result) {
669         osrfLogError(OSRF_LOG_MARK, "%s: Error committing transaction", MODULENAME );
670         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error committing transaction" );
671         return -1;
672     } else {
673         osrfHashRemove(ctx->session->userData, "xact_id");
674         jsonObject* ret = jsonNewObject(ctx->session->session_id);
675         osrfAppRespondComplete( ctx, ret );
676         jsonObjectFree(ret);
677     }
678     return 0;
679 }
680
681 int rollbackTransaction ( osrfMethodContext* ctx ) {
682         if(osrfMethodVerifyContext( ctx )) {
683                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
684                 return -1;
685         }
686
687 #ifdef PCRUD
688     jsonObject* user = verifyUserPCRUD( ctx );
689     if (!user) return -1;
690     jsonObjectFree(user);
691 #endif
692
693     if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
694         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "No active transaction to roll back" );
695         return -1;
696     }
697
698     dbi_result result = dbi_conn_query(writehandle, "ROLLBACK;");
699     if (!result) {
700         osrfLogError(OSRF_LOG_MARK, "%s: Error rolling back transaction", MODULENAME );
701         osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, "Error rolling back transaction" );
702         return -1;
703     } else {
704         osrfHashRemove(ctx->session->userData, "xact_id");
705         jsonObject* ret = jsonNewObject(ctx->session->session_id);
706         osrfAppRespondComplete( ctx, ret );
707         jsonObjectFree(ret);
708     }
709     return 0;
710 }
711
712 int dispatchCRUDMethod ( osrfMethodContext* ctx ) {
713         if(osrfMethodVerifyContext( ctx )) {
714                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
715                 return -1;
716         }
717
718         osrfHash* meta = (osrfHash*) ctx->method->userData;
719     osrfHash* class_obj = osrfHashGet( meta, "class" );
720
721     int err = 0;
722
723     const char* methodtype = osrfHashGet(meta, "methodtype");
724     jsonObject * obj = NULL;
725
726     if (!strcmp(methodtype, "create")) {
727         obj = doCreate(ctx, &err);
728         osrfAppRespondComplete( ctx, obj );
729     }
730     else if (!strcmp(methodtype, "retrieve")) {
731         obj = doRetrieve(ctx, &err);
732         osrfAppRespondComplete( ctx, obj );
733     }
734     else if (!strcmp(methodtype, "update")) {
735         obj = doUpdate(ctx, &err);
736         osrfAppRespondComplete( ctx, obj );
737     }
738     else if (!strcmp(methodtype, "delete")) {
739         obj = doDelete(ctx, &err);
740         osrfAppRespondComplete( ctx, obj );
741     }
742     else if (!strcmp(methodtype, "search")) {
743
744         jsonObject* _p = jsonObjectClone( ctx->params );
745 #ifdef PCRUD
746         jsonObjectFree(_p);
747         _p = jsonParseString("[]");
748         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 1)));
749         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 2)));
750 #endif
751
752         obj = doFieldmapperSearch(ctx, class_obj, _p, &err);
753
754         jsonObjectFree(_p);
755         if(err) return err;
756
757         jsonObject* cur;
758         jsonIterator* itr = jsonNewIterator( obj );
759         while ((cur = jsonIteratorNext( itr ))) {
760 #ifdef PCRUD
761             if(!verifyObjectPCRUD(ctx, cur)) continue;
762 #endif
763             osrfAppRespond( ctx, cur );
764         }
765         jsonIteratorFree(itr);
766         osrfAppRespondComplete( ctx, NULL );
767
768     } else if (!strcmp(methodtype, "id_list")) {
769
770         jsonObject* _p = jsonObjectClone( ctx->params );
771 #ifdef PCRUD
772         jsonObjectFree(_p);
773         _p = jsonParseString("[]");
774         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 1)));
775         jsonObjectPush(_p, jsonObjectClone(jsonObjectGetIndex(ctx->params, 2)));
776 #endif
777
778         if (jsonObjectGetIndex( _p, 1 )) {
779             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "select" );
780             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "no_i18n" );
781             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "flesh" );
782             jsonObjectRemoveKey( jsonObjectGetIndex( _p, 1 ), "flesh_columns" );
783         } else {
784             jsonObjectSetIndex( _p, 1, jsonNewObjectType(JSON_HASH) );
785         }
786
787                 jsonObjectSetKey( jsonObjectGetIndex( _p, 1 ), "no_i18n", jsonNewBoolObject( 1 ) );
788
789         jsonObjectSetKey(
790             jsonObjectGetIndex( _p, 1 ),
791             "select",
792             jsonParseStringFmt(
793                 "{ \"%s\":[\"%s\"] }",
794                 osrfHashGet( class_obj, "classname" ),
795                 osrfHashGet( class_obj, "primarykey" )
796             )
797         );
798
799         obj = doFieldmapperSearch(ctx, class_obj, _p, &err);
800
801         jsonObjectFree(_p);
802         if(err) return err;
803
804         jsonObject* cur;
805         jsonIterator* itr = jsonNewIterator( obj );
806         while ((cur = jsonIteratorNext( itr ))) {
807 #ifdef PCRUD
808             if(!verifyObjectPCRUD(ctx, cur)) continue;
809 #endif
810             osrfAppRespond(
811                     ctx,
812                     oilsFMGetObject( cur, osrfHashGet( class_obj, "primarykey" ) )
813                     );
814         }
815         jsonIteratorFree(itr);
816         osrfAppRespondComplete( ctx, NULL );
817
818     } else {
819         osrfAppRespondComplete( ctx, obj );
820     }
821
822     jsonObjectFree(obj);
823
824     return err;
825 }
826
827 static int verifyObjectClass ( osrfMethodContext* ctx, const jsonObject* param ) {
828
829     int ret = 1;
830     osrfHash* meta = (osrfHash*) ctx->method->userData;
831     osrfHash* class = osrfHashGet( meta, "class" );
832
833     if (!param->classname || (strcmp( osrfHashGet(class, "classname"), param->classname ))) {
834
835         growing_buffer* msg = buffer_init(128);
836         buffer_fadd(
837                 msg,
838                 "%s: %s method for type %s was passed a %s",
839                 MODULENAME,
840                 osrfHashGet(meta, "methodtype"),
841                 osrfHashGet(class, "classname"),
842                 param->classname
843                 );
844
845         char* m = buffer_release(msg);
846         osrfAppSessionStatus( ctx->session, OSRF_STATUS_BADREQUEST, "osrfMethodException", ctx->request, m );
847
848         free(m);
849
850         return 0;
851     }
852
853 #ifdef PCRUD
854     ret = verifyObjectPCRUD( ctx, param );
855 #endif
856
857     return ret;
858 }
859
860 #ifdef PCRUD
861
862 static jsonObject* verifyUserPCRUD( osrfMethodContext* ctx ) {
863     char* auth = jsonObjectToSimpleString( jsonObjectGetIndex( ctx->params, 0 ) );
864     jsonObject* auth_object = jsonNewObject(auth);
865     jsonObject* user = oilsUtilsQuickReq("open-ils.auth","open-ils.auth.session.retrieve", auth_object);
866     jsonObjectFree(auth_object);
867
868     if (!user->classname || strcmp(user->classname, "au")) {
869
870         growing_buffer* msg = buffer_init(128);
871         buffer_fadd(
872             msg,
873             "%s: permacrud received a bad auth token: %s",
874             MODULENAME,
875             auth
876         );
877
878         char* m = buffer_release(msg);
879         osrfAppSessionStatus( ctx->session, OSRF_STATUS_UNAUTHORIZED, "osrfMethodException", ctx->request, m );
880
881         free(m);
882         jsonObjectFree(user);
883         user = jsonNULL;
884     }
885
886     free(auth);
887     return user;
888
889 }
890
891 static int verifyObjectPCRUD (  osrfMethodContext* ctx, const jsonObject* obj ) {
892
893     dbhandle = writehandle;
894
895     osrfHash* meta = (osrfHash*) ctx->method->userData;
896     osrfHash* class = osrfHashGet( meta, "class" );
897     char* method_type = strdup( osrfHashGet(meta, "methodtype") );
898     int fetch = 0;
899
900     if ( ( *method_type == 's' || *method_type == 'i' ) ) {
901         free(method_type);
902         method_type = strdup("retrieve"); // search and id_list are equivelant to retrieve for this
903     } else if ( *method_type == 'u' || *method_type == 'd' ) {
904         fetch = 1; // MUST go to the db for the object for update and delete
905     }
906
907     osrfHash* pcrud = osrfHashGet( osrfHashGet(class, "permacrud"), method_type );
908     free(method_type);
909
910     if (!pcrud) {
911         // No permacrud for this method type on this class
912
913         growing_buffer* msg = buffer_init(128);
914         buffer_fadd(
915             msg,
916             "%s: %s on class %s has no permacrud IDL entry",
917             MODULENAME,
918             osrfHashGet(meta, "methodtype"),
919             osrfHashGet(class, "classname")
920         );
921
922         char* m = buffer_release(msg);
923         osrfAppSessionStatus( ctx->session, OSRF_STATUS_FORBIDDEN, "osrfMethodException", ctx->request, m );
924
925         free(m);
926
927         return 0;
928     }
929
930     jsonObject* user = verifyUserPCRUD( ctx );
931     if (!user) return 0;
932
933     int userid = atoi( oilsFMGetString( user, "id" ) );
934     jsonObjectFree(user);
935
936     osrfStringArray* permission = osrfHashGet(pcrud, "permission");
937     osrfStringArray* local_context = osrfHashGet(pcrud, "local_context");
938     osrfHash* foreign_context = osrfHashGet(pcrud, "foreign_context");
939
940     osrfStringArray* context_org_array = osrfNewStringArray(1);
941
942     int err = 0;
943     char* pkey_value = NULL;
944         if ( str_is_true( osrfHashGet(pcrud, "global_required") ) ) {
945             osrfLogDebug( OSRF_LOG_MARK, "global-level permissions required, fetching top of the org tree" );
946
947         // check for perm at top of org tree
948         jsonObject* _tmp_params = jsonParseString("[{\"parent_ou\":null}]");
949                 jsonObject* _list = doFieldmapperSearch(ctx, osrfHashGet( oilsIDL(), "aou" ), _tmp_params, &err);
950
951         jsonObject* _tree_top = jsonObjectGetIndex(_list, 0);
952
953         if (!_tree_top) {
954             jsonObjectFree(_tmp_params);
955             jsonObjectFree(_list);
956     
957             growing_buffer* msg = buffer_init(128);
958                         OSRF_BUFFER_ADD( msg, MODULENAME );
959                         OSRF_BUFFER_ADD( msg,
960                                 ": Internal error, could not find the top of the org tree (parent_ou = NULL)" );
961     
962             char* m = buffer_release(msg);
963             osrfAppSessionStatus( ctx->session, OSRF_STATUS_INTERNALSERVERERROR, "osrfMethodException", ctx->request, m );
964             free(m);
965
966             return 0;
967         }
968
969         osrfStringArrayAdd( context_org_array, oilsFMGetString( _tree_top, "id" ) );
970             osrfLogDebug( OSRF_LOG_MARK, "top of the org tree is %s", osrfStringArrayGetString(context_org_array, 0) );
971
972         jsonObjectFree(_tmp_params);
973         jsonObjectFree(_list);
974
975     } else {
976             osrfLogDebug( OSRF_LOG_MARK, "global-level permissions not required, fetching context org ids" );
977             char* pkey = osrfHashGet(class, "primarykey");
978         jsonObject *param = NULL;
979
980         if (obj->classname) {
981             pkey_value = oilsFMGetString( obj, pkey );
982             if (!fetch) param = jsonObjectClone(obj);
983                 osrfLogDebug( OSRF_LOG_MARK, "Object supplied, using primary key value of %s", pkey_value );
984         } else {
985             pkey_value = jsonObjectToSimpleString( obj );
986             fetch = 1;
987                 osrfLogDebug( OSRF_LOG_MARK, "Object not supplied, using primary key value of %s and retrieving from the database", pkey_value );
988         }
989
990         if (fetch) {
991             jsonObject* _tmp_params = jsonParseStringFmt("[{\"%s\":\"%s\"}]", pkey, pkey_value);
992                 jsonObject* _list = doFieldmapperSearch(
993                 ctx,
994                 class,
995                 _tmp_params,
996                 &err
997             );
998     
999             param = jsonObjectClone(jsonObjectGetIndex(_list, 0));
1000     
1001             jsonObjectFree(_tmp_params);
1002             jsonObjectFree(_list);
1003         }
1004
1005         if (!param) {
1006             osrfLogDebug( OSRF_LOG_MARK, "Object not found in the database with primary key %s of %s", pkey, pkey_value );
1007
1008             growing_buffer* msg = buffer_init(128);
1009             buffer_fadd(
1010                 msg,
1011                 "%s: no object found with primary key %s of %s",
1012                 MODULENAME,
1013                 pkey,
1014                 pkey_value
1015             );
1016         
1017             char* m = buffer_release(msg);
1018             osrfAppSessionStatus(
1019                 ctx->session,
1020                 OSRF_STATUS_INTERNALSERVERERROR,
1021                 "osrfMethodException",
1022                 ctx->request,
1023                 m
1024             );
1025         
1026             free(m);
1027             if (pkey_value) free(pkey_value);
1028
1029             return 0;
1030         }
1031
1032         if (local_context->size > 0) {
1033                 osrfLogDebug( OSRF_LOG_MARK, "%d class-local context field(s) specified", local_context->size);
1034             int i = 0;
1035             char* lcontext = NULL;
1036             while ( (lcontext = osrfStringArrayGetString(local_context, i++)) ) {
1037                 osrfStringArrayAdd( context_org_array, oilsFMGetString( param, lcontext ) );
1038                     osrfLogDebug(
1039                     OSRF_LOG_MARK,
1040                     "adding class-local field %s (value: %s) to the context org list",
1041                     lcontext,
1042                     osrfStringArrayGetString(context_org_array, context_org_array->size - 1)
1043                 );
1044             }
1045         }
1046
1047         osrfStringArray* class_list;
1048
1049         if (foreign_context) {
1050             class_list = osrfHashKeys( foreign_context );
1051                 osrfLogDebug( OSRF_LOG_MARK, "%d foreign context classes(s) specified", class_list->size);
1052
1053             if (class_list->size > 0) {
1054     
1055                 int i = 0;
1056                 char* class_name = NULL;
1057                 while ( (class_name = osrfStringArrayGetString(class_list, i++)) ) {
1058                     osrfHash* fcontext = osrfHashGet(foreign_context, class_name);
1059
1060                         osrfLogDebug(
1061                         OSRF_LOG_MARK,
1062                         "%d foreign context fields(s) specified for class %s",
1063                         ((osrfStringArray*)osrfHashGet(fcontext,"context"))->size,
1064                         class_name
1065                     );
1066     
1067                     char* foreign_pkey = osrfHashGet(fcontext, "field");
1068                     char* foreign_pkey_value = oilsFMGetString(param, osrfHashGet(fcontext, "fkey"));
1069
1070                     jsonObject* _tmp_params = jsonParseStringFmt(
1071                         "[{\"%s\":\"%s\"}]",
1072                         foreign_pkey,
1073                         foreign_pkey_value
1074                     );
1075     
1076                         jsonObject* _list = doFieldmapperSearch(
1077                         ctx,
1078                         osrfHashGet( oilsIDL(), class_name ),
1079                         _tmp_params,
1080                         &err
1081                     );
1082
1083                     jsonObject* _fparam = jsonObjectClone(jsonObjectGetIndex(_list, 0));
1084                     jsonObjectFree(_tmp_params);
1085                     jsonObjectFree(_list);
1086  
1087                     osrfStringArray* jump_list = osrfHashGet(fcontext, "jump");
1088
1089                     if (_fparam && jump_list) {
1090                         char* flink = NULL;
1091                         int k = 0;
1092                         while ( (flink = osrfStringArrayGetString(jump_list, k++)) && _fparam ) {
1093                             free(foreign_pkey_value);
1094
1095                             osrfHash* foreign_link_hash = oilsIDLFindPath( "/%s/links/%s", _fparam->classname, flink );
1096
1097                             foreign_pkey_value = oilsFMGetString(_fparam, flink);
1098                             foreign_pkey = osrfHashGet( foreign_link_hash, "key" );
1099
1100                             _tmp_params = jsonParseStringFmt(
1101                                 "[{\"%s\":\"%s\"}]",
1102                                 foreign_pkey,
1103                                 foreign_pkey_value
1104                             );
1105
1106                                 _list = doFieldmapperSearch(
1107                                 ctx,
1108                                 osrfHashGet( oilsIDL(), osrfHashGet( foreign_link_hash, "class" ) ),
1109                                 _tmp_params,
1110                                 &err
1111                             );
1112
1113                             _fparam = jsonObjectClone(jsonObjectGetIndex(_list, 0));
1114                             jsonObjectFree(_tmp_params);
1115                             jsonObjectFree(_list);
1116                         }
1117                     }
1118
1119            
1120                     if (!_fparam) {
1121
1122                         growing_buffer* msg = buffer_init(128);
1123                         buffer_fadd(
1124                             msg,
1125                             "%s: no object found with primary key %s of %s",
1126                             MODULENAME,
1127                             foreign_pkey,
1128                             foreign_pkey_value
1129                         );
1130                 
1131                         char* m = buffer_release(msg);
1132                         osrfAppSessionStatus(
1133                             ctx->session,
1134                             OSRF_STATUS_INTERNALSERVERERROR,
1135                             "osrfMethodException",
1136                             ctx->request,
1137                             m
1138                         );
1139
1140                         free(m);
1141                         osrfStringArrayFree(class_list);
1142                         free(foreign_pkey_value);
1143                         jsonObjectFree(param);
1144
1145                         return 0;
1146                     }
1147         
1148                     free(foreign_pkey_value);
1149     
1150                     int j = 0;
1151                     char* foreign_field = NULL;
1152                     while ( (foreign_field = osrfStringArrayGetString(osrfHashGet(fcontext,"context"), j++)) ) {
1153                         osrfStringArrayAdd( context_org_array, oilsFMGetString( _fparam, foreign_field ) );
1154                             osrfLogDebug(
1155                             OSRF_LOG_MARK,
1156                             "adding foreign class %s field %s (value: %s) to the context org list",
1157                             class_name,
1158                             foreign_field,
1159                             osrfStringArrayGetString(context_org_array, context_org_array->size - 1)
1160                         );
1161                     }
1162
1163                     jsonObjectFree(_fparam);
1164                 }
1165     
1166                 osrfStringArrayFree(class_list);
1167             }
1168         }
1169
1170         jsonObjectFree(param);
1171     }
1172
1173     char* context_org = NULL;
1174     char* perm = NULL;
1175     int OK = 0;
1176
1177     if (permission->size == 0) {
1178             osrfLogDebug( OSRF_LOG_MARK, "No permission specified for this action, passing through" );
1179         OK = 1;
1180     }
1181     
1182     int i = 0;
1183     while ( (perm = osrfStringArrayGetString(permission, i++)) ) {
1184         int j = 0;
1185         while ( (context_org = osrfStringArrayGetString(context_org_array, j++)) ) {
1186             dbi_result result;
1187
1188             if (pkey_value) {
1189                     osrfLogDebug(
1190                     OSRF_LOG_MARK,
1191                     "Checking object permission [%s] for user %d on object %s (class %s) at org %d",
1192                     perm,
1193                     userid,
1194                     pkey_value,
1195                     osrfHashGet(class, "classname"),
1196                     atoi(context_org)
1197                 );
1198
1199                 result = dbi_conn_queryf(
1200                     writehandle,
1201                     "SELECT permission.usr_has_object_perm(%d, '%s', '%s', '%s', %d) AS has_perm;",
1202                     userid,
1203                     perm,
1204                     osrfHashGet(class, "classname"),
1205                     pkey_value,
1206                     atoi(context_org)
1207                 );
1208
1209                 if (result) {
1210                     osrfLogDebug(
1211                         OSRF_LOG_MARK,
1212                         "Recieved a result for object permission [%s] for user %d on object %s (class %s) at org %d",
1213                         perm,
1214                         userid,
1215                         pkey_value,
1216                         osrfHashGet(class, "classname"),
1217                         atoi(context_org)
1218                     );
1219
1220                     if (dbi_result_first_row(result)) {
1221                         jsonObject* return_val = oilsMakeJSONFromResult( result );
1222                         char* has_perm = jsonObjectToSimpleString( jsonObjectGetKeyConst(return_val, "has_perm") );
1223
1224                             osrfLogDebug(
1225                             OSRF_LOG_MARK,
1226                             "Status of object permission [%s] for user %d on object %s (class %s) at org %d is %s",
1227                             perm,
1228                             userid,
1229                             pkey_value,
1230                             osrfHashGet(class, "classname"),
1231                             atoi(context_org),
1232                             has_perm
1233                         );
1234
1235                         if ( *has_perm == 't' ) OK = 1;
1236                         free(has_perm); 
1237                         jsonObjectFree(return_val);
1238                     }
1239
1240                     dbi_result_free(result); 
1241                     if (OK) break;
1242                 }
1243             }
1244
1245                 osrfLogDebug( OSRF_LOG_MARK, "Checking non-object permission [%s] for user %d at org %d", perm, userid, atoi(context_org) );
1246             result = dbi_conn_queryf(
1247                 writehandle,
1248                 "SELECT permission.usr_has_perm(%d, '%s', %d) AS has_perm;",
1249                 userid,
1250                 perm,
1251                 atoi(context_org)
1252             );
1253
1254             if (result) {
1255                     osrfLogDebug( OSRF_LOG_MARK, "Recieved a result for permission [%s] for user %d at org %d", perm, userid, atoi(context_org) );
1256                 if (dbi_result_first_row(result)) {
1257                     jsonObject* return_val = oilsMakeJSONFromResult( result );
1258                     char* has_perm = jsonObjectToSimpleString( jsonObjectGetKeyConst(return_val, "has_perm") );
1259                         osrfLogDebug( OSRF_LOG_MARK, "Status of permission [%s] for user %d at org %d is [%s]", perm, userid, atoi(context_org), has_perm );
1260                     if ( *has_perm == 't' ) OK = 1;
1261                     free(has_perm); 
1262                     jsonObjectFree(return_val);
1263                 }
1264
1265                 dbi_result_free(result); 
1266                 if (OK) break;
1267             }
1268
1269         }
1270         if (OK) break;
1271     }
1272
1273     if (pkey_value) free(pkey_value);
1274     osrfStringArrayFree(context_org_array);
1275
1276     return OK;
1277 }
1278 #endif
1279
1280
1281 static jsonObject* doCreate(osrfMethodContext* ctx, int* err ) {
1282
1283         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
1284 #ifdef PCRUD
1285         jsonObject* target = jsonObjectGetIndex( ctx->params, 1 );
1286         jsonObject* options = jsonObjectGetIndex( ctx->params, 2 );
1287 #else
1288         jsonObject* target = jsonObjectGetIndex( ctx->params, 0 );
1289         jsonObject* options = jsonObjectGetIndex( ctx->params, 1 );
1290 #endif
1291
1292         if (!verifyObjectClass(ctx, target)) {
1293                 *err = -1;
1294                 return jsonNULL;
1295         }
1296
1297         osrfLogDebug( OSRF_LOG_MARK, "Object seems to be of the correct type" );
1298
1299         if (!ctx->session || !ctx->session->userData || !osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
1300                 osrfLogError( OSRF_LOG_MARK, "No active transaction -- required for CREATE" );
1301
1302                 osrfAppSessionStatus(
1303                         ctx->session,
1304                         OSRF_STATUS_BADREQUEST,
1305                         "osrfMethodException",
1306                         ctx->request,
1307                         "No active transaction -- required for CREATE"
1308                 );
1309                 *err = -1;
1310                 return jsonNULL;
1311         }
1312
1313         // The following test is harmless but redundant.  If a class is
1314         // readonly, we don't register a create method for it.
1315         if( str_is_true( osrfHashGet( meta, "readonly" ) ) ) {
1316                 osrfAppSessionStatus(
1317                         ctx->session,
1318                         OSRF_STATUS_BADREQUEST,
1319                         "osrfMethodException",
1320                         ctx->request,
1321                         "Cannot INSERT readonly class"
1322                 );
1323                 *err = -1;
1324                 return jsonNULL;
1325         }
1326
1327
1328         char* trans_id = osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" );
1329
1330         // Set the last_xact_id
1331         int index = oilsIDL_ntop( target->classname, "last_xact_id" );
1332         if (index > -1) {
1333                 osrfLogDebug(OSRF_LOG_MARK, "Setting last_xact_id to %s on %s at position %d", trans_id, target->classname, index);
1334                 jsonObjectSetIndex(target, index, jsonNewObject(trans_id));
1335         }       
1336
1337         osrfLogDebug( OSRF_LOG_MARK, "There is a transaction running..." );
1338
1339         dbhandle = writehandle;
1340
1341         osrfHash* fields = osrfHashGet(meta, "fields");
1342         char* pkey = osrfHashGet(meta, "primarykey");
1343         char* seq = osrfHashGet(meta, "sequence");
1344
1345         growing_buffer* table_buf = buffer_init(128);
1346         growing_buffer* col_buf = buffer_init(128);
1347         growing_buffer* val_buf = buffer_init(128);
1348
1349         OSRF_BUFFER_ADD(table_buf, "INSERT INTO ");
1350         OSRF_BUFFER_ADD(table_buf, osrfHashGet(meta, "tablename"));
1351         OSRF_BUFFER_ADD_CHAR( col_buf, '(' );
1352         buffer_add(val_buf,"VALUES (");
1353
1354
1355         int i = 0;
1356         int first = 1;
1357         char* field_name;
1358         osrfStringArray* field_list = osrfHashKeys( fields );
1359         while ( (field_name = osrfStringArrayGetString(field_list, i++)) ) {
1360
1361                 osrfHash* field = osrfHashGet( fields, field_name );
1362
1363                 if( str_is_true( osrfHashGet( field, "virtual" ) ) )
1364                         continue;
1365
1366                 const jsonObject* field_object = oilsFMGetObject( target, field_name );
1367
1368                 char* value;
1369                 if (field_object && field_object->classname) {
1370                         value = oilsFMGetString(
1371                                 field_object,
1372                                 (char*)oilsIDLFindPath("/%s/primarykey", field_object->classname)
1373                         );
1374                 } else {
1375                         value = jsonObjectToSimpleString( field_object );
1376                 }
1377
1378
1379                 if (first) {
1380                         first = 0;
1381                 } else {
1382                         OSRF_BUFFER_ADD_CHAR( col_buf, ',' );
1383                         OSRF_BUFFER_ADD_CHAR( val_buf, ',' );
1384                 }
1385
1386                 buffer_add(col_buf, field_name);
1387
1388                 if (!field_object || field_object->type == JSON_NULL) {
1389                         buffer_add( val_buf, "DEFAULT" );
1390                         
1391                 } else if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1392                         if ( !strcmp(osrfHashGet(field, "datatype"), "INT8") ) {
1393                                 buffer_fadd( val_buf, "%lld", atoll(value) );
1394                                 
1395                         } else if ( !strcmp(osrfHashGet(field, "datatype"), "INT") ) {
1396                                 buffer_fadd( val_buf, "%d", atoi(value) );
1397                                 
1398                         } else if ( !strcmp(osrfHashGet(field, "datatype"), "NUMERIC") ) {
1399                                 buffer_fadd( val_buf, "%f", atof(value) );
1400                         }
1401                 } else {
1402                         if ( dbi_conn_quote_string(writehandle, &value) ) {
1403                                 OSRF_BUFFER_ADD( val_buf, value );
1404
1405                         } else {
1406                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting string [%s]", MODULENAME, value);
1407                                 osrfAppSessionStatus(
1408                                         ctx->session,
1409                                         OSRF_STATUS_INTERNALSERVERERROR,
1410                                         "osrfMethodException",
1411                                         ctx->request,
1412                                         "Error quoting string -- please see the error log for more details"
1413                                 );
1414                                 free(value);
1415                                 buffer_free(table_buf);
1416                                 buffer_free(col_buf);
1417                                 buffer_free(val_buf);
1418                                 *err = -1;
1419                                 return jsonNULL;
1420                         }
1421                 }
1422
1423                 free(value);
1424                 
1425         }
1426
1427
1428         OSRF_BUFFER_ADD_CHAR( col_buf, ')' );
1429         OSRF_BUFFER_ADD_CHAR( val_buf, ')' );
1430
1431         char* table_str = buffer_release(table_buf);
1432         char* col_str   = buffer_release(col_buf);
1433         char* val_str   = buffer_release(val_buf);
1434         growing_buffer* sql = buffer_init(128);
1435         buffer_fadd( sql, "%s %s %s;", table_str, col_str, val_str );
1436         free(table_str);
1437         free(col_str);
1438         free(val_str);
1439
1440         char* query = buffer_release(sql);
1441
1442         osrfLogDebug(OSRF_LOG_MARK, "%s: Insert SQL [%s]", MODULENAME, query);
1443
1444         
1445         dbi_result result = dbi_conn_query(writehandle, query);
1446
1447         jsonObject* obj = NULL;
1448
1449         if (!result) {
1450                 obj = jsonNewObject(NULL);
1451                 osrfLogError(
1452                         OSRF_LOG_MARK,
1453                         "%s ERROR inserting %s object using query [%s]",
1454                         MODULENAME,
1455                         osrfHashGet(meta, "fieldmapper"),
1456                         query
1457                 );
1458                 osrfAppSessionStatus(
1459                         ctx->session,
1460                         OSRF_STATUS_INTERNALSERVERERROR,
1461                         "osrfMethodException",
1462                         ctx->request,
1463                         "INSERT error -- please see the error log for more details"
1464                 );
1465                 *err = -1;
1466         } else {
1467
1468                 char* id = oilsFMGetString(target, pkey);
1469                 if (!id) {
1470                         unsigned long long new_id = dbi_conn_sequence_last(writehandle, seq);
1471                         growing_buffer* _id = buffer_init(10);
1472                         buffer_fadd(_id, "%lld", new_id);
1473                         id = buffer_release(_id);
1474                 }
1475
1476                 // Find quietness specification, if present
1477                 char* quiet_str = NULL;
1478                 if ( options ) {
1479                         const jsonObject* quiet_obj = jsonObjectGetKeyConst( options, "quiet" );
1480                         if( quiet_obj )
1481                                 quiet_str = jsonObjectToSimpleString( quiet_obj );
1482                 }
1483
1484                 if( str_is_true( quiet_str ) ) {  // if quietness is specified
1485                         obj = jsonNewObject(id);
1486                 }
1487                 else {
1488
1489                         jsonObject* fake_params = jsonNewObjectType(JSON_ARRAY);
1490                         jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH));
1491
1492                         jsonObjectSetKey(
1493                                 jsonObjectGetIndex(fake_params, 0),
1494                                 pkey,
1495                                 jsonNewObject(id)
1496                         );
1497
1498                         jsonObject* list = doFieldmapperSearch( ctx,meta, fake_params, err);
1499
1500                         if(*err) {
1501                                 jsonObjectFree( fake_params );
1502                                 obj = jsonNULL;
1503                         } else {
1504                                 obj = jsonObjectClone( jsonObjectGetIndex(list, 0) );
1505                         }
1506
1507                         jsonObjectFree( list );
1508                         jsonObjectFree( fake_params );
1509                 }
1510
1511                 if(quiet_str) free(quiet_str);
1512                 free(id);
1513         }
1514
1515         free(query);
1516
1517         return obj;
1518
1519 }
1520
1521
1522 static jsonObject* doRetrieve(osrfMethodContext* ctx, int* err ) {
1523
1524     int id_pos = 0;
1525     int order_pos = 1;
1526
1527 #ifdef PCRUD
1528     id_pos = 1;
1529     order_pos = 2;
1530 #endif
1531
1532         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
1533
1534         char* id = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, id_pos));
1535         jsonObject* order_hash = jsonObjectGetIndex(ctx->params, order_pos);
1536
1537         osrfLogDebug(
1538                 OSRF_LOG_MARK,
1539                 "%s retrieving %s object with primary key value of %s",
1540                 MODULENAME,
1541                 osrfHashGet(meta, "fieldmapper"),
1542                 id
1543         );
1544         free(id);
1545
1546         jsonObject* fake_params = jsonNewObjectType(JSON_ARRAY);
1547         jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH));
1548
1549         jsonObjectSetKey(
1550                 jsonObjectGetIndex(fake_params, 0),
1551                 osrfHashGet(meta, "primarykey"),
1552                 jsonObjectClone(jsonObjectGetIndex(ctx->params, id_pos))
1553         );
1554
1555
1556         if (order_hash) jsonObjectPush(fake_params, jsonObjectClone(order_hash) );
1557
1558         jsonObject* list = doFieldmapperSearch( ctx,meta, fake_params, err);
1559
1560         if(*err) {
1561                 jsonObjectFree( fake_params );
1562                 return jsonNULL;
1563         }
1564
1565         jsonObject* obj = jsonObjectClone( jsonObjectGetIndex(list, 0) );
1566
1567         jsonObjectFree( list );
1568         jsonObjectFree( fake_params );
1569
1570 #ifdef PCRUD
1571         if(!verifyObjectPCRUD(ctx, obj)) {
1572         jsonObjectFree(obj);
1573         *err = -1;
1574
1575         growing_buffer* msg = buffer_init(128);
1576                 OSRF_BUFFER_ADD( msg, MODULENAME );
1577                 OSRF_BUFFER_ADD( msg, ": Insufficient permissions to retrieve object" );
1578
1579         char* m = buffer_release(msg);
1580         osrfAppSessionStatus( ctx->session, OSRF_STATUS_NOTALLOWED, "osrfMethodException", ctx->request, m );
1581
1582         free(m);
1583
1584                 return jsonNULL;
1585         }
1586 #endif
1587
1588         return obj;
1589 }
1590
1591 static char* jsonNumberToDBString ( osrfHash* field, const jsonObject* value ) {
1592         growing_buffer* val_buf = buffer_init(32);
1593
1594         if ( !strncmp(osrfHashGet(field, "datatype"), "INT", (size_t)3) ) {
1595                 if (value->type == JSON_NUMBER) buffer_fadd( val_buf, "%ld", (long)jsonObjectGetNumber(value) );
1596                 else {
1597                         char* val_str = jsonObjectToSimpleString(value);
1598                         buffer_fadd( val_buf, "%ld", atol(val_str) );
1599                         free(val_str);
1600                 }
1601
1602         } else if ( !strcmp(osrfHashGet(field, "datatype"), "NUMERIC") ) {
1603                 if (value->type == JSON_NUMBER) buffer_fadd( val_buf, "%f",  jsonObjectGetNumber(value) );
1604                 else {
1605                         char* val_str = jsonObjectToSimpleString(value);
1606                         buffer_fadd( val_buf, "%f", atof(val_str) );
1607                         free(val_str);
1608                 }
1609         }
1610
1611         return buffer_release(val_buf);
1612 }
1613
1614 static char* searchINPredicate (const char* class, osrfHash* field,
1615                 jsonObject* node, const char* op, osrfMethodContext* ctx ) {
1616         growing_buffer* sql_buf = buffer_init(32);
1617         
1618         buffer_fadd(
1619                 sql_buf,
1620                 "\"%s\".%s ",
1621                 class,
1622                 osrfHashGet(field, "name")
1623         );
1624
1625         if (!op) {
1626                 buffer_add(sql_buf, "IN (");
1627         } else if (!(strcasecmp(op,"not in"))) {
1628                 buffer_add(sql_buf, "NOT IN (");
1629         } else {
1630                 buffer_add(sql_buf, "IN (");
1631         }
1632
1633     if (node->type == JSON_HASH) {
1634         // subquery predicate
1635         char* subpred = SELECT(
1636             ctx,
1637             jsonObjectGetKey( node, "select" ),
1638             jsonObjectGetKey( node, "from" ),
1639             jsonObjectGetKey( node, "where" ),
1640             jsonObjectGetKey( node, "having" ),
1641             jsonObjectGetKey( node, "order_by" ),
1642             jsonObjectGetKey( node, "limit" ),
1643             jsonObjectGetKey( node, "offset" ),
1644             SUBSELECT
1645         );
1646
1647         buffer_add(sql_buf, subpred);
1648         free(subpred);
1649
1650     } else if (node->type == JSON_ARRAY) {
1651         // litteral value list
1652         int in_item_index = 0;
1653         int in_item_first = 1;
1654         jsonObject* in_item;
1655         while ( (in_item = jsonObjectGetIndex(node, in_item_index++)) ) {
1656     
1657                 if (in_item_first)
1658                         in_item_first = 0;
1659                 else
1660                         buffer_add(sql_buf, ", ");
1661     
1662                 if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1663                         char* val = jsonNumberToDBString( field, in_item );
1664                         OSRF_BUFFER_ADD( sql_buf, val );
1665                         free(val);
1666     
1667                 } else {
1668                         char* key_string = jsonObjectToSimpleString(in_item);
1669                         if ( dbi_conn_quote_string(dbhandle, &key_string) ) {
1670                                 OSRF_BUFFER_ADD( sql_buf, key_string );
1671                                 free(key_string);
1672                         } else {
1673                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, key_string);
1674                                 free(key_string);
1675                                 buffer_free(sql_buf);
1676                                 return NULL;
1677                         }
1678                 }
1679         }
1680     }
1681     
1682         OSRF_BUFFER_ADD_CHAR( sql_buf, ')' );
1683
1684         return buffer_release(sql_buf);
1685 }
1686
1687 // Receive a JSON_ARRAY representing a function call.  The first
1688 // entry in the array is the function name.  The rest are parameters.
1689 static char* searchValueTransform( const jsonObject* array ) {
1690         growing_buffer* sql_buf = buffer_init(32);
1691
1692         char* val = NULL;
1693         jsonObject* func_item;
1694         
1695         // Get the function name
1696         if( array->size > 0 ) {
1697                 func_item = jsonObjectGetIndex( array, 0 );
1698                 val = jsonObjectToSimpleString( func_item );
1699                 OSRF_BUFFER_ADD( sql_buf, val );
1700                 OSRF_BUFFER_ADD( sql_buf, "( " );
1701                 free(val);
1702         }
1703         
1704         // Get the parameters
1705         int func_item_index = 1;   // We already grabbed the zeroth entry
1706         while ( (func_item = jsonObjectGetIndex(array, func_item_index++)) ) {
1707
1708                 // Add a separator comma, if we need one
1709                 if( func_item_index > 2 )
1710                         buffer_add( sql_buf, ", " );
1711
1712                 // Add the current parameter
1713                 if (func_item->type == JSON_NULL) {
1714                         buffer_add( sql_buf, "NULL" );
1715                 } else {
1716                         val = jsonObjectToSimpleString(func_item);
1717                         if ( dbi_conn_quote_string(dbhandle, &val) ) {
1718                                 OSRF_BUFFER_ADD( sql_buf, val );
1719                                 free(val);
1720                         } else {
1721                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, val);
1722                                 buffer_free(sql_buf);
1723                                 free(val);
1724                                 return NULL;
1725                         }
1726                 }
1727         }
1728
1729         buffer_add( sql_buf, " )" );
1730
1731         return buffer_release(sql_buf);
1732 }
1733
1734 static char* searchFunctionPredicate (const char* class, osrfHash* field,
1735                 const jsonObject* node, const char* node_key) {
1736         growing_buffer* sql_buf = buffer_init(32);
1737
1738         char* val = searchValueTransform(node);
1739         
1740         buffer_fadd(
1741                 sql_buf,
1742                 "\"%s\".%s %s %s",
1743                 class,
1744                 osrfHashGet(field, "name"),
1745                 node_key,
1746                 val
1747         );
1748
1749         free(val);
1750
1751         return buffer_release(sql_buf);
1752 }
1753
1754 // class is a class name
1755 // field is a field definition as stored in the IDL
1756 // node comes from the method parameter, and represents an entry in the SELECT list
1757 static char* searchFieldTransform (const char* class, osrfHash* field, const jsonObject* node) {
1758         growing_buffer* sql_buf = buffer_init(32);
1759         
1760         char* field_transform = jsonObjectToSimpleString( jsonObjectGetKeyConst( node, "transform" ) );
1761         char* transform_subcolumn = jsonObjectToSimpleString( jsonObjectGetKeyConst( node, "result_field" ) );
1762
1763         if(transform_subcolumn)
1764                 OSRF_BUFFER_ADD_CHAR( sql_buf, '(' );    // enclose transform in parentheses
1765
1766         if (field_transform) {
1767                 buffer_fadd( sql_buf, "%s(\"%s\".%s", field_transform, class, osrfHashGet(field, "name"));
1768             const jsonObject* array = jsonObjectGetKeyConst( node, "params" );
1769
1770         if (array) {
1771                 int func_item_index = 0;
1772                 jsonObject* func_item;
1773                 while ( (func_item = jsonObjectGetIndex(array, func_item_index++)) ) {
1774
1775                         char* val = jsonObjectToSimpleString(func_item);
1776
1777                     if ( !val ) {
1778                             buffer_add( sql_buf, ",NULL" );
1779                     } else if ( dbi_conn_quote_string(dbhandle, &val) ) {
1780                                         OSRF_BUFFER_ADD_CHAR( sql_buf, ',' );
1781                                         OSRF_BUFFER_ADD( sql_buf, val );
1782                         } else {
1783                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, val);
1784                                         free(transform_subcolumn);
1785                                         free(field_transform);
1786                                         free(val);
1787                                 buffer_free(sql_buf);
1788                                 return NULL;
1789                 }
1790                                 free(val);
1791                         }
1792         }
1793
1794                 buffer_add( sql_buf, " )" );
1795
1796         } else {
1797                 buffer_fadd( sql_buf, "\"%s\".%s", class, osrfHashGet(field, "name"));
1798         }
1799
1800     if (transform_subcolumn)
1801         buffer_fadd( sql_buf, ").\"%s\"", transform_subcolumn );
1802  
1803         if (field_transform) free(field_transform);
1804         if (transform_subcolumn) free(transform_subcolumn);
1805
1806         return buffer_release(sql_buf);
1807 }
1808
1809 static char* searchFieldTransformPredicate (const char* class, osrfHash* field, jsonObject* node, const char* node_key) {
1810         char* field_transform = searchFieldTransform( class, field, node );
1811         char* value = NULL;
1812
1813         if (!jsonObjectGetKeyConst( node, "value" )) {
1814                 value = searchWHERE( node, osrfHashGet( oilsIDL(), class ), AND_OP_JOIN, NULL );
1815         } else if (jsonObjectGetKeyConst( node, "value" )->type == JSON_ARRAY) {
1816                 value = searchValueTransform(jsonObjectGetKeyConst( node, "value" ));
1817         } else if (jsonObjectGetKeyConst( node, "value" )->type == JSON_HASH) {
1818                 value = searchWHERE( jsonObjectGetKeyConst( node, "value" ), osrfHashGet( oilsIDL(), class ), AND_OP_JOIN, NULL );
1819         } else if (jsonObjectGetKeyConst( node, "value" )->type != JSON_NULL) {
1820                 if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1821                         value = jsonNumberToDBString( field, jsonObjectGetKeyConst( node, "value" ) );
1822                 } else {
1823                         value = jsonObjectToSimpleString(jsonObjectGetKeyConst( node, "value" ));
1824                         if ( !dbi_conn_quote_string(dbhandle, &value) ) {
1825                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, value);
1826                                 free(value);
1827                                 free(field_transform);
1828                                 return NULL;
1829                         }
1830                 }
1831         }
1832
1833         growing_buffer* sql_buf = buffer_init(32);
1834         
1835         buffer_fadd(
1836                 sql_buf,
1837                 "%s %s %s",
1838                 field_transform,
1839                 node_key,
1840                 value
1841         );
1842
1843         free(value);
1844         free(field_transform);
1845
1846         return buffer_release(sql_buf);
1847 }
1848
1849 static char* searchSimplePredicate (const char* orig_op, const char* class,
1850                 osrfHash* field, const jsonObject* node) {
1851
1852         char* val = NULL;
1853
1854         if (node->type != JSON_NULL) {
1855                 if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1856                         val = jsonNumberToDBString( field, node );
1857                 } else {
1858                         val = jsonObjectToSimpleString(node);
1859                 }
1860         }
1861
1862         char* pred = searchWriteSimplePredicate( class, field, osrfHashGet(field, "name"), orig_op, val );
1863
1864         if (val) free(val);
1865
1866         return pred;
1867 }
1868
1869 static char* searchWriteSimplePredicate ( const char* class, osrfHash* field,
1870         const char* left, const char* orig_op, const char* right ) {
1871
1872         char* val = NULL;
1873         char* op = NULL;
1874         if (right == NULL) {
1875                 val = strdup("NULL");
1876
1877                 if (strcmp( orig_op, "=" ))
1878                         op = strdup("IS NOT");
1879                 else
1880                         op = strdup("IS");
1881
1882         } else if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1883                 val = strdup(right);
1884                 op = strdup(orig_op);
1885
1886         } else {
1887                 val = strdup(right);
1888                 if ( !dbi_conn_quote_string(dbhandle, &val) ) {
1889                         osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key string [%s]", MODULENAME, val);
1890                         free(val);
1891                         return NULL;
1892                 }
1893                 op = strdup(orig_op);
1894         }
1895
1896         growing_buffer* sql_buf = buffer_init(16);
1897         buffer_fadd( sql_buf, "\"%s\".%s %s %s", class, left, op, val );
1898         free(val);
1899         free(op);
1900
1901         return buffer_release(sql_buf);
1902 }
1903
1904 static char* searchBETWEENPredicate (const char* class, osrfHash* field, jsonObject* node) {
1905
1906         char* x_string;
1907         char* y_string;
1908
1909         if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
1910                 x_string = jsonNumberToDBString(field, jsonObjectGetIndex(node,0));
1911                 y_string = jsonNumberToDBString(field, jsonObjectGetIndex(node,1));
1912
1913         } else {
1914                 x_string = jsonObjectToSimpleString(jsonObjectGetIndex(node,0));
1915                 y_string = jsonObjectToSimpleString(jsonObjectGetIndex(node,1));
1916                 if ( !(dbi_conn_quote_string(dbhandle, &x_string) && dbi_conn_quote_string(dbhandle, &y_string)) ) {
1917                         osrfLogError(OSRF_LOG_MARK, "%s: Error quoting key strings [%s] and [%s]", MODULENAME, x_string, y_string);
1918                         free(x_string);
1919                         free(y_string);
1920                         return NULL;
1921                 }
1922         }
1923
1924         growing_buffer* sql_buf = buffer_init(32);
1925         buffer_fadd( sql_buf, "%s BETWEEN %s AND %s", osrfHashGet(field, "name"), x_string, y_string );
1926         free(x_string);
1927         free(y_string);
1928
1929         return buffer_release(sql_buf);
1930 }
1931
1932 static char* searchPredicate ( const char* class, osrfHash* field, 
1933                                                            jsonObject* node, osrfMethodContext* ctx ) {
1934
1935         char* pred = NULL;
1936         if (node->type == JSON_ARRAY) { // equality IN search
1937                 pred = searchINPredicate( class, field, node, NULL, ctx );
1938         } else if (node->type == JSON_HASH) { // non-equality search
1939                 jsonObject* pred_node;
1940                 jsonIterator* pred_itr = jsonNewIterator( node );
1941                 while ( (pred_node = jsonIteratorNext( pred_itr )) ) {
1942                         if ( !(strcasecmp( pred_itr->key,"between" )) )
1943                                 pred = searchBETWEENPredicate( class, field, pred_node );
1944                         else if ( !(strcasecmp( pred_itr->key,"in" )) || !(strcasecmp( pred_itr->key,"not in" )) )
1945                                 pred = searchINPredicate( class, field, pred_node, pred_itr->key, ctx );
1946                         else if ( pred_node->type == JSON_ARRAY )
1947                                 pred = searchFunctionPredicate( class, field, pred_node, pred_itr->key );
1948                         else if ( pred_node->type == JSON_HASH )
1949                                 pred = searchFieldTransformPredicate( class, field, pred_node, pred_itr->key );
1950                         else 
1951                                 pred = searchSimplePredicate( pred_itr->key, class, field, pred_node );
1952
1953                         break;
1954                 }
1955         jsonIteratorFree(pred_itr);
1956         } else if (node->type == JSON_NULL) { // IS NULL search
1957                 growing_buffer* _p = buffer_init(64);
1958                 buffer_fadd(
1959                         _p,
1960                         "\"%s\".%s IS NULL",
1961                         class,
1962                         osrfHashGet(field, "name")
1963                 );
1964                 pred = buffer_release(_p);
1965         } else { // equality search
1966                 pred = searchSimplePredicate( "=", class, field, node );
1967         }
1968
1969         return pred;
1970
1971 }
1972
1973
1974 /*
1975
1976 join : {
1977         acn : {
1978                 field : record,
1979                 fkey : id
1980                 type : left
1981                 filter_op : or
1982                 filter : { ... },
1983                 join : {
1984                         acp : {
1985                                 field : call_number,
1986                                 fkey : id,
1987                                 filter : { ... },
1988                         },
1989                 },
1990         },
1991         mrd : {
1992                 field : record,
1993                 type : inner
1994                 fkey : id,
1995                 filter : { ... },
1996         }
1997 }
1998
1999 */
2000
2001 static char* searchJOIN ( const jsonObject* join_hash, osrfHash* leftmeta ) {
2002
2003         const jsonObject* working_hash;
2004         jsonObject* freeable_hash = NULL;
2005
2006         if (join_hash->type == JSON_STRING) {
2007                 // create a wrapper around a copy of the original
2008                 char* _tmp = jsonObjectToSimpleString( join_hash );
2009                 freeable_hash = jsonNewObjectType(JSON_HASH);
2010                 jsonObjectSetKey(freeable_hash, _tmp, NULL);
2011                 free(_tmp);
2012                 working_hash = freeable_hash;
2013         }
2014         else {
2015                 if( join_hash->type != JSON_HASH ) {
2016                         osrfLogError(
2017                                 OSRF_LOG_MARK,
2018                                 "%s: JOIN failed; expected JSON object type not found",
2019                                 MODULENAME
2020                         );
2021                         return NULL;
2022                 }
2023                 working_hash = join_hash;
2024         }
2025
2026         growing_buffer* join_buf = buffer_init(128);
2027         const char* leftclass = osrfHashGet(leftmeta, "classname");
2028
2029         jsonObject* snode = NULL;
2030         jsonIterator* search_itr = jsonNewIterator( working_hash );
2031         if(freeable_hash)
2032                 jsonObjectFree(freeable_hash);
2033         
2034         while ( (snode = jsonIteratorNext( search_itr )) ) {
2035                 osrfHash* idlClass = osrfHashGet( oilsIDL(), search_itr->key );
2036
2037                 const char* class = osrfHashGet(idlClass, "classname");
2038
2039                 char* fkey = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "fkey" ) );
2040                 char* field = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "field" ) );
2041
2042                 if (field && !fkey) {
2043                         fkey = (char*)oilsIDLFindPath("/%s/links/%s/key", class, field);
2044                         if (!fkey) {
2045                                 osrfLogError(
2046                                         OSRF_LOG_MARK,
2047                                         "%s: JOIN failed.  No link defined from %s.%s to %s",
2048                                         MODULENAME,
2049                                         class,
2050                                         field,
2051                                         leftclass
2052                                 );
2053                                 buffer_free(join_buf);
2054                                 free(field);
2055                                 jsonIteratorFree(search_itr);
2056                                 return NULL;
2057                         }
2058                         fkey = strdup( fkey );
2059
2060                 } else if (!field && fkey) {
2061                         field = (char*)oilsIDLFindPath("/%s/links/%s/key", leftclass, fkey );
2062                         if (!field) {
2063                                 osrfLogError(
2064                                         OSRF_LOG_MARK,
2065                                         "%s: JOIN failed.  No link defined from %s.%s to %s",
2066                                         MODULENAME,
2067                                         leftclass,
2068                                         fkey,
2069                                         class
2070                                 );
2071                                 buffer_free(join_buf);
2072                                 free(fkey);
2073                                 jsonIteratorFree(search_itr);
2074                                 return NULL;
2075                         }
2076                         field = strdup( field );
2077
2078                 } else if (!field && !fkey) {
2079                         osrfHash* _links = oilsIDLFindPath("/%s/links", leftclass);
2080
2081                         int i = 0;
2082                         const char* tmp_fkey;
2083                         osrfStringArray* keys = osrfHashKeys( _links );
2084                         while ( (tmp_fkey = osrfStringArrayGetString(keys, i++)) ) {
2085                                 if ( !strcmp( (char*)oilsIDLFindPath("/%s/links/%s/class", leftclass, tmp_fkey), class) ) {
2086                                         field = strdup( (char*)oilsIDLFindPath("/%s/links/%s/key", leftclass, tmp_fkey) );
2087                                         fkey = strdup(tmp_fkey);
2088                                         break;
2089                                 }
2090                         }
2091                         osrfStringArrayFree(keys);
2092
2093                         if (!field && !fkey) {
2094                                 _links = oilsIDLFindPath("/%s/links", class);
2095
2096                                 i = 0;
2097                                 const char* tmp_fld;
2098                                 keys = osrfHashKeys( _links );
2099                                 while ( (tmp_fld = osrfStringArrayGetString(keys, i++)) ) {
2100                                         if ( !strcmp( (char*)oilsIDLFindPath("/%s/links/%s/class", class, tmp_fld), class) ) {
2101                                                 fkey = strdup( (char*)oilsIDLFindPath("/%s/links/%s/key", class, tmp_fld) );
2102                                                 field = strdup( tmp_fld );
2103                                                 break;
2104                                         }
2105                                 }
2106                                 osrfStringArrayFree(keys);
2107                         }
2108
2109                         if (!field && !fkey) {
2110                                 osrfLogError(
2111                                         OSRF_LOG_MARK,
2112                                         "%s: JOIN failed.  No link defined between %s and %s",
2113                                         MODULENAME,
2114                                         leftclass,
2115                                         class
2116                                 );
2117                                 buffer_free(join_buf);
2118                                 jsonIteratorFree(search_itr);
2119                                 return NULL;
2120                         }
2121
2122                 }
2123
2124                 char* type = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "type" ) );
2125                 if (type) {
2126                         if ( !strcasecmp(type,"left") ) {
2127                                 buffer_add(join_buf, " LEFT JOIN");
2128                         } else if ( !strcasecmp(type,"right") ) {
2129                                 buffer_add(join_buf, " RIGHT JOIN");
2130                         } else if ( !strcasecmp(type,"full") ) {
2131                                 buffer_add(join_buf, " FULL JOIN");
2132                         } else {
2133                                 buffer_add(join_buf, " INNER JOIN");
2134                         }
2135                 } else {
2136                         buffer_add(join_buf, " INNER JOIN");
2137                 }
2138                 free(type);
2139
2140                 char* table = getSourceDefinition(idlClass);
2141                 buffer_fadd(join_buf, " %s AS \"%s\" ON ( \"%s\".%s = \"%s\".%s",
2142                                         table, class, class, field, leftclass, fkey);
2143                 free(table);
2144
2145                 const jsonObject* filter = jsonObjectGetKeyConst( snode, "filter" );
2146                 if (filter) {
2147                         char* filter_op = jsonObjectToSimpleString( jsonObjectGetKeyConst( snode, "filter_op" ) );
2148                         if (filter_op) {
2149                                 if (!strcasecmp("or",filter_op)) {
2150                                         buffer_add( join_buf, " OR " );
2151                                 } else {
2152                                         buffer_add( join_buf, " AND " );
2153                                 }
2154                         } else {
2155                                 buffer_add( join_buf, " AND " );
2156                         }
2157
2158                         char* jpred = searchWHERE( filter, idlClass, AND_OP_JOIN, NULL );
2159                         OSRF_BUFFER_ADD_CHAR( join_buf, ' ' );
2160                         OSRF_BUFFER_ADD( join_buf, jpred );
2161                         free(jpred);
2162                         free(filter_op);
2163                 }
2164
2165                 buffer_add(join_buf, " ) ");
2166                 
2167                 const jsonObject* join_filter = jsonObjectGetKeyConst( snode, "join" );
2168                 if (join_filter) {
2169                         char* jpred = searchJOIN( join_filter, idlClass );
2170                         OSRF_BUFFER_ADD_CHAR( join_buf, ' ' );
2171                         OSRF_BUFFER_ADD( join_buf, jpred );
2172                         free(jpred);
2173                 }
2174
2175                 free(fkey);
2176                 free(field);
2177         }
2178
2179     jsonIteratorFree(search_itr);
2180
2181         return buffer_release(join_buf);
2182 }
2183
2184 /*
2185
2186 { +class : { -or|-and : { field : { op : value }, ... } ... }, ... }
2187 { +class : { -or|-and : [ { field : { op : value }, ... }, ...] ... }, ... }
2188 [ { +class : { -or|-and : [ { field : { op : value }, ... }, ...] ... }, ... }, ... ]
2189
2190 */
2191
2192 static char* searchWHERE ( const jsonObject* search_hash, osrfHash* meta, int opjoin_type, osrfMethodContext* ctx ) {
2193
2194         osrfLogDebug(
2195         OSRF_LOG_MARK,
2196         "%s: Entering searchWHERE; search_hash addr = %p, meta addr = %p, opjoin_type = %d, ctx addr = %p",
2197         MODULENAME,
2198         search_hash,
2199         meta,
2200         opjoin_type,
2201         ctx
2202     );
2203
2204         growing_buffer* sql_buf = buffer_init(128);
2205
2206         jsonObject* node = NULL;
2207
2208     int first = 1;
2209     if ( search_hash->type == JSON_ARRAY ) {
2210             osrfLogDebug(OSRF_LOG_MARK, "%s: In WHERE clause, condition type is JSON_ARRAY", MODULENAME);
2211         jsonIterator* search_itr = jsonNewIterator( search_hash );
2212         while ( (node = jsonIteratorNext( search_itr )) ) {
2213             if (first) {
2214                 first = 0;
2215             } else {
2216                 if (opjoin_type == OR_OP_JOIN) buffer_add(sql_buf, " OR ");
2217                 else buffer_add(sql_buf, " AND ");
2218             }
2219
2220             char* subpred = searchWHERE( node, meta, opjoin_type, ctx );
2221             buffer_fadd(sql_buf, "( %s )", subpred);
2222             free(subpred);
2223         }
2224         jsonIteratorFree(search_itr);
2225
2226     } else if ( search_hash->type == JSON_HASH ) {
2227             osrfLogDebug(OSRF_LOG_MARK, "%s: In WHERE clause, condition type is JSON_HASH", MODULENAME);
2228         jsonIterator* search_itr = jsonNewIterator( search_hash );
2229         while ( (node = jsonIteratorNext( search_itr )) ) {
2230
2231             if (first) {
2232                 first = 0;
2233             } else {
2234                 if (opjoin_type == OR_OP_JOIN) buffer_add(sql_buf, " OR ");
2235                 else buffer_add(sql_buf, " AND ");
2236             }
2237
2238             if ( !strncmp("+",search_itr->key,1) ) {
2239                 if ( node->type == JSON_STRING ) {
2240                     char* subpred = jsonObjectToSimpleString( node );
2241                     buffer_fadd(sql_buf, " \"%s\".%s ", search_itr->key + 1, subpred);
2242                     free(subpred);
2243                 } else {
2244                     char* subpred = searchWHERE( node, osrfHashGet( oilsIDL(), search_itr->key + 1 ), AND_OP_JOIN, ctx );
2245                     buffer_fadd(sql_buf, "( %s )", subpred);
2246                     free(subpred);
2247                 }
2248             } else if ( !strcasecmp("-or",search_itr->key) ) {
2249                 char* subpred = searchWHERE( node, meta, OR_OP_JOIN, ctx );
2250                 buffer_fadd(sql_buf, "( %s )", subpred);
2251                 free(subpred);
2252             } else if ( !strcasecmp("-and",search_itr->key) ) {
2253                 char* subpred = searchWHERE( node, meta, AND_OP_JOIN, ctx );
2254                 buffer_fadd(sql_buf, "( %s )", subpred);
2255                 free(subpred);
2256             } else if ( !strcasecmp("-exists",search_itr->key) ) {
2257                 char* subpred = SELECT(
2258                     ctx,
2259                     jsonObjectGetKey( node, "select" ),
2260                     jsonObjectGetKey( node, "from" ),
2261                     jsonObjectGetKey( node, "where" ),
2262                     jsonObjectGetKey( node, "having" ),
2263                     jsonObjectGetKey( node, "order_by" ),
2264                     jsonObjectGetKey( node, "limit" ),
2265                     jsonObjectGetKey( node, "offset" ),
2266                     SUBSELECT
2267                 );
2268
2269                 buffer_fadd(sql_buf, "EXISTS ( %s )", subpred);
2270                 free(subpred);
2271             } else if ( !strcasecmp("-not-exists",search_itr->key) ) {
2272                 char* subpred = SELECT(
2273                     ctx,
2274                     jsonObjectGetKey( node, "select" ),
2275                     jsonObjectGetKey( node, "from" ),
2276                     jsonObjectGetKey( node, "where" ),
2277                     jsonObjectGetKey( node, "having" ),
2278                     jsonObjectGetKey( node, "order_by" ),
2279                     jsonObjectGetKey( node, "limit" ),
2280                     jsonObjectGetKey( node, "offset" ),
2281                     SUBSELECT
2282                 );
2283
2284                 buffer_fadd(sql_buf, "NOT EXISTS ( %s )", subpred);
2285                 free(subpred);
2286             } else {
2287
2288                 char* class = osrfHashGet(meta, "classname");
2289                 osrfHash* fields = osrfHashGet(meta, "fields");
2290                 osrfHash* field = osrfHashGet( fields, search_itr->key );
2291
2292
2293                 if (!field) {
2294                     char* table = getSourceDefinition(meta);
2295                     osrfLogError(
2296                         OSRF_LOG_MARK,
2297                         "%s: Attempt to reference non-existent column %s on %s (%s)",
2298                         MODULENAME,
2299                         search_itr->key,
2300                         table,
2301                         class
2302                     );
2303                     buffer_free(sql_buf);
2304                     free(table);
2305                                         jsonIteratorFree(search_itr);
2306                                         return NULL;
2307                 }
2308
2309                 char* subpred = searchPredicate( class, field, node, ctx );
2310                 buffer_add( sql_buf, subpred );
2311                 free(subpred);
2312             }
2313         }
2314             jsonIteratorFree(search_itr);
2315
2316     } else {
2317         // ERROR ... only hash and array allowed at this level
2318         char* predicate_string = jsonObjectToJSON( search_hash );
2319         osrfLogError(
2320             OSRF_LOG_MARK,
2321             "%s: Invalid predicate structure: %s",
2322             MODULENAME,
2323             predicate_string
2324         );
2325         buffer_free(sql_buf);
2326         free(predicate_string);
2327         return NULL;
2328     }
2329
2330
2331         return buffer_release(sql_buf);
2332 }
2333
2334 char* SELECT (
2335                 /* method context */ osrfMethodContext* ctx,
2336                 
2337                 /* SELECT   */ jsonObject* selhash,
2338                 /* FROM     */ jsonObject* join_hash,
2339                 /* WHERE    */ jsonObject* search_hash,
2340                 /* HAVING   */ jsonObject* having_hash,
2341                 /* ORDER BY */ jsonObject* order_hash,
2342                 /* LIMIT    */ jsonObject* limit,
2343                 /* OFFSET   */ jsonObject* offset,
2344                 /* flags    */ int flags
2345 ) {
2346         const char* locale = osrf_message_get_last_locale();
2347
2348         // in case we don't get a select list
2349         jsonObject* defaultselhash = NULL;
2350
2351         // general tmp objects
2352         const jsonObject* tmp_const;
2353         jsonObject* selclass = NULL;
2354         jsonObject* selfield = NULL;
2355         jsonObject* snode = NULL;
2356         jsonObject* onode = NULL;
2357
2358         char* string = NULL;
2359         int from_function = 0;
2360         int first = 1;
2361         int gfirst = 1;
2362         //int hfirst = 1;
2363
2364         // the core search class
2365         char* core_class = NULL;
2366
2367         // metadata about the core search class
2368         osrfHash* core_meta = NULL;
2369
2370         // punt if there's no core class
2371         if (!join_hash || ( join_hash->type == JSON_HASH && !join_hash->size ))
2372                 return NULL;
2373
2374         // get the core class -- the only key of the top level FROM clause, or a string
2375         if (join_hash->type == JSON_HASH) {
2376                 jsonIterator* tmp_itr = jsonNewIterator( join_hash );
2377                 snode = jsonIteratorNext( tmp_itr );
2378                 
2379                 core_class = strdup( tmp_itr->key );
2380                 join_hash = snode;
2381                 
2382                 jsonObject* extra = jsonIteratorNext( tmp_itr );
2383
2384                 jsonIteratorFree( tmp_itr );
2385                 snode = NULL;
2386                 
2387                 // There shouldn't be more than one entry in join_hash
2388                 if( extra )
2389                         return NULL;    // Malformed join_hash; extra entry
2390
2391         } else if (join_hash->type == JSON_ARRAY) {
2392                 from_function = 1;
2393                 core_class = jsonObjectToSimpleString( jsonObjectGetIndex(join_hash, 0) );
2394                 selhash = NULL;
2395
2396         } else if (join_hash->type == JSON_STRING) {
2397                 core_class = jsonObjectToSimpleString( join_hash );
2398                 join_hash = NULL;
2399         }
2400         else
2401                 return NULL;
2402
2403         // punt if we don't know about the core class (and it's not a function)
2404         if (!from_function && !(core_meta = osrfHashGet( oilsIDL(), core_class ))) {
2405                 free(core_class);
2406                 return NULL;
2407         }
2408
2409         // if the select list is empty, or the core class field list is '*',
2410         // build the default select list ...
2411         if (!selhash) {
2412                 selhash = defaultselhash = jsonNewObjectType(JSON_HASH);
2413                 jsonObjectSetKey( selhash, core_class, jsonNewObjectType(JSON_ARRAY) );
2414         } else if ( (tmp_const = jsonObjectGetKeyConst( selhash, core_class )) && tmp_const->type == JSON_STRING ) {
2415                 char* _x = jsonObjectToSimpleString( tmp_const );
2416                 if (!strncmp( "*", _x, 1 )) {
2417                         jsonObjectRemoveKey( selhash, core_class );
2418                         jsonObjectSetKey( selhash, core_class, jsonNewObjectType(JSON_ARRAY) );
2419                 }
2420                 free(_x);
2421         }
2422
2423         // the query buffer
2424         growing_buffer* sql_buf = buffer_init(128);
2425
2426         // temp buffer for the SELECT list
2427         growing_buffer* select_buf = buffer_init(128);
2428         growing_buffer* order_buf = buffer_init(128);
2429         growing_buffer* group_buf = buffer_init(128);
2430         growing_buffer* having_buf = buffer_init(128);
2431
2432         // Build a select list
2433         if(from_function)   // From a function we select everything
2434                 OSRF_BUFFER_ADD_CHAR( select_buf, '*' );
2435         else {
2436
2437                 // If we need to build a default list, do so
2438                 jsonObject* _tmp = jsonObjectGetKey( selhash, core_class );
2439                 if ( _tmp && !_tmp->size ) {
2440
2441                         int i = 0;
2442                         char* field;
2443                         osrfHash* core_fields = osrfHashGet( core_meta, "fields" );
2444
2445                 osrfStringArray* keys = osrfHashKeys( core_fields );
2446                         while ( (field = osrfStringArrayGetString(keys, i++)) ) {
2447                                 if( ! str_is_true( osrfHashGet( osrfHashGet( core_fields, field ), "virtual" ) ) )
2448                                         jsonObjectPush( _tmp, jsonNewObject( field ) );   // not virtual; use it
2449                 }
2450                         osrfStringArrayFree(keys);
2451                 }
2452         
2453                 // Now build the actual select list
2454             int sel_pos = 1;
2455             jsonObject* is_agg = jsonObjectFindPath(selhash, "//aggregate");
2456             first = 1;
2457             gfirst = 1;
2458             jsonIterator* selclass_itr = jsonNewIterator( selhash );
2459             while ( (selclass = jsonIteratorNext( selclass_itr )) ) {    // For each class
2460
2461                     // round trip through the idl, just to be safe
2462                         const char* cname = selclass_itr->key;
2463                         osrfHash* idlClass = osrfHashGet( oilsIDL(), cname );
2464                     if (!idlClass)
2465                                 // No such class.  Skip it.
2466                                 continue;
2467
2468                     // Make sure the target relation is in the join tree.
2469                         
2470                         // At this point join_hash is a step down from the join_hash we
2471                         // received as a parameter.  If the original was a JSON_STRING,
2472                         // then json_hash is now NULL.  If the original was a JSON_HASH,
2473                         // then json_hash is now the first (and only) entry in it,
2474                         // denoting the core class.  We've already excluded the
2475                         // possibility that the original was a JSON_ARRAY, because in
2476                         // that case from_function would be non-NULL, and we wouldn't
2477                         // be here.
2478
2479                     if ( strcmp( core_class, cname )) {
2480                             if (!join_hash) 
2481                                         // There's only one class in the FROM clause,
2482                                         // and this isn't it.  Skip it.
2483                                         continue;
2484
2485                                 if (join_hash->type == JSON_STRING) {
2486                                     string = jsonObjectToSimpleString(join_hash);
2487                                         int different = strcmp( string, cname );
2488                                     free(string);
2489                                         if ( different )
2490                                                 // There's only one class in the FROM clause,
2491                                                 // and this isn't it.  Skip it.
2492                                                 continue;
2493                                 } else {
2494                                     jsonObject* found = jsonObjectFindPath(join_hash, "//%s", cname);
2495                                         unsigned long size = found->size;
2496                                         jsonObjectFree( found );
2497                                         if ( 0 == size )
2498                                                 // No such class anywhere in the join tree.  Skip it.
2499                                                 continue;
2500                                 }
2501                     }
2502
2503                         // Look up some attributes of the current class, so that we 
2504                         // don't have to look them up again for each field
2505                         osrfHash* class_field_set = osrfHashGet( idlClass, "fields" );
2506                         char* class_pkey = osrfHashGet( idlClass, "primarykey" );
2507                         char* class_tname = osrfHashGet( idlClass, "tablename" );
2508                         
2509                     // stitch together the column list ...
2510                     jsonIterator* select_itr = jsonNewIterator( selclass );
2511                     while ( (selfield = jsonIteratorNext( select_itr )) ) {   // for each SELECT column
2512
2513                                 // If we need a separator comma, add one
2514                                 if (first) {
2515                                         first = 0;
2516                                 } else {
2517                                         OSRF_BUFFER_ADD_CHAR( select_buf, ',' );
2518                                 }
2519
2520                             // ... if it's a string, just toss it on the pile
2521                             if (selfield->type == JSON_STRING) {
2522
2523                                     // again, just to be safe
2524                                         const char* _requested_col = selfield->value.s;
2525                                     osrfHash* field = osrfHashGet( class_field_set, _requested_col );
2526                                     if (!field) continue;               // No such field in current class; skip it
2527
2528                                         const char* col_name = osrfHashGet(field, "name");
2529
2530                     if (locale) {
2531                             const char* i18n;
2532                                     if (flags & DISABLE_I18N)
2533                             i18n = NULL;
2534                                                 else
2535                                                         i18n = osrfHashGet(field, "i18n");
2536
2537                                                 if( str_is_true( i18n ) ) {
2538                             buffer_fadd( select_buf,
2539                                                                 " oils_i18n_xlate('%s', '%s', '%s', '%s', \"%s\".%s::TEXT, '%s') AS \"%s\"",
2540                                                                 class_tname, cname, col_name, class_pkey, cname, class_pkey, locale, col_name );
2541                         } else {
2542                                             buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, col_name, col_name );
2543                         }
2544                     } else {
2545                                         buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, col_name, col_name );
2546                     }
2547                                         
2548                             // ... but it could be an object, in which case we check for a Field Transform
2549                             } else {
2550
2551                                     char* _column = jsonObjectToSimpleString( jsonObjectGetKeyConst( selfield, "column" ) );
2552
2553                                     // Get the field definition from the IDL
2554                                     osrfHash* field = osrfHashGet( class_field_set, _column );
2555                                     if (!field) continue;         // No such field defined in IDL.  Skip it.
2556
2557                                         // Decide what to use as a column alias
2558                                         char* _alias;
2559                                         if ((tmp_const = jsonObjectGetKeyConst( selfield, "alias" ))) {
2560                                                 _alias = jsonObjectToSimpleString( tmp_const );
2561                                                 free(_column);
2562                                         } else {         // Use column name as its own alias
2563                                                 _alias = _column;
2564                                         }
2565                                         _column = NULL;   // To emphasize that we're through with _column
2566
2567                                         if (jsonObjectGetKeyConst( selfield, "transform" )) {
2568                                                 char* transform_str = searchFieldTransform(cname, field, selfield);
2569                                                 buffer_fadd(select_buf, " %s AS \"%s\"", transform_str, _alias);
2570                                                 free(transform_str);
2571                                         } else {
2572
2573                                                 const char* fname = osrfHashGet(field, "name");
2574
2575                         if (locale) {
2576                                     const char* i18n;
2577                                         if (flags & DISABLE_I18N)
2578                                 i18n = NULL;
2579                                                         else
2580                                                                 i18n = osrfHashGet(field, "i18n");
2581
2582                                                         if( str_is_true( i18n ) ) {
2583                                 buffer_fadd( select_buf,
2584                                                                         " oils_i18n_xlate('%s', '%s', '%s', '%s', \"%s\".%s::TEXT, '%s') AS \"%s\"",
2585                                                                         class_tname, cname, fname, class_pkey, cname, class_pkey, locale, _alias);
2586                             } else {
2587                                                     buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, fname, _alias);
2588                             }
2589                         } else {
2590                                                 buffer_fadd(select_buf, " \"%s\".%s AS \"%s\"", cname, fname, _alias);
2591                         }
2592                                     }
2593
2594                                     free(_alias);
2595                             }
2596
2597                             if (is_agg->size || (flags & SELECT_DISTINCT)) {
2598
2599                                         const jsonObject* aggregate_obj = jsonObjectGetKey( selfield, "aggregate" );
2600                                     if ( ! obj_is_true( aggregate_obj ) ) {
2601                                             if (gfirst) {
2602                                                     gfirst = 0;
2603                                             } else {
2604                                                         OSRF_BUFFER_ADD_CHAR( group_buf, ',' );
2605                                             }
2606
2607                                             buffer_fadd(group_buf, " %d", sel_pos);
2608                                         /*
2609                                     } else if (is_agg = jsonObjectGetKey( selfield, "having" )) {
2610                                             if (gfirst) {
2611                                                     gfirst = 0;
2612                                             } else {
2613                                                         OSRF_BUFFER_ADD_CHAR( group_buf, ',' );
2614                                             }
2615
2616                                             _column = searchFieldTransform(cname, field, selfield);
2617                                                 OSRF_BUFFER_ADD_CHAR(group_buf, ' ');
2618                                                 OSRF_BUFFER_ADD(group_buf, _column);
2619                                             _column = searchFieldTransform(cname, field, selfield);
2620                                         */
2621                                     }
2622                             }
2623
2624                             sel_pos++;
2625                     } // end while -- iterating across SELECT columns
2626
2627             jsonIteratorFree(select_itr);
2628             } // end while -- iterating across classes
2629
2630         jsonIteratorFree(selclass_itr);
2631
2632             if (is_agg) jsonObjectFree(is_agg);
2633     }
2634
2635
2636         char* col_list = buffer_release(select_buf);
2637         char* table = NULL;
2638         if (from_function) table = searchValueTransform(join_hash);
2639         else table = getSourceDefinition(core_meta);
2640
2641         // Put it all together
2642         buffer_fadd(sql_buf, "SELECT %s FROM %s AS \"%s\" ", col_list, table, core_class );
2643         free(col_list);
2644         free(table);
2645
2646     if (!from_function) {
2647             // Now, walk the join tree and add that clause
2648             if ( join_hash ) {
2649                     char* join_clause = searchJOIN( join_hash, core_meta );
2650                     buffer_add(sql_buf, join_clause);
2651                     free(join_clause);
2652             }
2653
2654                 // Build a WHERE clause, if there is one
2655             if ( search_hash ) {
2656                     buffer_add(sql_buf, " WHERE ");
2657
2658                     // and it's on the WHERE clause
2659                     char* pred = searchWHERE( search_hash, core_meta, AND_OP_JOIN, ctx );
2660
2661                     if (pred) {
2662                                 buffer_add(sql_buf, pred);
2663                                 free(pred);
2664                         } else {
2665                                 if (ctx) {
2666                                 osrfAppSessionStatus(
2667                                         ctx->session,
2668                                         OSRF_STATUS_INTERNALSERVERERROR,
2669                                         "osrfMethodException",
2670                                         ctx->request,
2671                                         "Severe query error in WHERE predicate -- see error log for more details"
2672                                 );
2673                             }
2674                             free(core_class);
2675                             buffer_free(having_buf);
2676                             buffer_free(group_buf);
2677                             buffer_free(order_buf);
2678                             buffer_free(sql_buf);
2679                             if (defaultselhash) jsonObjectFree(defaultselhash);
2680                             return NULL;
2681                     }
2682         }
2683
2684                 // Build a HAVING clause, if there is one
2685             if ( having_hash ) {
2686                     buffer_add(sql_buf, " HAVING ");
2687
2688                     // and it's on the the WHERE clause
2689                     char* pred = searchWHERE( having_hash, core_meta, AND_OP_JOIN, ctx );
2690
2691                     if (pred) {
2692                                 buffer_add(sql_buf, pred);
2693                                 free(pred);
2694                         } else {
2695                                 if (ctx) {
2696                                 osrfAppSessionStatus(
2697                                         ctx->session,
2698                                         OSRF_STATUS_INTERNALSERVERERROR,
2699                                         "osrfMethodException",
2700                                         ctx->request,
2701                                         "Severe query error in HAVING predicate -- see error log for more details"
2702                                 );
2703                             }
2704                             free(core_class);
2705                             buffer_free(having_buf);
2706                             buffer_free(group_buf);
2707                             buffer_free(order_buf);
2708                             buffer_free(sql_buf);
2709                             if (defaultselhash) jsonObjectFree(defaultselhash);
2710                             return NULL;
2711                     }
2712             }
2713
2714                 // Build an ORDER BY clause, if there is one
2715             first = 1;
2716             jsonIterator* class_itr = jsonNewIterator( order_hash );
2717             while ( (snode = jsonIteratorNext( class_itr )) ) {
2718
2719                     if (!jsonObjectGetKeyConst(selhash,class_itr->key))
2720                             continue;
2721
2722                     if ( snode->type == JSON_HASH ) {
2723
2724                         jsonIterator* order_itr = jsonNewIterator( snode );
2725                             while ( (onode = jsonIteratorNext( order_itr )) ) {
2726
2727                                     if (!oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ))
2728                                             continue;
2729
2730                                     char* direction = NULL;
2731                                     if ( onode->type == JSON_HASH ) {
2732                                             if ( jsonObjectGetKeyConst( onode, "transform" ) ) {
2733                                                     string = searchFieldTransform(
2734                                                             class_itr->key,
2735                                                             oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ),
2736                                                             onode
2737                                                     );
2738                                             } else {
2739                                                     growing_buffer* field_buf = buffer_init(16);
2740                                                     buffer_fadd(field_buf, "\"%s\".%s", class_itr->key, order_itr->key);
2741                                                     string = buffer_release(field_buf);
2742                                             }
2743
2744                                             if ( (tmp_const = jsonObjectGetKeyConst( onode, "direction" )) ) {
2745                                                     direction = jsonObjectToSimpleString(tmp_const);
2746                                                     if (!strncasecmp(direction, "d", 1)) {
2747                                                             free(direction);
2748                                                             direction = " DESC";
2749                                                     } else {
2750                                                             free(direction);
2751                                                             direction = " ASC";
2752                                                     }
2753                                             }
2754
2755                                     } else {
2756                                             string = strdup(order_itr->key);
2757                                             direction = jsonObjectToSimpleString(onode);
2758                                             if (!strncasecmp(direction, "d", 1)) {
2759                                                     free(direction);
2760                                                     direction = " DESC";
2761                                             } else {
2762                                                     free(direction);
2763                                                     direction = " ASC";
2764                                             }
2765                                     }
2766
2767                                     if (first) {
2768                                             first = 0;
2769                                     } else {
2770                                             buffer_add(order_buf, ", ");
2771                                     }
2772
2773                                     buffer_add(order_buf, string);
2774                                     free(string);
2775
2776                                     if (direction) {
2777                                             buffer_add(order_buf, direction);
2778                                     }
2779
2780                             } // end while
2781                 // jsonIteratorFree(order_itr);
2782
2783                     } else if ( snode->type == JSON_ARRAY ) {
2784
2785                         jsonIterator* order_itr = jsonNewIterator( snode );
2786                             while ( (onode = jsonIteratorNext( order_itr )) ) {
2787
2788                                     char* _f = jsonObjectToSimpleString( onode );
2789
2790                                     if (!oilsIDLFindPath( "/%s/fields/%s", class_itr->key, _f))
2791                                             continue;
2792
2793                                     if (first) {
2794                                             first = 0;
2795                                     } else {
2796                                             buffer_add(order_buf, ", ");
2797                                     }
2798
2799                                     buffer_add(order_buf, _f);
2800                                     free(_f);
2801
2802                             } // end while
2803                 // jsonIteratorFree(order_itr);
2804
2805
2806                     // IT'S THE OOOOOOOOOOOLD STYLE!
2807                     } else {
2808                             osrfLogError(OSRF_LOG_MARK, "%s: Possible SQL injection attempt; direct order by is not allowed", MODULENAME);
2809                             if (ctx) {
2810                                 osrfAppSessionStatus(
2811                                         ctx->session,
2812                                         OSRF_STATUS_INTERNALSERVERERROR,
2813                                         "osrfMethodException",
2814                                         ctx->request,
2815                                         "Severe query error -- see error log for more details"
2816                                 );
2817                             }
2818
2819                             free(core_class);
2820                             buffer_free(having_buf);
2821                             buffer_free(group_buf);
2822                             buffer_free(order_buf);
2823                             buffer_free(sql_buf);
2824                             if (defaultselhash) jsonObjectFree(defaultselhash);
2825                             jsonIteratorFree(class_itr);
2826                             return NULL;
2827                     }
2828
2829             } // end while
2830                 // jsonIteratorFree(class_itr);
2831         }
2832
2833
2834         string = buffer_release(group_buf);
2835
2836         if (strlen(string)) {
2837                 OSRF_BUFFER_ADD( sql_buf, " GROUP BY " );
2838                 OSRF_BUFFER_ADD( sql_buf, string );
2839         }
2840
2841         free(string);
2842
2843         string = buffer_release(having_buf);
2844  
2845         if (strlen(string)) {
2846                 OSRF_BUFFER_ADD( sql_buf, " HAVING " );
2847                 OSRF_BUFFER_ADD( sql_buf, string );
2848         }
2849
2850         free(string);
2851
2852         string = buffer_release(order_buf);
2853
2854         if (strlen(string)) {
2855                 OSRF_BUFFER_ADD( sql_buf, " ORDER BY " );
2856                 OSRF_BUFFER_ADD( sql_buf, string );
2857         }
2858
2859         free(string);
2860
2861         if ( limit ){
2862                 string = jsonObjectToSimpleString(limit);
2863                 buffer_fadd( sql_buf, " LIMIT %d", atoi(string) );
2864                 free(string);
2865         }
2866
2867         if (offset) {
2868                 string = jsonObjectToSimpleString(offset);
2869                 buffer_fadd( sql_buf, " OFFSET %d", atoi(string) );
2870                 free(string);
2871         }
2872
2873         if (!(flags & SUBSELECT)) OSRF_BUFFER_ADD_CHAR(sql_buf, ';');
2874
2875         free(core_class);
2876         if (defaultselhash) jsonObjectFree(defaultselhash);
2877
2878         return buffer_release(sql_buf);
2879
2880 }
2881
2882 static char* buildSELECT ( jsonObject* search_hash, jsonObject* order_hash, osrfHash* meta, osrfMethodContext* ctx ) {
2883
2884         const char* locale = osrf_message_get_last_locale();
2885
2886         osrfHash* fields = osrfHashGet(meta, "fields");
2887         char* core_class = osrfHashGet(meta, "classname");
2888
2889         const jsonObject* join_hash = jsonObjectGetKeyConst( order_hash, "join" );
2890
2891         jsonObject* node = NULL;
2892         jsonObject* snode = NULL;
2893         jsonObject* onode = NULL;
2894         const jsonObject* _tmp = NULL;
2895         jsonObject* selhash = NULL;
2896         jsonObject* defaultselhash = NULL;
2897
2898         growing_buffer* sql_buf = buffer_init(128);
2899         growing_buffer* select_buf = buffer_init(128);
2900
2901         if ( !(selhash = jsonObjectGetKey( order_hash, "select" )) ) {
2902                 defaultselhash = jsonNewObjectType(JSON_HASH);
2903                 selhash = defaultselhash;
2904         }
2905         
2906         if ( !jsonObjectGetKeyConst(selhash,core_class) ) {
2907                 jsonObjectSetKey( selhash, core_class, jsonNewObjectType(JSON_ARRAY) );
2908                 jsonObject* flist = jsonObjectGetKey( selhash, core_class );
2909                 
2910                 int i = 0;
2911                 char* field;
2912
2913                 osrfStringArray* keys = osrfHashKeys( fields );
2914                 while ( (field = osrfStringArrayGetString(keys, i++)) ) {
2915                         if( ! str_is_true( osrfHashGet( osrfHashGet( fields, field ), "virtual" ) ) )
2916                                 jsonObjectPush( flist, jsonNewObject( field ) );
2917                 }
2918                 osrfStringArrayFree(keys);
2919         }
2920
2921         int first = 1;
2922         jsonIterator* class_itr = jsonNewIterator( selhash );
2923         while ( (snode = jsonIteratorNext( class_itr )) ) {
2924
2925                 osrfHash* idlClass = osrfHashGet( oilsIDL(), class_itr->key );
2926                 if (!idlClass) continue;
2927                 char* cname = osrfHashGet(idlClass, "classname");
2928
2929                 if (strcmp(core_class,class_itr->key)) {
2930                         if (!join_hash) continue;
2931
2932                         jsonObject* found =  jsonObjectFindPath(join_hash, "//%s", class_itr->key);
2933                         if (!found->size) {
2934                                 jsonObjectFree(found);
2935                                 continue;
2936                         }
2937
2938                         jsonObjectFree(found);
2939                 }
2940
2941                 jsonIterator* select_itr = jsonNewIterator( snode );
2942                 while ( (node = jsonIteratorNext( select_itr )) ) {
2943                         char* item_str = jsonObjectToSimpleString(node);
2944                         osrfHash* field = osrfHashGet( osrfHashGet( idlClass, "fields" ), item_str );
2945                         free(item_str);
2946                         char* fname = osrfHashGet(field, "name");
2947
2948                         if (!field) continue;
2949
2950                         if (first) {
2951                                 first = 0;
2952                         } else {
2953                                 OSRF_BUFFER_ADD_CHAR(select_buf, ',');
2954                         }
2955
2956             if (locale) {
2957                         const char* i18n;
2958                                 const jsonObject* no_i18n_obj = jsonObjectGetKey( order_hash, "no_i18n" );
2959                                 if ( obj_is_true( no_i18n_obj ) )    // Suppress internationalization?
2960                                         i18n = NULL;
2961                                 else
2962                                         i18n = osrfHashGet(field, "i18n");
2963
2964                                 if( str_is_true( i18n ) ) {
2965                         char* pkey = osrfHashGet(idlClass, "primarykey");
2966                         char* tname = osrfHashGet(idlClass, "tablename");
2967
2968                     buffer_fadd(select_buf, " oils_i18n_xlate('%s', '%s', '%s', '%s', \"%s\".%s::TEXT, '%s') AS \"%s\"", tname, cname, fname, pkey, cname, pkey, locale, fname);
2969                 } else {
2970                                 buffer_fadd(select_buf, " \"%s\".%s", cname, fname);
2971                 }
2972             } else {
2973                             buffer_fadd(select_buf, " \"%s\".%s", cname, fname);
2974             }
2975                 }
2976
2977         jsonIteratorFree(select_itr);
2978         }
2979
2980     jsonIteratorFree(class_itr);
2981
2982         char* col_list = buffer_release(select_buf);
2983         char* table = getSourceDefinition(meta);
2984
2985         buffer_fadd(sql_buf, "SELECT %s FROM %s AS \"%s\"", col_list, table, core_class );
2986         free(col_list);
2987         free(table);
2988
2989         if ( join_hash ) {
2990                 char* join_clause = searchJOIN( join_hash, meta );
2991                 OSRF_BUFFER_ADD_CHAR(sql_buf, ' ');
2992                 OSRF_BUFFER_ADD(sql_buf, join_clause);
2993                 free(join_clause);
2994         }
2995
2996         osrfLogDebug(OSRF_LOG_MARK, "%s pre-predicate SQL =  %s",
2997                                  MODULENAME, OSRF_BUFFER_C_STR(sql_buf));
2998
2999         buffer_add(sql_buf, " WHERE ");
3000
3001         char* pred = searchWHERE( search_hash, meta, AND_OP_JOIN, ctx );
3002         if (!pred) {
3003                 osrfAppSessionStatus(
3004                         ctx->session,
3005                         OSRF_STATUS_INTERNALSERVERERROR,
3006                                 "osrfMethodException",
3007                                 ctx->request,
3008                                 "Severe query error -- see error log for more details"
3009                         );
3010                 buffer_free(sql_buf);
3011                 if(defaultselhash) jsonObjectFree(defaultselhash);
3012                 return NULL;
3013         } else {
3014                 buffer_add(sql_buf, pred);
3015                 free(pred);
3016         }
3017
3018         if (order_hash) {
3019                 char* string = NULL;
3020                 if ( (_tmp = jsonObjectGetKeyConst( order_hash, "order_by" )) ){
3021
3022                         growing_buffer* order_buf = buffer_init(128);
3023
3024                         first = 1;
3025                         jsonIterator* class_itr = jsonNewIterator( _tmp );
3026                         while ( (snode = jsonIteratorNext( class_itr )) ) {
3027
3028                                 if (!jsonObjectGetKeyConst(selhash,class_itr->key))
3029                                         continue;
3030
3031                                 if ( snode->type == JSON_HASH ) {
3032
3033                                         jsonIterator* order_itr = jsonNewIterator( snode );
3034                                         while ( (onode = jsonIteratorNext( order_itr )) ) {
3035
3036                                                 if (!oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ))
3037                                                         continue;
3038
3039                                                 char* direction = NULL;
3040                                                 if ( onode->type == JSON_HASH ) {
3041                                                         if ( jsonObjectGetKeyConst( onode, "transform" ) ) {
3042                                                                 string = searchFieldTransform(
3043                                                                         class_itr->key,
3044                                                                         oilsIDLFindPath( "/%s/fields/%s", class_itr->key, order_itr->key ),
3045                                                                         onode
3046                                                                 );
3047                                                         } else {
3048                                                                 growing_buffer* field_buf = buffer_init(16);
3049                                                                 buffer_fadd(field_buf, "\"%s\".%s", class_itr->key, order_itr->key);
3050                                                                 string = buffer_release(field_buf);
3051                                                         }
3052
3053                                                         if ( (_tmp = jsonObjectGetKeyConst( onode, "direction" )) ) {
3054                                                                 direction = jsonObjectToSimpleString(_tmp);
3055                                                                 if (!strncasecmp(direction, "d", 1)) {
3056                                                                         free(direction);
3057                                                                         direction = " DESC";
3058                                                                 } else {
3059                                                                         free(direction);
3060                                                                         direction = " ASC";
3061                                                                 }
3062                                                         }
3063
3064                                                 } else {
3065                                                         string = strdup(order_itr->key);
3066                                                         direction = jsonObjectToSimpleString(onode);
3067                                                         if (!strncasecmp(direction, "d", 1)) {
3068                                                                 free(direction);
3069                                                                 direction = " DESC";
3070                                                         } else {
3071                                                                 free(direction);
3072                                                                 direction = " ASC";
3073                                                         }
3074                                                 }
3075
3076                                                 if (first) {
3077                                                         first = 0;
3078                                                 } else {
3079                                                         buffer_add(order_buf, ", ");
3080                                                 }
3081
3082                                                 buffer_add(order_buf, string);
3083                                                 free(string);
3084
3085                                                 if (direction) {
3086                                                         buffer_add(order_buf, direction);
3087                                                 }
3088
3089                                         }
3090
3091                     jsonIteratorFree(order_itr);
3092
3093                                 } else {
3094                                         string = jsonObjectToSimpleString(snode);
3095                                         buffer_add(order_buf, string);
3096                                         free(string);
3097                                         break;
3098                                 }
3099
3100                         }
3101
3102             jsonIteratorFree(class_itr);
3103
3104                         string = buffer_release(order_buf);
3105
3106                         if (strlen(string)) {
3107                                 OSRF_BUFFER_ADD( sql_buf, " ORDER BY " );
3108                                 OSRF_BUFFER_ADD( sql_buf, string );
3109                         }
3110
3111                         free(string);
3112                 }
3113
3114                 if ( (_tmp = jsonObjectGetKeyConst( order_hash, "limit" )) ){
3115                         string = jsonObjectToSimpleString(_tmp);
3116                         buffer_fadd(
3117                                 sql_buf,
3118                                 " LIMIT %d",
3119                                 atoi(string)
3120                         );
3121                         free(string);
3122                 }
3123
3124                 _tmp = jsonObjectGetKeyConst( order_hash, "offset" );
3125                 if (_tmp) {
3126                         string = jsonObjectToSimpleString(_tmp);
3127                         buffer_fadd(
3128                                 sql_buf,
3129                                 " OFFSET %d",
3130                                 atoi(string)
3131                         );
3132                         free(string);
3133                 }
3134         }
3135
3136         if (defaultselhash) jsonObjectFree(defaultselhash);
3137
3138         OSRF_BUFFER_ADD_CHAR(sql_buf, ';');
3139         return buffer_release(sql_buf);
3140 }
3141
3142 int doJSONSearch ( osrfMethodContext* ctx ) {
3143         if(osrfMethodVerifyContext( ctx )) {
3144                 osrfLogError( OSRF_LOG_MARK,  "Invalid method context" );
3145                 return -1;
3146         }
3147
3148         osrfLogDebug(OSRF_LOG_MARK, "Recieved query request");
3149
3150         int err = 0;
3151
3152         // XXX for now...
3153         dbhandle = writehandle;
3154
3155         jsonObject* hash = jsonObjectGetIndex(ctx->params, 0);
3156
3157         int flags = 0;
3158
3159         if ( obj_is_true( jsonObjectGetKey( hash, "distinct" ) ) )
3160                 flags |= SELECT_DISTINCT;
3161
3162         if ( obj_is_true( jsonObjectGetKey( hash, "no_i18n" ) ) )
3163                 flags |= DISABLE_I18N;
3164
3165         osrfLogDebug(OSRF_LOG_MARK, "Building SQL ...");
3166         char* sql = SELECT(
3167                         ctx,
3168                         jsonObjectGetKey( hash, "select" ),
3169                         jsonObjectGetKey( hash, "from" ),
3170                         jsonObjectGetKey( hash, "where" ),
3171                         jsonObjectGetKey( hash, "having" ),
3172                         jsonObjectGetKey( hash, "order_by" ),
3173                         jsonObjectGetKey( hash, "limit" ),
3174                         jsonObjectGetKey( hash, "offset" ),
3175                         flags
3176         );
3177
3178         if (!sql) {
3179                 err = -1;
3180                 return err;
3181         }
3182         
3183         osrfLogDebug(OSRF_LOG_MARK, "%s SQL =  %s", MODULENAME, sql);
3184         dbi_result result = dbi_conn_query(dbhandle, sql);
3185
3186         if(result) {
3187                 osrfLogDebug(OSRF_LOG_MARK, "Query returned with no errors");
3188
3189                 if (dbi_result_first_row(result)) {
3190                         /* JSONify the result */
3191                         osrfLogDebug(OSRF_LOG_MARK, "Query returned at least one row");
3192
3193                         do {
3194                                 jsonObject* return_val = oilsMakeJSONFromResult( result );
3195                                 osrfAppRespond( ctx, return_val );
3196                 jsonObjectFree( return_val );
3197                         } while (dbi_result_next_row(result));
3198
3199                 } else {
3200                         osrfLogDebug(OSRF_LOG_MARK, "%s returned no results for query %s", MODULENAME, sql);
3201                 }
3202
3203                 osrfAppRespondComplete( ctx, NULL );
3204
3205                 /* clean up the query */
3206                 dbi_result_free(result); 
3207
3208         } else {
3209                 err = -1;
3210                 osrfLogError(OSRF_LOG_MARK, "%s: Error with query [%s]", MODULENAME, sql);
3211                 osrfAppSessionStatus(
3212                         ctx->session,
3213                         OSRF_STATUS_INTERNALSERVERERROR,
3214                         "osrfMethodException",
3215                         ctx->request,
3216                         "Severe query error -- see error log for more details"
3217                 );
3218         }
3219
3220         free(sql);
3221         return err;
3222 }
3223
3224 static jsonObject* doFieldmapperSearch ( osrfMethodContext* ctx, osrfHash* meta,
3225                 const jsonObject* params, int* err ) {
3226
3227         // XXX for now...
3228         dbhandle = writehandle;
3229
3230         osrfHash* links = osrfHashGet(meta, "links");
3231         osrfHash* fields = osrfHashGet(meta, "fields");
3232         char* core_class = osrfHashGet(meta, "classname");
3233         char* pkey = osrfHashGet(meta, "primarykey");
3234
3235         const jsonObject* _tmp;
3236         jsonObject* obj;
3237         jsonObject* search_hash = jsonObjectGetIndex(params, 0);
3238         jsonObject* order_hash = jsonObjectGetIndex(params, 1);
3239
3240         char* sql = buildSELECT( search_hash, order_hash, meta, ctx );
3241         if (!sql) {
3242                 osrfLogDebug(OSRF_LOG_MARK, "Problem building query, returning NULL");
3243                 *err = -1;
3244                 return NULL;
3245         }
3246         
3247         osrfLogDebug(OSRF_LOG_MARK, "%s SQL =  %s", MODULENAME, sql);
3248
3249         dbi_result result = dbi_conn_query(dbhandle, sql);
3250         if( NULL == result ) {
3251                 osrfLogError(OSRF_LOG_MARK, "%s: Error retrieving %s with query [%s]",
3252                         MODULENAME, osrfHashGet(meta, "fieldmapper"), sql);
3253                 osrfAppSessionStatus(
3254                         ctx->session,
3255                         OSRF_STATUS_INTERNALSERVERERROR,
3256                         "osrfMethodException",
3257                         ctx->request,
3258                         "Severe query error -- see error log for more details"
3259                 );
3260                 *err = -1;
3261                 free(sql);
3262                 return jsonNULL;
3263
3264         } else {
3265                 osrfLogDebug(OSRF_LOG_MARK, "Query returned with no errors");
3266         }
3267
3268         jsonObject* res_list = jsonNewObjectType(JSON_ARRAY);
3269         osrfHash* dedup = osrfNewHash();
3270
3271         if (dbi_result_first_row(result)) {
3272                 /* JSONify the result */
3273                 osrfLogDebug(OSRF_LOG_MARK, "Query returned at least one row");
3274                 do {
3275                         obj = oilsMakeFieldmapperFromResult( result, meta );
3276                         char* pkey_val = oilsFMGetString( obj, pkey );
3277                         if ( osrfHashGet( dedup, pkey_val ) ) {
3278                                 jsonObjectFree(obj);
3279                                 free(pkey_val);
3280                         } else {
3281                                 osrfHashSet( dedup, pkey_val, pkey_val );
3282                                 jsonObjectPush(res_list, obj);
3283                         }
3284                 } while (dbi_result_next_row(result));
3285         } else {
3286                 osrfLogDebug(OSRF_LOG_MARK, "%s returned no results for query %s",
3287                         MODULENAME, sql );
3288         }
3289
3290         osrfHashFree(dedup);
3291         /* clean up the query */
3292         dbi_result_free(result);
3293         free(sql);
3294
3295         if (res_list->size && order_hash) {
3296                 _tmp = jsonObjectGetKeyConst( order_hash, "flesh" );
3297                 if (_tmp) {
3298                         int x = (int)jsonObjectGetNumber(_tmp);
3299                         if (x == -1 || x > max_flesh_depth) x = max_flesh_depth;
3300
3301                         const jsonObject* temp_blob;
3302                         if ((temp_blob = jsonObjectGetKeyConst( order_hash, "flesh_fields" )) && x > 0) {
3303
3304                                 jsonObject* flesh_blob = jsonObjectClone( temp_blob );
3305                                 const jsonObject* flesh_fields = jsonObjectGetKeyConst( flesh_blob, core_class );
3306
3307                                 osrfStringArray* link_fields = NULL;
3308
3309                                 if (flesh_fields) {
3310                                         if (flesh_fields->size == 1) {
3311                                                 char* _t = jsonObjectToSimpleString( jsonObjectGetIndex( flesh_fields, 0 ) );
3312                                                 if (!strcmp(_t,"*")) link_fields = osrfHashKeys( links );
3313                                                 free(_t);
3314                                         }
3315
3316                                         if (!link_fields) {
3317                                                 jsonObject* _f;
3318                                                 link_fields = osrfNewStringArray(1);
3319                                                 jsonIterator* _i = jsonNewIterator( flesh_fields );
3320                                                 while ((_f = jsonIteratorNext( _i ))) {
3321                                                         osrfStringArrayAdd( link_fields, jsonObjectToSimpleString( _f ) );
3322                                                 }
3323                         jsonIteratorFree(_i);
3324                                         }
3325                                 }
3326
3327                                 jsonObject* cur;
3328                                 jsonIterator* itr = jsonNewIterator( res_list );
3329                                 while ((cur = jsonIteratorNext( itr ))) {
3330
3331                                         int i = 0;
3332                                         char* link_field;
3333                                         
3334                                         while ( (link_field = osrfStringArrayGetString(link_fields, i++)) ) {
3335
3336                                                 osrfLogDebug(OSRF_LOG_MARK, "Starting to flesh %s", link_field);
3337
3338                                                 osrfHash* kid_link = osrfHashGet(links, link_field);
3339                                                 if (!kid_link) continue;
3340
3341                                                 osrfHash* field = osrfHashGet(fields, link_field);
3342                                                 if (!field) continue;
3343
3344                                                 osrfHash* value_field = field;
3345
3346                                                 osrfHash* kid_idl = osrfHashGet(oilsIDL(), osrfHashGet(kid_link, "class"));
3347                                                 if (!kid_idl) continue;
3348
3349                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "has_many" ))) { // has_many
3350                                                         value_field = osrfHashGet( fields, osrfHashGet(meta, "primarykey") );
3351                                                 }
3352                                                         
3353                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "might_have" ))) { // might_have
3354                                                         value_field = osrfHashGet( fields, osrfHashGet(meta, "primarykey") );
3355                                                 }
3356
3357                                                 osrfStringArray* link_map = osrfHashGet( kid_link, "map" );
3358
3359                                                 if (link_map->size > 0) {
3360                                                         jsonObject* _kid_key = jsonNewObjectType(JSON_ARRAY);
3361                                                         jsonObjectPush(
3362                                                                 _kid_key,
3363                                                                 jsonNewObject( osrfStringArrayGetString( link_map, 0 ) )
3364                                                         );
3365
3366                                                         jsonObjectSetKey(
3367                                                                 flesh_blob,
3368                                                                 osrfHashGet(kid_link, "class"),
3369                                                                 _kid_key
3370                                                         );
3371                                                 };
3372
3373                                                 osrfLogDebug(
3374                                                         OSRF_LOG_MARK,
3375                                                         "Link field: %s, remote class: %s, fkey: %s, reltype: %s",
3376                                                         osrfHashGet(kid_link, "field"),
3377                                                         osrfHashGet(kid_link, "class"),
3378                                                         osrfHashGet(kid_link, "key"),
3379                                                         osrfHashGet(kid_link, "reltype")
3380                                                 );
3381
3382                                                 jsonObject* fake_params = jsonNewObjectType(JSON_ARRAY);
3383                                                 jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH)); // search hash
3384                                                 jsonObjectPush(fake_params, jsonNewObjectType(JSON_HASH)); // order/flesh hash
3385
3386                                                 osrfLogDebug(OSRF_LOG_MARK, "Creating dummy params object...");
3387
3388                                                 char* search_key =
3389                                                 jsonObjectToSimpleString(
3390                                                         jsonObjectGetIndex(
3391                                                                 cur,
3392                                                                 atoi( osrfHashGet(value_field, "array_position") )
3393                                                         )
3394                                                 );
3395
3396                                                 if (!search_key) {
3397                                                         osrfLogDebug(OSRF_LOG_MARK, "Nothing to search for!");
3398                                                         continue;
3399                                                 }
3400                                                         
3401                                                 jsonObjectSetKey(
3402                                                         jsonObjectGetIndex(fake_params, 0),
3403                                                         osrfHashGet(kid_link, "key"),
3404                                                         jsonNewObject( search_key )
3405                                                 );
3406
3407                                                 free(search_key);
3408
3409
3410                                                 jsonObjectSetKey(
3411                                                         jsonObjectGetIndex(fake_params, 1),
3412                                                         "flesh",
3413                                                         jsonNewNumberObject( (double)(x - 1 + link_map->size) )
3414                                                 );
3415
3416                                                 if (flesh_blob)
3417                                                         jsonObjectSetKey( jsonObjectGetIndex(fake_params, 1), "flesh_fields", jsonObjectClone(flesh_blob) );
3418
3419                                                 if (jsonObjectGetKeyConst(order_hash, "order_by")) {
3420                                                         jsonObjectSetKey(
3421                                                                 jsonObjectGetIndex(fake_params, 1),
3422                                                                 "order_by",
3423                                                                 jsonObjectClone(jsonObjectGetKeyConst(order_hash, "order_by"))
3424                                                         );
3425                                                 }
3426
3427                                                 if (jsonObjectGetKeyConst(order_hash, "select")) {
3428                                                         jsonObjectSetKey(
3429                                                                 jsonObjectGetIndex(fake_params, 1),
3430                                                                 "select",
3431                                                                 jsonObjectClone(jsonObjectGetKeyConst(order_hash, "select"))
3432                                                         );
3433                                                 }
3434
3435                                                 jsonObject* kids = doFieldmapperSearch(ctx, kid_idl, fake_params, err);
3436
3437                                                 if(*err) {
3438                                                         jsonObjectFree( fake_params );
3439                                                         osrfStringArrayFree(link_fields);
3440                                                         jsonIteratorFree(itr);
3441                                                         jsonObjectFree(res_list);
3442                                                         jsonObjectFree(flesh_blob);
3443                                                         return jsonNULL;
3444                                                 }
3445
3446                                                 osrfLogDebug(OSRF_LOG_MARK, "Search for %s return %d linked objects", osrfHashGet(kid_link, "class"), kids->size);
3447
3448                                                 jsonObject* X = NULL;
3449                                                 if ( link_map->size > 0 && kids->size > 0 ) {
3450                                                         X = kids;
3451                                                         kids = jsonNewObjectType(JSON_ARRAY);
3452
3453                                                         jsonObject* _k_node;
3454                                                         jsonIterator* _k = jsonNewIterator( X );
3455                                                         while ((_k_node = jsonIteratorNext( _k ))) {
3456                                                                 jsonObjectPush(
3457                                                                         kids,
3458                                                                         jsonObjectClone(
3459                                                                                 jsonObjectGetIndex(
3460                                                                                         _k_node,
3461                                                                                         (unsigned long)atoi(
3462                                                                                                 osrfHashGet(
3463                                                                                                         osrfHashGet(
3464                                                                                                                 osrfHashGet(
3465                                                                                                                         osrfHashGet(
3466                                                                                                                                 oilsIDL(),
3467                                                                                                                                 osrfHashGet(kid_link, "class")
3468                                                                                                                         ),
3469                                                                                                                         "fields"
3470                                                                                                                 ),
3471                                                                                                                 osrfStringArrayGetString( link_map, 0 )
3472                                                                                                         ),
3473                                                                                                         "array_position"
3474                                                                                                 )
3475                                                                                         )
3476                                                                                 )
3477                                                                         )
3478                                                                 );
3479                                                         }
3480                                                         jsonIteratorFree(_k);
3481                                                 }
3482
3483                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "has_a" )) || !(strcmp( osrfHashGet(kid_link, "reltype"), "might_have" ))) {
3484                                                         osrfLogDebug(OSRF_LOG_MARK, "Storing fleshed objects in %s", osrfHashGet(kid_link, "field"));
3485                                                         jsonObjectSetIndex(
3486                                                                 cur,
3487                                                                 (unsigned long)atoi( osrfHashGet( field, "array_position" ) ),
3488                                                                 jsonObjectClone( jsonObjectGetIndex(kids, 0) )
3489                                                         );
3490                                                 }
3491
3492                                                 if (!(strcmp( osrfHashGet(kid_link, "reltype"), "has_many" ))) { // has_many
3493                                                         osrfLogDebug(OSRF_LOG_MARK, "Storing fleshed objects in %s", osrfHashGet(kid_link, "field"));
3494                                                         jsonObjectSetIndex(
3495                                                                 cur,
3496                                                                 (unsigned long)atoi( osrfHashGet( field, "array_position" ) ),
3497                                                                 jsonObjectClone( kids )
3498                                                         );
3499                                                 }
3500
3501                                                 if (X) {
3502                                                         jsonObjectFree(kids);
3503                                                         kids = X;
3504                                                 }
3505
3506                                                 jsonObjectFree( kids );
3507                                                 jsonObjectFree( fake_params );
3508
3509                                                 osrfLogDebug(OSRF_LOG_MARK, "Fleshing of %s complete", osrfHashGet(kid_link, "field"));
3510                                                 osrfLogDebug(OSRF_LOG_MARK, "%s", jsonObjectToJSON(cur));
3511
3512                                         }
3513                                 }
3514                                 jsonObjectFree( flesh_blob );
3515                                 osrfStringArrayFree(link_fields);
3516                                 jsonIteratorFree(itr);
3517                         }
3518                 }
3519         }
3520
3521         return res_list;
3522 }
3523
3524
3525 static jsonObject* doUpdate(osrfMethodContext* ctx, int* err ) {
3526
3527         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
3528 #ifdef PCRUD
3529         jsonObject* target = jsonObjectGetIndex( ctx->params, 1 );
3530 #else
3531         jsonObject* target = jsonObjectGetIndex( ctx->params, 0 );
3532 #endif
3533
3534         if (!verifyObjectClass(ctx, target)) {
3535                 *err = -1;
3536                 return jsonNULL;
3537         }
3538
3539         if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
3540                 osrfAppSessionStatus(
3541                         ctx->session,
3542                         OSRF_STATUS_BADREQUEST,
3543                         "osrfMethodException",
3544                         ctx->request,
3545                         "No active transaction -- required for UPDATE"
3546                 );
3547                 *err = -1;
3548                 return jsonNULL;
3549         }
3550
3551         // The following test is harmless but redundant.  If a class is
3552         // readonly, we don't register an update method for it.
3553         if( str_is_true( osrfHashGet( meta, "readonly" ) ) ) {
3554                 osrfAppSessionStatus(
3555                         ctx->session,
3556                         OSRF_STATUS_BADREQUEST,
3557                         "osrfMethodException",
3558                         ctx->request,
3559                         "Cannot UPDATE readonly class"
3560                 );
3561                 *err = -1;
3562                 return jsonNULL;
3563         }
3564
3565         dbhandle = writehandle;
3566
3567         char* trans_id = osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" );
3568
3569         // Set the last_xact_id
3570         int index = oilsIDL_ntop( target->classname, "last_xact_id" );
3571         if (index > -1) {
3572                 osrfLogDebug(OSRF_LOG_MARK, "Setting last_xact_id to %s on %s at position %d", trans_id, target->classname, index);
3573                 jsonObjectSetIndex(target, index, jsonNewObject(trans_id));
3574         }       
3575
3576         char* pkey = osrfHashGet(meta, "primarykey");
3577         osrfHash* fields = osrfHashGet(meta, "fields");
3578
3579         char* id = oilsFMGetString( target, pkey );
3580
3581         osrfLogDebug(
3582                 OSRF_LOG_MARK,
3583                 "%s updating %s object with %s = %s",
3584                 MODULENAME,
3585                 osrfHashGet(meta, "fieldmapper"),
3586                 pkey,
3587                 id
3588         );
3589
3590         growing_buffer* sql = buffer_init(128);
3591         buffer_fadd(sql,"UPDATE %s SET", osrfHashGet(meta, "tablename"));
3592
3593         int i = 0;
3594         int first = 1;
3595         char* field_name;
3596         osrfStringArray* field_list = osrfHashKeys( fields );
3597         while ( (field_name = osrfStringArrayGetString(field_list, i++)) ) {
3598
3599                 osrfHash* field = osrfHashGet( fields, field_name );
3600
3601                 if(!( strcmp( field_name, pkey ) )) continue;
3602                 if( str_is_true( osrfHashGet(osrfHashGet(fields,field_name), "virtual") ) )
3603                         continue;
3604
3605                 const jsonObject* field_object = oilsFMGetObject( target, field_name );
3606
3607                 char* value;
3608                 if (field_object && field_object->classname) {
3609                         value = oilsFMGetString(
3610                                 field_object,
3611                                 (char*)oilsIDLFindPath("/%s/primarykey", field_object->classname)
3612             );
3613                 } else {
3614                         value = jsonObjectToSimpleString( field_object );
3615                 }
3616
3617                 osrfLogDebug( OSRF_LOG_MARK, "Updating %s object with %s = %s", osrfHashGet(meta, "fieldmapper"), field_name, value);
3618
3619                 if (!field_object || field_object->type == JSON_NULL) {
3620                         if ( !(!( strcmp( osrfHashGet(meta, "classname"), "au" ) ) && !( strcmp( field_name, "passwd" ) )) ) { // arg at the special case!
3621                                 if (first) first = 0;
3622                                 else OSRF_BUFFER_ADD_CHAR(sql, ',');
3623                                 buffer_fadd( sql, " %s = NULL", field_name );
3624                         }
3625                         
3626                 } else if ( !strcmp(osrfHashGet(field, "primitive"), "number") ) {
3627                         if (first) first = 0;
3628                         else OSRF_BUFFER_ADD_CHAR(sql, ',');
3629
3630                         if ( !strncmp(osrfHashGet(field, "datatype"), "INT", (size_t)3) ) {
3631                                 buffer_fadd( sql, " %s = %ld", field_name, atol(value) );
3632                         } else if ( !strcmp(osrfHashGet(field, "datatype"), "NUMERIC") ) {
3633                                 buffer_fadd( sql, " %s = %f", field_name, atof(value) );
3634                         }
3635
3636                         osrfLogDebug( OSRF_LOG_MARK, "%s is of type %s", field_name, osrfHashGet(field, "datatype"));
3637
3638                 } else {
3639                         if ( dbi_conn_quote_string(dbhandle, &value) ) {
3640                                 if (first) first = 0;
3641                                 else OSRF_BUFFER_ADD_CHAR(sql, ',');
3642                                 buffer_fadd( sql, " %s = %s", field_name, value );
3643
3644                         } else {
3645                                 osrfLogError(OSRF_LOG_MARK, "%s: Error quoting string [%s]", MODULENAME, value);
3646                                 osrfAppSessionStatus(
3647                                         ctx->session,
3648                                         OSRF_STATUS_INTERNALSERVERERROR,
3649                                         "osrfMethodException",
3650                                         ctx->request,
3651                                         "Error quoting string -- please see the error log for more details"
3652                                 );
3653                                 free(value);
3654                                 free(id);
3655                                 buffer_free(sql);
3656                                 *err = -1;
3657                                 return jsonNULL;
3658                         }
3659                 }
3660
3661                 free(value);
3662                 
3663         }
3664
3665         jsonObject* obj = jsonNewObject(id);
3666
3667         if ( strcmp( osrfHashGet( osrfHashGet( osrfHashGet(meta, "fields"), pkey ), "primitive" ), "number" ) )
3668                 dbi_conn_quote_string(dbhandle, &id);
3669
3670         buffer_fadd( sql, " WHERE %s = %s;", pkey, id );
3671
3672         char* query = buffer_release(sql);
3673         osrfLogDebug(OSRF_LOG_MARK, "%s: Update SQL [%s]", MODULENAME, query);
3674
3675         dbi_result result = dbi_conn_query(dbhandle, query);
3676         free(query);
3677
3678         if (!result) {
3679                 jsonObjectFree(obj);
3680                 obj = jsonNewObject(NULL);
3681                 osrfLogError(
3682                         OSRF_LOG_MARK,
3683                         "%s ERROR updating %s object with %s = %s",
3684                         MODULENAME,
3685                         osrfHashGet(meta, "fieldmapper"),
3686                         pkey,
3687                         id
3688                 );
3689         }
3690
3691         free(id);
3692
3693         return obj;
3694 }
3695
3696 static jsonObject* doDelete(osrfMethodContext* ctx, int* err ) {
3697
3698         osrfHash* meta = osrfHashGet( (osrfHash*) ctx->method->userData, "class" );
3699
3700         if (!osrfHashGet( (osrfHash*)ctx->session->userData, "xact_id" )) {
3701                 osrfAppSessionStatus(
3702                         ctx->session,
3703                         OSRF_STATUS_BADREQUEST,
3704                         "osrfMethodException",
3705                         ctx->request,
3706                         "No active transaction -- required for DELETE"
3707                 );
3708                 *err = -1;
3709                 return jsonNULL;
3710         }
3711
3712         // The following test is harmless but redundant.  If a class is
3713         // readonly, we don't register a delete method for it.
3714         if( str_is_true( osrfHashGet( meta, "readonly" ) ) ) {
3715                 osrfAppSessionStatus(
3716                         ctx->session,
3717                         OSRF_STATUS_BADREQUEST,
3718                         "osrfMethodException",
3719                         ctx->request,
3720                         "Cannot DELETE readonly class"
3721                 );
3722                 *err = -1;
3723                 return jsonNULL;
3724         }
3725
3726         dbhandle = writehandle;
3727
3728         jsonObject* obj;
3729
3730         char* pkey = osrfHashGet(meta, "primarykey");
3731
3732         int _obj_pos = 0;
3733 #ifdef PCRUD
3734                 _obj_pos = 1;
3735 #endif
3736
3737         char* id;
3738         if (jsonObjectGetIndex(ctx->params, _obj_pos)->classname) {
3739                 if (!verifyObjectClass(ctx, jsonObjectGetIndex( ctx->params, _obj_pos ))) {
3740                         *err = -1;
3741                         return jsonNULL;
3742                 }
3743
3744                 id = oilsFMGetString( jsonObjectGetIndex(ctx->params, _obj_pos), pkey );
3745         } else {
3746 #ifdef PCRUD
3747         if (!verifyObjectPCRUD( ctx, NULL )) {
3748                         *err = -1;
3749                         return jsonNULL;
3750         }
3751 #endif
3752                 id = jsonObjectToSimpleString(jsonObjectGetIndex(ctx->params, _obj_pos));
3753         }
3754
3755         osrfLogDebug(
3756                 OSRF_LOG_MARK,
3757                 "%s deleting %s object with %s = %s",
3758                 MODULENAME,
3759                 osrfHashGet(meta, "fieldmapper"),
3760                 pkey,
3761                 id
3762         );
3763
3764         obj = jsonNewObject(id);
3765
3766         if ( strcmp( osrfHashGet( osrfHashGet( osrfHashGet(meta, "fields"), pkey ), "primitive" ), "number" ) )
3767                 dbi_conn_quote_string(writehandle, &id);
3768
3769         dbi_result result = dbi_conn_queryf(writehandle, "DELETE FROM %s WHERE %s = %s;", osrfHashGet(meta, "tablename"), pkey, id);
3770
3771         if (!result) {
3772                 jsonObjectFree(obj);
3773                 obj = jsonNewObject(NULL);
3774                 osrfLogError(
3775                         OSRF_LOG_MARK,
3776                         "%s ERROR deleting %s object with %s = %s",
3777                         MODULENAME,
3778                         osrfHashGet(meta, "fieldmapper"),
3779                         pkey,
3780                         id
3781                 );
3782         }
3783
3784         free(id);
3785
3786         return obj;
3787
3788 }
3789
3790
3791 static jsonObject* oilsMakeFieldmapperFromResult( dbi_result result, osrfHash* meta) {
3792         if(!(result && meta)) return jsonNULL;
3793
3794         jsonObject* object = jsonNewObject(NULL);
3795         jsonObjectSetClass(object, osrfHashGet(meta, "classname"));
3796
3797         osrfHash* fields = osrfHashGet(meta, "fields");
3798
3799         osrfLogInternal(OSRF_LOG_MARK, "Setting object class to %s ", object->classname);
3800
3801         osrfHash* _f;
3802         time_t _tmp_dt;
3803         char dt_string[256];
3804         struct tm gmdt;
3805
3806         int fmIndex;
3807         int columnIndex = 1;
3808         int attr;
3809         unsigned short type;
3810         const char* columnName;
3811
3812         /* cycle through the column list */
3813         while( (columnName = dbi_result_get_field_name(result, columnIndex++)) ) {
3814
3815                 osrfLogInternal(OSRF_LOG_MARK, "Looking for column named [%s]...", (char*)columnName);
3816
3817                 fmIndex = -1; // reset the position
3818                 
3819                 /* determine the field type and storage attributes */
3820                 type = dbi_result_get_field_type(result, columnName);
3821                 attr = dbi_result_get_field_attribs(result, columnName);
3822
3823                 /* fetch the fieldmapper index */
3824                 if( (_f = osrfHashGet(fields, (char*)columnName)) ) {
3825                         
3826                         if ( str_is_true( osrfHashGet(_f, "virtual") ) )
3827                                 continue;
3828                         
3829                         const char* pos = (char*)osrfHashGet(_f, "array_position");
3830                         if ( !pos ) continue;
3831
3832                         fmIndex = atoi( pos );
3833                         osrfLogInternal(OSRF_LOG_MARK, "... Found column at position [%s]...", pos);
3834                 } else {
3835                         continue;
3836                 }
3837
3838                 if (dbi_result_field_is_null(result, columnName)) {
3839                         jsonObjectSetIndex( object, fmIndex, jsonNewObject(NULL) );
3840                 } else {
3841
3842                         switch( type ) {
3843
3844                                 case DBI_TYPE_INTEGER :
3845
3846                                         if( attr & DBI_INTEGER_SIZE8 ) 
3847                                                 jsonObjectSetIndex( object, fmIndex, 
3848                                                         jsonNewNumberObject(dbi_result_get_longlong(result, columnName)));
3849                                         else 
3850                                                 jsonObjectSetIndex( object, fmIndex, 
3851                                                         jsonNewNumberObject(dbi_result_get_int(result, columnName)));
3852
3853                                         break;
3854
3855                                 case DBI_TYPE_DECIMAL :
3856                                         jsonObjectSetIndex( object, fmIndex, 
3857                                                         jsonNewNumberObject(dbi_result_get_double(result, columnName)));
3858                                         break;
3859
3860                                 case DBI_TYPE_STRING :
3861
3862
3863                                         jsonObjectSetIndex(
3864                                                 object,
3865                                                 fmIndex,
3866                                                 jsonNewObject( dbi_result_get_string(result, columnName) )
3867                                         );
3868
3869                                         break;
3870
3871                                 case DBI_TYPE_DATETIME :
3872
3873                                         memset(dt_string, '\0', sizeof(dt_string));
3874                                         memset(&gmdt, '\0', sizeof(gmdt));
3875
3876                                         _tmp_dt = dbi_result_get_datetime(result, columnName);
3877
3878
3879                                         if (!(attr & DBI_DATETIME_DATE)) {
3880                                                 gmtime_r( &_tmp_dt, &gmdt );
3881                                                 strftime(dt_string, sizeof(dt_string), "%T", &gmdt);
3882                                         } else if (!(attr & DBI_DATETIME_TIME)) {
3883                                                 localtime_r( &_tmp_dt, &gmdt );
3884                                                 strftime(dt_string, sizeof(dt_string), "%F", &gmdt);
3885                                         } else {
3886                                                 localtime_r( &_tmp_dt, &gmdt );
3887                                                 strftime(dt_string, sizeof(dt_string), "%FT%T%z", &gmdt);
3888                                         }
3889
3890                                         jsonObjectSetIndex( object, fmIndex, jsonNewObject(dt_string) );
3891
3892                                         break;
3893
3894                                 case DBI_TYPE_BINARY :
3895                                         osrfLogError( OSRF_LOG_MARK, 
3896                                                 "Can't do binary at column %s : index %d", columnName, columnIndex - 1);
3897                         }
3898                 }
3899         }
3900
3901         return object;
3902 }
3903
3904 static jsonObject* oilsMakeJSONFromResult( dbi_result result ) {
3905         if(!result) return jsonNULL;
3906
3907         jsonObject* object = jsonNewObject(NULL);
3908
3909         time_t _tmp_dt;
3910         char dt_string[256];
3911         struct tm gmdt;
3912
3913         int fmIndex;
3914         int columnIndex = 1;
3915         int attr;
3916         unsigned short type;
3917         const char* columnName;
3918
3919         /* cycle through the column list */
3920         while( (columnName = dbi_result_get_field_name(result, columnIndex++)) ) {
3921
3922                 osrfLogInternal(OSRF_LOG_MARK, "Looking for column named [%s]...", (char*)columnName);
3923
3924                 fmIndex = -1; // reset the position
3925                 
3926                 /* determine the field type and storage attributes */
3927                 type = dbi_result_get_field_type(result, columnName);
3928                 attr = dbi_result_get_field_attribs(result, columnName);
3929
3930                 if (dbi_result_field_is_null(result, columnName)) {
3931                         jsonObjectSetKey( object, columnName, jsonNewObject(NULL) );
3932                 } else {
3933
3934                         switch( type ) {
3935
3936                                 case DBI_TYPE_INTEGER :
3937
3938                                         if( attr & DBI_INTEGER_SIZE8 ) 
3939                                                 jsonObjectSetKey( object, columnName, jsonNewNumberObject(dbi_result_get_longlong(result, columnName)) );
3940                                         else 
3941                                                 jsonObjectSetKey( object, columnName, jsonNewNumberObject(dbi_result_get_int(result, columnName)) );
3942                                         break;
3943
3944                                 case DBI_TYPE_DECIMAL :
3945                                         jsonObjectSetKey( object, columnName, jsonNewNumberObject(dbi_result_get_double(result, columnName)) );
3946                                         break;
3947
3948                                 case DBI_TYPE_STRING :
3949                                         jsonObjectSetKey( object, columnName, jsonNewObject(dbi_result_get_string(result, columnName)) );
3950                                         break;
3951
3952                                 case DBI_TYPE_DATETIME :
3953
3954                                         memset(dt_string, '\0', sizeof(dt_string));
3955                                         memset(&gmdt, '\0', sizeof(gmdt));
3956
3957                                         _tmp_dt = dbi_result_get_datetime(result, columnName);
3958
3959
3960                                         if (!(attr & DBI_DATETIME_DATE)) {
3961                                                 gmtime_r( &_tmp_dt, &gmdt );
3962                                                 strftime(dt_string, sizeof(dt_string), "%T", &gmdt);
3963                                         } else if (!(attr & DBI_DATETIME_TIME)) {
3964                                                 localtime_r( &_tmp_dt, &gmdt );
3965                                                 strftime(dt_string, sizeof(dt_string), "%F", &gmdt);
3966                                         } else {
3967                                                 localtime_r( &_tmp_dt, &gmdt );
3968                                                 strftime(dt_string, sizeof(dt_string), "%FT%T%z", &gmdt);
3969                                         }
3970
3971                                         jsonObjectSetKey( object, columnName, jsonNewObject(dt_string) );
3972                                         break;
3973
3974                                 case DBI_TYPE_BINARY :
3975                                         osrfLogError( OSRF_LOG_MARK, 
3976                                                 "Can't do binary at column %s : index %d", columnName, columnIndex - 1);
3977                         }
3978                 }
3979         }
3980
3981         return object;
3982 }
3983
3984 // Interpret a string as true or false
3985 static int str_is_true( const char* str ) {
3986         if( NULL == str || strcasecmp( str, "true" ) )
3987                 return 0;
3988         else
3989                 return 1;
3990 }
3991
3992 // Interpret a jsonObject as true or false
3993 static int obj_is_true( const jsonObject* obj ) {
3994         if( !obj )
3995                 return 0;
3996         else switch( obj->type )
3997         {
3998                 case JSON_BOOL :
3999                         if( obj->value.b )
4000                                 return 1;
4001                         else
4002                                 return 0;
4003                 case JSON_STRING :
4004                         if( strcasecmp( obj->value.s, "true" ) )
4005                                 return 0;
4006                         else
4007                                 return 1;
4008                 case JSON_NUMBER :          // Support 1/0 for perl's sake
4009                         if( jsonObjectGetNumber( obj ) == 1.0 )
4010                                 return 1;
4011                         else
4012                                 return 0;
4013                 default :
4014                         return 0;
4015         }
4016 }