final class Analyzer
Public API: explicitly declared with @visibility public.

Reads PHP source and reports the SQL statements it can issue.

The whole source tree is indexed before any of it is walked, so a statement assembled from a constant, an enum or a method in another file still resolves.

Cataloguing a query written inlinedoctest
$catalog = (new \SqlCatalog\Facade\Analyzer())->analyzeSource([
        'users.php' => '<?php function all(PDO $db) { return $db->query("SELECT id FROM users"); }',
    ]);
    $catalog->entries()[0]->sql() // => 'SELECT id FROM users'
    $catalog->entries()[0]->tables // => ['users']
Reporting a value spliced into the statement textdoctest
$catalog = (new \SqlCatalog\Facade\Analyzer())->analyzeSource([
        'unsafe.php' => '<?php function find(PDO $db) { return $db->query("SELECT * FROM users WHERE id = " . $_GET["id"]); }',
    ]);
    $catalog->entries()[0]->sql() // => 'SELECT * FROM users WHERE id = {$}'
    $catalog->entries()[0]->severity()->value // => 'high'

Methods§

public function __construct(
    ExtensionRegistry|null $extensions = null,
    Registry|null $functionModels = null,
)

Parameters

$extensionsExtensionRegistry|nullThe extensions available to the run, or null for the built-in ones
$functionModelsRegistry|nullThe function interpretations, or null for the built-in models
Calls 5
public function withConfiguration(Configuration $configuration): self

An independent analyzer with the function registrations from catalog settings.

Parameters

$configurationConfiguration

Returns

self

Throws

RuntimeException When a configured function model cannot be resolved
Test cases 1
Called from 1
Calls 2
public function extensions(): ExtensionRegistry
public function analyzePaths(
    list<string> $paths,
    ?AnalysisOptions $options = null,
    string $root = '.',
    list<string> $excluded = [],
): Catalog

The statements the files under the given paths can issue.

Parameters

$pathslist<string>Files and directories to read
$options?AnalysisOptions
$rootstringThe directory reported paths are relative to
$excludedlist<string>Patterns, matched against reported paths, to leave out

Returns

Throws

SourceScanException When one of the paths cannot be read
UnknownExtensionException When the options name an extension that is not registered
Test cases 3
Calls 3
public function analyzeSource(
    array<string, string> $sources,
    ?AnalysisOptions $options = null,
): Catalog

The statements the given sources can issue.

Parameters

$sourcesarray<string, string>Source text, keyed by the path the catalog reports
$options?AnalysisOptions

Returns

Throws

UnknownExtensionException When the options name an extension that is not registered
Test cases 85
Called from 1
Calls 5
public function parse(SourceFile $file): ParsedFile|AnalysisProblem

The file parsed, or the problem that stopped it from being parsed.

Parameters

Test cases 1
Called from 1
Calls 2
public function entriesOf(list<ParsedFile> $files, AnalysisOptions $options): list<CatalogEntry>
public function sortRecords(list<CatalogEntry> $entries): list<CatalogEntry>

The entries in the order a report lists them.

Parameters

$entrieslist<CatalogEntry>

Returns

Test cases 1
Called from 1
Calls 2

Private surface 5§

Implementation details, listed for orientation only.

private Registry $functionModels
private ExtensionRegistry $extensions
private SourceParser $parser
private ProgramIndexBuilder $indexes
private EntryFactory $entries

Test cases 95§

Test cases that cover or call this symbol, from the coverage report and from the analyzed test sources.

Dedicated tests 73
Other tests reaching this symbol 22

Relations§

Instantiated in 1
Method calls 2
Type declarations 3