<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PlanetMysql.ru - информация о СУБД MySQL &#187; alter</title>
	<atom:link href="http://planetmysql.ru/category/alter/feed/" rel="self" type="application/rss+xml" />
	<link>http://planetmysql.ru</link>
	<description>Блог о самой популярной СУБД MySQL</description>
	<lastBuildDate>Fri, 10 Sep 2010 11:16:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>TaskFreak! v0.6.2 – Alter Search Plugin</title>
		<link>http://www.adamsdesk.com/be/archives/2010/07/15/taskfreak-v0-6-2-alter-search-plugin/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=taskfreak-v0-6-2-%25e2%2580%2593-alter-search-plugin</link>
		<comments>http://www.adamsdesk.com/be/archives/2010/07/15/taskfreak-v0-6-2-alter-search-plugin/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 19:27:02 +0000</pubDate>
		<dc:creator>Adam Douglas</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Search]]></category>
		<category><![CDATA[alter]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[mod]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[searching]]></category>
		<category><![CDATA[taskfreak!]]></category>

		<guid isPermaLink="false">http://www.adamsdesk.com/be/?p=587</guid>
		<description><![CDATA[Background Knowledge

The Search Plugin for TaskFreak! created by DaDaemon and xdu v0.0.1 (March 26, 2007) was designed to create a simple, quick search capability of the tasks title and description. As well it only searched through he current task view (tasks visible at the time) and tasks that are not completed. For some this was not what was desired and would rather have the Search Plugin search through all tasks weather completed or not and as well search through the comments of tasks along with the title and description. I&#8217;ll show you how this is done using Searcher, bchristie and davidlmansfield instructions posted on the TaskFreak! Forums.

Solution &#8211; Add the Ability to Search All Tasks

Edit the &#8220;index.php&#8221; located in the root of TaskFreak! as follows. We will be working in the &#8220;Load Tasks&#8221; section to just above the &#8220;Task Order&#8221; section. This solution was posted by Searcher at Re: Quick &#8216;n&#8217; Dirty Search Plugin.
Code Before

39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
$arrFilters = array&#40;&#41;;
&#160;
// --- filter: project ---
if &#40;$pProject&#41; &#123;
    // load tasks for specific project
	$sqlFilter = 'ii.projectId = \''.$pProject.'\'';
    $pLink=Tzn::concatUrl&#40;$pLink,'sProject='.$pProject&#41;;
&#125; else if &#40;!$objUser-&#62;checkLevel&#40;6&#41;&#41; &#123;
    // user can only access his own projects
    if &#40;$objUserProjectList-&#62;rMore&#40;&#41;&#41; &#123;
        $arrProject = array&#40;&#41;;
        while&#40;$objTmp = $objUserProjectList-&#62;rNext&#40;&#41;&#41; &#123;
            $arrProject&#91;&#93; = $objTmp-&#62;id;
        &#125;
        if &#40;$objUser-&#62;checkLevel&#40;13&#41;&#41; &#123;
        	$arrProject&#91;&#93; = '0';
        &#125;
        $sqlFilter = 'ii.projectId IN ('.implode&#40;',',$arrProject&#41;.')';
&#160;
        unset&#40;$arrProject&#41;;
        $objUserProjectList-&#62;rReset&#40;&#41;;
    &#125;
&#125;
&#160;
$objItemList-&#62;addWhere&#40;$sqlFilter&#41;;
&#160;
// --- filter: user ---
$pUser = intval&#40;$_REQUEST&#91;'sUser'&#93;&#41;;
if &#40;!isset&#40;$_REQUEST&#91;'sUser'&#93;&#41; &#38;&#38; @constant&#40;'FRK_DEFAULT_VIEW_OWN_TASKS'&#41;&#41; &#123;
	// default view is own tasks only
	$pUser = $objUser-&#62;id;
&#125;
&#160;
if&#40;$_REQUEST&#91;'sUser'&#93; == 'myprojects' &#38;&#38; $_SESSION&#91;'selUser'&#93;&#41;&#123;
   $objItemList-&#62;addWhere&#40;'ii.authorId='.$_SESSION&#91;'selUser'&#93;&#41;;
&#125;
elseif &#40;$pUser&#41; &#123;
	$objItemList-&#62;addWhere&#40;'ii.memberId = \''.$pUser.'\''&#41;;
    $_SESSION&#91;'selUser'&#93; = $pUser;
    $pDefaultUserId = $pUser;
&#125; else &#123;
    unset&#40;$_SESSION&#91;'selUser'&#93;&#41;;
    session_unregister&#40;'selUser'&#41;;
    $pDefaultUserId = $objUser-&#62;id;
    // by default, show own tasks
    /*
    if (!$objUser-&#62;checkLevel(1)) { // admin can see all
	    $objItemList-&#62;addWhere('(ii.memberId='.$objUser-&#62;id
    		.' OR ii.authorId='.$objUser-&#62;id.')');
    }
    */
&#125;
&#160;
$pLink=Tzn::concatUrl&#40;$pLink,'sUser='.$pUser&#41;;
&#160;
// --- private tasks --------------------------------------------------------
&#160;
$arrFilter&#91;&#93; = 'showPrivate=0';
&#160;
if &#40;$objUser-&#62;checkLevel&#40;12&#41;&#41; &#123;
	// show internal tasks
	$arrFilter&#91;&#93; = 'showPrivate=1';
&#125;
&#160;
$arrFilter&#91;&#93; = '(showPrivate=2 AND (ii.memberId='.$objUser-&#62;id
	.' OR ii.authorId='.$objUser-&#62;id.'))';
&#160;
$objItemList-&#62;addWhere&#40;'('.implode&#40;' OR ',$arrFilter&#41;.')'&#41;;
&#160;
// --- filter: context ---
&#160;
if &#40;$_REQUEST&#91;'sContext'&#93;&#41; &#123;
	$pContext = Tzn::getHttp&#40;$_REQUEST&#91;'sContext'&#93;,true&#41;;
	$objItemList-&#62;addWhere&#40;'context = \''.$pContext.'\''&#41;;
    $pLink=Tzn::concatUrl&#40;$pLink,'sContext='.$pContext&#41;;
&#125;
&#160;
$sqlFilter = '';
$pShow = &#40;$_REQUEST&#91;'show'&#93;&#41;?$_REQUEST&#91;'show'&#93;:'today';
$pLink=Tzn::concatUrl&#40;$pLink,'show='.$pShow&#41;;
&#160;
$pKeepNoDead = intval&#40;@constant&#40;'FRK_NO_DEADLINE_KEEP'&#41; -1&#41; * 86400;
&#160;
// --- Filter per date -----------------------------------------------------
&#160;
switch &#40;$pShow&#41; &#123;
	case 'all':
		break;
	case 'future':
		// show coming tasks and late tasks (undone only)
		$sqlFilter = '((deadlineDate &#62;= \''
			.strftime&#40;TZN_DATE_SQL,PRJ_DTE_NOW&#41;.'\' AND statusKey &#60; '
			.FRK_STATUS_LEVELS.')'.' OR statusKey &#60; '.FRK_STATUS_LEVELS.')';
        // show uncompleted tasks with no deadline
		$sqlFilter .= ' OR (deadlineDate = \'9999-00-00\' AND statusKey &#60; '
			.FRK_STATUS_LEVELS.')';
		break;
	case 'past':
		// show past tasks and already done
		$sqlFilter = '(deadlineDate &#60; \''
			.strftime&#40;TZN_DATE_SQL,PRJ_DTE_NOW&#41;.'\' OR statusKey = '
			.FRK_STATUS_LEVELS.')';
		break;
	case 'today':
		// show all future tasks (done + undone) and late tasks
		$pKeepNoDead = intval&#40;@constant&#40;'FRK_NO_DEADLINE_KEEP'&#41; -1&#41; * 86400;
		$sqlFilter = '(statusKey = '.FRK_STATUS_LEVELS.' AND statusDate &#62; \''
			.gmdate&#40;'Y-m-d 00:00:00',time&#40;&#41;-$pKeepNoDead&#41;.'\') ';
&#160;
		// hide far future tasks ?
		$tmpFilter = '';
		if &#40;@constant&#40;'FRK_DEFAULT_FAR_FUTURE_HIDE'&#41;&#41; &#123;
			$tmp = intval&#40;FRK_DEFAULT_FAR_FUTURE_HIDE&#41; * 86400;
			$tmpFilter .= 'deadlineDate &#60; \''
				.gmdate&#40;'Y-m-d 00:00:00',time&#40;&#41;+$tmp&#41;.'\'';
		&#125;
&#160;
		// show tasks with no deadline ?
		if &#40;@constant&#40;'FRK_NO_DEADLINE_TOO'&#41;&#41; &#123;
			// yes
			if &#40;$tmpFilter&#41; &#123;
				$sqlFilter .= 'OR ('.$tmpFilter
					.' OR deadlineDate = \'9999-00-00\')'
					. ' AND statusKey &#60; '.FRK_STATUS_LEVELS;
			&#125; else &#123;
				$sqlFilter .= ' OR statusKey &#60; '.FRK_STATUS_LEVELS;
			&#125;
		&#125; else &#123;
			// don't show uncompleted non planned tasks
			if &#40;$tmpFilter&#41; &#123;
				$sqlFilter .= ' OR ('.$tmpFilter.' AND statusKey &#60; '
    	        	.FRK_STATUS_LEVELS.')';
			&#125; else &#123;
	            $sqlFilter .= ' OR (deadlineDate &#60;&#62; \'9999-00-00\' AND statusKey &#60; '
    	        	.FRK_STATUS_LEVELS.')';
			&#125;
		&#125;
&#160;
        if &#40;@constant&#40;'FRK_DEFAULT_CURRENT_TASKS'&#41;&#41; &#123;
            $objItemList-&#62;setPagination&#40;FRK_DEFAULT_CURRENT_TASKS&#41;;
        &#125;
		break;
	default:
		break;
&#125;
&#160;
// -TODO- Add filter current project only (no completed, no cancelled)
&#160;
// echo '&#60;p&#62;&#38;&#60;/p&#62;&#60;p&#62;-&#60;/p&#62;&#60;p&#62;-&#60;/p&#62;'.$sqlFilter;
&#160;
if &#40;$sqlFilter&#41; &#123;
	$objItemList-&#62;addDateFilter&#40;$sqlFilter&#41;;
&#125;
&#160;
// search filter
	$pSearch = &#40;$_REQUEST&#91;'search'&#93;&#41;;
	if &#40;$pSearch&#41; &#123;
		$sqlFilter = '(ii.title LIKE \'%'.$pSearch.'%\' OR ii.description LIKE \'%'.$pSearch.'%\')';
		$objItemList-&#62;addWhere&#40;$sqlFilter&#41;;
	&#125;

Code After

39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
$pSearch = &#40;$_REQUEST&#91;'search'&#93;&#41;;
if &#40;$pSearch&#41; &#123;
	$sqlFilter = '(ii.title LIKE \'%'.$pSearch.'%\' OR ii.description LIKE \'%'.$pSearch.'%\')';
	$objItemList-&#62;addWhere&#40;$sqlFilter&#41;;
&#125;
else
&#123;
	$arrFilters = array&#40;&#41;;
&#160;
	// --- filter: project ---
	if &#40;$pProject&#41; &#123;
	    // load tasks for specific project
		$sqlFilter = 'ii.projectId = \''.$pProject.'\'';
	    $pLink=Tzn::concatUrl&#40;$pLink,'sProject='.$pProject&#41;;
	&#125; else if &#40;!$objUser-&#62;checkLevel&#40;6&#41;&#41; &#123;
	    // user can only access his own projects
	    if &#40;$objUserProjectList-&#62;rMore&#40;&#41;&#41; &#123;
	        $arrProject = array&#40;&#41;;
	        while&#40;$objTmp = $objUserProjectList-&#62;rNext&#40;&#41;&#41; &#123;
	            $arrProject&#91;&#93; = $objTmp-&#62;id;
	        &#125;
	        if &#40;$objUser-&#62;checkLevel&#40;13&#41;&#41; &#123;
	        	$arrProject&#91;&#93; = '0';
	        &#125;
	        $sqlFilter = 'ii.projectId IN ('.implode&#40;',',$arrProject&#41;.')';
&#160;
	        unset&#40;$arrProject&#41;;
	        $objUserProjectList-&#62;rReset&#40;&#41;;
	    &#125;
	&#125;
&#160;
	$objItemList-&#62;addWhere&#40;$sqlFilter&#41;;
&#160;
	// --- filter: user ---
	$pUser = intval&#40;$_REQUEST&#91;'sUser'&#93;&#41;;
	if &#40;!isset&#40;$_REQUEST&#91;'sUser'&#93;&#41; &#38;&#38; @constant&#40;'FRK_DEFAULT_VIEW_OWN_TASKS'&#41;&#41; &#123;
		// default view is own tasks only
		$pUser = $objUser-&#62;id;
	&#125;
&#160;
	if&#40;$_REQUEST&#91;'sUser'&#93; == 'myprojects' &#38;&#38; $_SESSION&#91;'selUser'&#93;&#41;&#123;
	   $objItemList-&#62;addWhere&#40;'ii.authorId='.$_SESSION&#91;'selUser'&#93;&#41;;
	&#125;
	elseif &#40;$pUser&#41; &#123;
		$objItemList-&#62;addWhere&#40;'ii.memberId = \''.$pUser.'\''&#41;;
	    $_SESSION&#91;'selUser'&#93; = $pUser;
	    $pDefaultUserId = $pUser;
	&#125; else &#123;
	    unset&#40;$_SESSION&#91;'selUser'&#93;&#41;;
	    session_unregister&#40;'selUser'&#41;;
	    $pDefaultUserId = $objUser-&#62;id;
	    // by default, show own tasks
	    /*
	    if (!$objUser-&#62;checkLevel(1)) { // admin can see all
		    $objItemList-&#62;addWhere('(ii.memberId='.$objUser-&#62;id
	    		.' OR ii.authorId='.$objUser-&#62;id.')');
	    }
	    */
	&#125;
&#160;
	$pLink=Tzn::concatUrl&#40;$pLink,'sUser='.$pUser&#41;;
&#160;
	// --- private tasks --------------------------------------------------------
&#160;
	$arrFilter&#91;&#93; = 'showPrivate=0';
&#160;
	if &#40;$objUser-&#62;checkLevel&#40;12&#41;&#41; &#123;
		// show internal tasks
		$arrFilter&#91;&#93; = 'showPrivate=1';
	&#125;
&#160;
	$arrFilter&#91;&#93; = '(showPrivate=2 AND (ii.memberId='.$objUser-&#62;id
		.' OR ii.authorId='.$objUser-&#62;id.'))';
&#160;
	$objItemList-&#62;addWhere&#40;'('.implode&#40;' OR ',$arrFilter&#41;.')'&#41;;
&#160;
	// --- filter: context ---
&#160;
	if &#40;$_REQUEST&#91;'sContext'&#93;&#41; &#123;
		$pContext = Tzn::getHttp&#40;$_REQUEST&#91;'sContext'&#93;,true&#41;;
		$objItemList-&#62;addWhere&#40;'context = \''.$pContext.'\''&#41;;
	    $pLink=Tzn::concatUrl&#40;$pLink,'sContext='.$pContext&#41;;
	&#125;
&#160;
	$sqlFilter = '';
	$pShow = &#40;$_REQUEST&#91;'show'&#93;&#41;?$_REQUEST&#91;'show'&#93;:'today';
	$pLink=Tzn::concatUrl&#40;$pLink,'show='.$pShow&#41;;
&#160;
	$pKeepNoDead = intval&#40;@constant&#40;'FRK_NO_DEADLINE_KEEP'&#41; -1&#41; * 86400;
&#160;
	// --- Filter per date -----------------------------------------------------
&#160;
	switch &#40;$pShow&#41; &#123;
		case 'all':
			break;
		case 'future':
			// show coming tasks and late tasks (undone only)
			$sqlFilter = '((deadlineDate &#62;= \''
				.strftime&#40;TZN_DATE_SQL,PRJ_DTE_NOW&#41;.'\' AND statusKey &#60; '
				.FRK_STATUS_LEVELS.')'.' OR statusKey &#60; '.FRK_STATUS_LEVELS.')';
	        // show uncompleted tasks with no deadline
			$sqlFilter .= ' OR (deadlineDate = \'9999-00-00\' AND statusKey &#60; '
				.FRK_STATUS_LEVELS.')';
			break;
		case 'past':
			// show past tasks and already done
			$sqlFilter = '(deadlineDate &#60; \''
				.strftime&#40;TZN_DATE_SQL,PRJ_DTE_NOW&#41;.'\' OR statusKey = '
				.FRK_STATUS_LEVELS.')';
			break;
		case 'today':
			// show all future tasks (done + undone) and late tasks
			$pKeepNoDead = intval&#40;@constant&#40;'FRK_NO_DEADLINE_KEEP'&#41; -1&#41; * 86400;
			$sqlFilter = '(statusKey = '.FRK_STATUS_LEVELS.' AND statusDate &#62; \''
				.gmdate&#40;'Y-m-d 00:00:00',time&#40;&#41;-$pKeepNoDead&#41;.'\') ';
&#160;
			// hide far future tasks ?
			$tmpFilter = '';
			if &#40;@constant&#40;'FRK_DEFAULT_FAR_FUTURE_HIDE'&#41;&#41; &#123;
				$tmp = intval&#40;FRK_DEFAULT_FAR_FUTURE_HIDE&#41; * 86400;
				$tmpFilter .= 'deadlineDate &#60; \''
					.gmdate&#40;'Y-m-d 00:00:00',time&#40;&#41;+$tmp&#41;.'\'';
			&#125;
&#160;
			// show tasks with no deadline ?
			if &#40;@constant&#40;'FRK_NO_DEADLINE_TOO'&#41;&#41; &#123;
				// yes
				if &#40;$tmpFilter&#41; &#123;
					$sqlFilter .= 'OR ('.$tmpFilter
						.' OR deadlineDate = \'9999-00-00\')'
						. ' AND statusKey &#60; '.FRK_STATUS_LEVELS;
				&#125; else &#123;
					$sqlFilter .= ' OR statusKey &#60; '.FRK_STATUS_LEVELS;
				&#125;
			&#125; else &#123;
				// don't show uncompleted non planned tasks
				if &#40;$tmpFilter&#41; &#123;
					$sqlFilter .= ' OR ('.$tmpFilter.' AND statusKey &#60; '
	    	        	.FRK_STATUS_LEVELS.')';
				&#125; else &#123;
		            $sqlFilter .= ' OR (deadlineDate &#60;&#62; \'9999-00-00\' AND statusKey &#60; '
	    	        	.FRK_STATUS_LEVELS.')';
				&#125;
			&#125;
&#160;
	        if &#40;@constant&#40;'FRK_DEFAULT_CURRENT_TASKS'&#41;&#41; &#123;
	            $objItemList-&#62;setPagination&#40;FRK_DEFAULT_CURRENT_TASKS&#41;;
	        &#125;
			break;
		default:
			break;
	&#125;
&#160;
	// -TODO- Add filter current project only (no completed, no cancelled)
&#160;
	// echo '&#60;p&#62;&#38;&#60;/p&#62;&#60;p&#62;-&#60;/p&#62;&#60;p&#62;-&#60;/p&#62;'.$sqlFilter;
&#160;
	if &#40;$sqlFilter&#41; &#123;
		$objItemList-&#62;addDateFilter&#40;$sqlFilter&#41;;
	&#125;
&#125;

Solution &#8211; Add Ability to Also Search within Task Comments

Edit the &#8220;index.php&#8221; located in the root of TaskFreak! as follows. We will be working in just below the heading section of the &#8220;Load Tasks&#8221;. This solution was posted by davidlmansfield at [PATCH] [Search Plugin] include tasks matching in comment fields.
Code Before

39
40
41
42
43
44
// search filter
$pSearch = &#40;$_REQUEST&#91;'search'&#93;&#41;;
if &#40;$pSearch&#41; &#123;
	$sqlFilter = '(ii.title LIKE \'%'.$pSearch.'%\' OR ii.description LIKE \'%'.$pSearch.'%\')';
	$objItemList-&#62;addWhere&#40;$sqlFilter&#41;;
&#125;

Code After

39
40
41
42
43
44
// search filter
$pSearch = &#40;$_REQUEST&#91;'search'&#93;&#41;;
if &#40;$pSearch&#41; &#123;
	$sqlFilter = '(ii.title LIKE \'%'.$pSearch.'%\' OR ii.description LIKE \'%'.$pSearch.'%\' OR ii.itemId in (select itemId from '.$objItemList-&#62;gTable&#40;'itemComment'&#41;.' where body LIKE \'%'.$pSearch.'%\'))';
	$objItemList-&#62;addWhere&#40;$sqlFilter&#41;;
&#125;

Solution &#8211; Stop SQL Injections

Edit the &#8220;index.php&#8221; located in the root of TaskFreak! as follows. We will be working in just below the heading section of the &#8220;Load Tasks&#8221;. This solution was posted by bchristie at Re: Quick &#8216;n&#8217; Dirty Search Plugin.
Code Before

39
40
// search filter
$pSearch = &#40;$_REQUEST&#91;'search'&#93;&#41;;

Code After

39
40
// search filter
$pSearch = isset&#40;$_REQUEST&#91;'search'&#93;&#41;?mysql_real_escape_string&#40;$_REQUEST&#91;'search'&#93;&#41;:false;]]></description>
			<content:encoded><![CDATA[<h4>Background Knowledge</h4>
<hr />
<p>The <a href="http://forum.taskfreak.com/index.php?topic=729.0">Search Plugin</a> for <a href="http://www.taskfreak.com/">TaskFreak!</a> created by DaDaemon and xdu v0.0.1 (March 26, 2007) was designed to create a simple, quick search capability of the tasks title and description. As well it only searched through he current task view (tasks visible at the time) and tasks that are not completed. For some this was not what was desired and would rather have the Search Plugin search through all tasks weather completed or not and as well search through the comments of tasks along with the title and description. I&#8217;ll show you how this is done using Searcher, bchristie and davidlmansfield instructions posted on the <a href="http://forum.taskfreak.com/">TaskFreak! Forums</a>.</p>
<p><span></span></p>
<h4>Solution &#8211; Add the Ability to Search All Tasks</h4>
<hr />
<p>Edit the &#8220;index.php&#8221; located in the root of TaskFreak! as follows. We will be working in the &#8220;Load Tasks&#8221; section to just above the &#8220;Task Order&#8221; section. This solution was posted by Searcher at <a href="http://forum.taskfreak.com/index.php?topic=729.msg3470#msg3470">Re: Quick &#8216;n&#8217; Dirty Search Plugin</a>.</p>
<h5>Code Before</h5>

<div><table><tr><td><pre>39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
</pre></td><td><pre><span>$arrFilters</span> <span>=</span> <span>array</span><span>&#40;</span><span>&#41;</span><span>;</span>
&nbsp;
<span>// --- filter: project ---</span>
<span>if</span> <span>&#40;</span><span>$pProject</span><span>&#41;</span> <span>&#123;</span>
    <span>// load tasks for specific project</span>
	<span>$sqlFilter</span> <span>=</span> <span>'ii.projectId = \''</span><span>.</span><span>$pProject</span><span>.</span><span>'\''</span><span>;</span>
    <span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'sProject='</span><span>.</span><span>$pProject</span><span>&#41;</span><span>;</span>
<span>&#125;</span> <span>else</span> <span>if</span> <span>&#40;</span><span>!</span><span>$objUser</span><span>-&gt;</span><span>checkLevel</span><span>&#40;</span><span>6</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
    <span>// user can only access his own projects</span>
    <span>if</span> <span>&#40;</span><span>$objUserProjectList</span><span>-&gt;</span><span>rMore</span><span>&#40;</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
        <span>$arrProject</span> <span>=</span> <span>array</span><span>&#40;</span><span>&#41;</span><span>;</span>
        <span>while</span><span>&#40;</span><span>$objTmp</span> <span>=</span> <span>$objUserProjectList</span><span>-&gt;</span><span>rNext</span><span>&#40;</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
            <span>$arrProject</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>$objTmp</span><span>-&gt;</span><span>id</span><span>;</span>
        <span>&#125;</span>
        <span>if</span> <span>&#40;</span><span>$objUser</span><span>-&gt;</span><span>checkLevel</span><span>&#40;</span><span>13</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
        	<span>$arrProject</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'0'</span><span>;</span>
        <span>&#125;</span>
        <span>$sqlFilter</span> <span>=</span> <span>'ii.projectId IN ('</span><span>.</span><span>implode</span><span>&#40;</span><span>','</span><span>,</span><span>$arrProject</span><span>&#41;</span><span>.</span><span>')'</span><span>;</span>
&nbsp;
        <span>unset</span><span>&#40;</span><span>$arrProject</span><span>&#41;</span><span>;</span>
        <span>$objUserProjectList</span><span>-&gt;</span><span>rReset</span><span>&#40;</span><span>&#41;</span><span>;</span>
    <span>&#125;</span>
<span>&#125;</span>
&nbsp;
<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
&nbsp;
<span>// --- filter: user ---</span>
<span>$pUser</span> <span>=</span> <span>intval</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sUser'</span><span>&#93;</span><span>&#41;</span><span>;</span>
<span>if</span> <span>&#40;</span><span>!</span><span>isset</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sUser'</span><span>&#93;</span><span>&#41;</span> <span>&amp;&amp;</span> <span>@</span><span>constant</span><span>&#40;</span><span>'FRK_DEFAULT_VIEW_OWN_TASKS'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
	<span>// default view is own tasks only</span>
	<span>$pUser</span> <span>=</span> <span>$objUser</span><span>-&gt;</span><span>id</span><span>;</span>
<span>&#125;</span>
&nbsp;
<span>if</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sUser'</span><span>&#93;</span> <span>==</span> <span>'myprojects'</span> <span>&amp;&amp;</span> <span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span><span>&#41;</span><span>&#123;</span>
   <span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'ii.authorId='</span><span>.</span><span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span><span>&#41;</span><span>;</span>
<span>&#125;</span>
<span>elseif</span> <span>&#40;</span><span>$pUser</span><span>&#41;</span> <span>&#123;</span>
	<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'ii.memberId = \''</span><span>.</span><span>$pUser</span><span>.</span><span>'\''</span><span>&#41;</span><span>;</span>
    <span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span> <span>=</span> <span>$pUser</span><span>;</span>
    <span>$pDefaultUserId</span> <span>=</span> <span>$pUser</span><span>;</span>
<span>&#125;</span> <span>else</span> <span>&#123;</span>
    <span>unset</span><span>&#40;</span><span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span><span>&#41;</span><span>;</span>
    <span>session_unregister</span><span>&#40;</span><span>'selUser'</span><span>&#41;</span><span>;</span>
    <span>$pDefaultUserId</span> <span>=</span> <span>$objUser</span><span>-&gt;</span><span>id</span><span>;</span>
    <span>// by default, show own tasks</span>
    <span>/*
    if (!$objUser-&gt;checkLevel(1)) { // admin can see all
	    $objItemList-&gt;addWhere('(ii.memberId='.$objUser-&gt;id
    		.' OR ii.authorId='.$objUser-&gt;id.')');
    }
    */</span>
<span>&#125;</span>
&nbsp;
<span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'sUser='</span><span>.</span><span>$pUser</span><span>&#41;</span><span>;</span>
&nbsp;
<span>// --- private tasks --------------------------------------------------------</span>
&nbsp;
<span>$arrFilter</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'showPrivate=0'</span><span>;</span>
&nbsp;
<span>if</span> <span>&#40;</span><span>$objUser</span><span>-&gt;</span><span>checkLevel</span><span>&#40;</span><span>12</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
	<span>// show internal tasks</span>
	<span>$arrFilter</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'showPrivate=1'</span><span>;</span>
<span>&#125;</span>
&nbsp;
<span>$arrFilter</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'(showPrivate=2 AND (ii.memberId='</span><span>.</span><span>$objUser</span><span>-&gt;</span><span>id</span>
	<span>.</span><span>' OR ii.authorId='</span><span>.</span><span>$objUser</span><span>-&gt;</span><span>id</span><span>.</span><span>'))'</span><span>;</span>
&nbsp;
<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'('</span><span>.</span><span>implode</span><span>&#40;</span><span>' OR '</span><span>,</span><span>$arrFilter</span><span>&#41;</span><span>.</span><span>')'</span><span>&#41;</span><span>;</span>
&nbsp;
<span>// --- filter: context ---</span>
&nbsp;
<span>if</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sContext'</span><span>&#93;</span><span>&#41;</span> <span>&#123;</span>
	<span>$pContext</span> <span>=</span> Tzn<span>::</span><span>getHttp</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sContext'</span><span>&#93;</span><span>,</span><span>true</span><span>&#41;</span><span>;</span>
	<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'context = \''</span><span>.</span><span>$pContext</span><span>.</span><span>'\''</span><span>&#41;</span><span>;</span>
    <span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'sContext='</span><span>.</span><span>$pContext</span><span>&#41;</span><span>;</span>
<span>&#125;</span>
&nbsp;
<span>$sqlFilter</span> <span>=</span> <span>''</span><span>;</span>
<span>$pShow</span> <span>=</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'show'</span><span>&#93;</span><span>&#41;</span>?<span>$_REQUEST</span><span>&#91;</span><span>'show'</span><span>&#93;</span><span>:</span><span>'today'</span><span>;</span>
<span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'show='</span><span>.</span><span>$pShow</span><span>&#41;</span><span>;</span>
&nbsp;
<span>$pKeepNoDead</span> <span>=</span> <span>intval</span><span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_NO_DEADLINE_KEEP'</span><span>&#41;</span> <span>-</span><span>1</span><span>&#41;</span> <span>*</span> <span>86400</span><span>;</span>
&nbsp;
<span>// --- Filter per date -----------------------------------------------------</span>
&nbsp;
<span>switch</span> <span>&#40;</span><span>$pShow</span><span>&#41;</span> <span>&#123;</span>
	<span>case</span> <span>'all'</span><span>:</span>
		<span>break</span><span>;</span>
	<span>case</span> <span>'future'</span><span>:</span>
		<span>// show coming tasks and late tasks (undone only)</span>
		<span>$sqlFilter</span> <span>=</span> <span>'((deadlineDate &gt;= \''</span>
			<span>.</span><span>strftime</span><span>&#40;</span>TZN_DATE_SQL<span>,</span>PRJ_DTE_NOW<span>&#41;</span><span>.</span><span>'\' AND statusKey &lt; '</span>
			<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>.</span><span>' OR statusKey &lt; '</span><span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
        <span>// show uncompleted tasks with no deadline</span>
		<span>$sqlFilter</span> <span>.=</span> <span>' OR (deadlineDate = \'9999-00-00\' AND statusKey &lt; '</span>
			<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
		<span>break</span><span>;</span>
	<span>case</span> <span>'past'</span><span>:</span>
		<span>// show past tasks and already done</span>
		<span>$sqlFilter</span> <span>=</span> <span>'(deadlineDate &lt; \''</span>
			<span>.</span><span>strftime</span><span>&#40;</span>TZN_DATE_SQL<span>,</span>PRJ_DTE_NOW<span>&#41;</span><span>.</span><span>'\' OR statusKey = '</span>
			<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
		<span>break</span><span>;</span>
	<span>case</span> <span>'today'</span><span>:</span>
		<span>// show all future tasks (done + undone) and late tasks</span>
		<span>$pKeepNoDead</span> <span>=</span> <span>intval</span><span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_NO_DEADLINE_KEEP'</span><span>&#41;</span> <span>-</span><span>1</span><span>&#41;</span> <span>*</span> <span>86400</span><span>;</span>
		<span>$sqlFilter</span> <span>=</span> <span>'(statusKey = '</span><span>.</span>FRK_STATUS_LEVELS<span>.</span><span>' AND statusDate &gt; \''</span>
			<span>.</span><span>gmdate</span><span>&#40;</span><span>'Y-m-d 00:00:00'</span><span>,</span><span>time</span><span>&#40;</span><span>&#41;</span><span>-</span><span>$pKeepNoDead</span><span>&#41;</span><span>.</span><span>'\') '</span><span>;</span>
&nbsp;
		<span>// hide far future tasks ?</span>
		<span>$tmpFilter</span> <span>=</span> <span>''</span><span>;</span>
		<span>if</span> <span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_DEFAULT_FAR_FUTURE_HIDE'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
			<span>$tmp</span> <span>=</span> <span>intval</span><span>&#40;</span>FRK_DEFAULT_FAR_FUTURE_HIDE<span>&#41;</span> <span>*</span> <span>86400</span><span>;</span>
			<span>$tmpFilter</span> <span>.=</span> <span>'deadlineDate &lt; \''</span>
				<span>.</span><span>gmdate</span><span>&#40;</span><span>'Y-m-d 00:00:00'</span><span>,</span><span>time</span><span>&#40;</span><span>&#41;</span><span>+</span><span>$tmp</span><span>&#41;</span><span>.</span><span>'\''</span><span>;</span>
		<span>&#125;</span>
&nbsp;
		<span>// show tasks with no deadline ?</span>
		<span>if</span> <span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_NO_DEADLINE_TOO'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
			<span>// yes</span>
			<span>if</span> <span>&#40;</span><span>$tmpFilter</span><span>&#41;</span> <span>&#123;</span>
				<span>$sqlFilter</span> <span>.=</span> <span>'OR ('</span><span>.</span><span>$tmpFilter</span>
					<span>.</span><span>' OR deadlineDate = \'9999-00-00\')'</span>
					<span>.</span> <span>' AND statusKey &lt; '</span><span>.</span>FRK_STATUS_LEVELS<span>;</span>
			<span>&#125;</span> <span>else</span> <span>&#123;</span>
				<span>$sqlFilter</span> <span>.=</span> <span>' OR statusKey &lt; '</span><span>.</span>FRK_STATUS_LEVELS<span>;</span>
			<span>&#125;</span>
		<span>&#125;</span> <span>else</span> <span>&#123;</span>
			<span>// don't show uncompleted non planned tasks</span>
			<span>if</span> <span>&#40;</span><span>$tmpFilter</span><span>&#41;</span> <span>&#123;</span>
				<span>$sqlFilter</span> <span>.=</span> <span>' OR ('</span><span>.</span><span>$tmpFilter</span><span>.</span><span>' AND statusKey &lt; '</span>
    	        	<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
			<span>&#125;</span> <span>else</span> <span>&#123;</span>
	            <span>$sqlFilter</span> <span>.=</span> <span>' OR (deadlineDate &lt;&gt; \'9999-00-00\' AND statusKey &lt; '</span>
    	        	<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
			<span>&#125;</span>
		<span>&#125;</span>
&nbsp;
        <span>if</span> <span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_DEFAULT_CURRENT_TASKS'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
            <span>$objItemList</span><span>-&gt;</span><span>setPagination</span><span>&#40;</span>FRK_DEFAULT_CURRENT_TASKS<span>&#41;</span><span>;</span>
        <span>&#125;</span>
		<span>break</span><span>;</span>
	<span>default</span><span>:</span>
		<span>break</span><span>;</span>
<span>&#125;</span>
&nbsp;
<span>// -TODO- Add filter current project only (no completed, no cancelled)</span>
&nbsp;
<span>// echo '&lt;p&gt;&amp;&lt;/p&gt;&lt;p&gt;-&lt;/p&gt;&lt;p&gt;-&lt;/p&gt;'.$sqlFilter;</span>
&nbsp;
<span>if</span> <span>&#40;</span><span>$sqlFilter</span><span>&#41;</span> <span>&#123;</span>
	<span>$objItemList</span><span>-&gt;</span><span>addDateFilter</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
<span>&#125;</span>
&nbsp;
<span>// search filter</span>
	<span>$pSearch</span> <span>=</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'search'</span><span>&#93;</span><span>&#41;</span><span>;</span>
	<span>if</span> <span>&#40;</span><span>$pSearch</span><span>&#41;</span> <span>&#123;</span>
		<span>$sqlFilter</span> <span>=</span> <span>'(ii.title LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\' OR ii.description LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\')'</span><span>;</span>
		<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
	<span>&#125;</span></pre></td></tr></table></div>

<h5>Code After</h5>

<div><table><tr><td><pre>39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
</pre></td><td><pre><span>$pSearch</span> <span>=</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'search'</span><span>&#93;</span><span>&#41;</span><span>;</span>
<span>if</span> <span>&#40;</span><span>$pSearch</span><span>&#41;</span> <span>&#123;</span>
	<span>$sqlFilter</span> <span>=</span> <span>'(ii.title LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\' OR ii.description LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\')'</span><span>;</span>
	<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
<span>&#125;</span>
<span>else</span>
<span>&#123;</span>
	<span>$arrFilters</span> <span>=</span> <span>array</span><span>&#40;</span><span>&#41;</span><span>;</span>
&nbsp;
	<span>// --- filter: project ---</span>
	<span>if</span> <span>&#40;</span><span>$pProject</span><span>&#41;</span> <span>&#123;</span>
	    <span>// load tasks for specific project</span>
		<span>$sqlFilter</span> <span>=</span> <span>'ii.projectId = \''</span><span>.</span><span>$pProject</span><span>.</span><span>'\''</span><span>;</span>
	    <span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'sProject='</span><span>.</span><span>$pProject</span><span>&#41;</span><span>;</span>
	<span>&#125;</span> <span>else</span> <span>if</span> <span>&#40;</span><span>!</span><span>$objUser</span><span>-&gt;</span><span>checkLevel</span><span>&#40;</span><span>6</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
	    <span>// user can only access his own projects</span>
	    <span>if</span> <span>&#40;</span><span>$objUserProjectList</span><span>-&gt;</span><span>rMore</span><span>&#40;</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
	        <span>$arrProject</span> <span>=</span> <span>array</span><span>&#40;</span><span>&#41;</span><span>;</span>
	        <span>while</span><span>&#40;</span><span>$objTmp</span> <span>=</span> <span>$objUserProjectList</span><span>-&gt;</span><span>rNext</span><span>&#40;</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
	            <span>$arrProject</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>$objTmp</span><span>-&gt;</span><span>id</span><span>;</span>
	        <span>&#125;</span>
	        <span>if</span> <span>&#40;</span><span>$objUser</span><span>-&gt;</span><span>checkLevel</span><span>&#40;</span><span>13</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
	        	<span>$arrProject</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'0'</span><span>;</span>
	        <span>&#125;</span>
	        <span>$sqlFilter</span> <span>=</span> <span>'ii.projectId IN ('</span><span>.</span><span>implode</span><span>&#40;</span><span>','</span><span>,</span><span>$arrProject</span><span>&#41;</span><span>.</span><span>')'</span><span>;</span>
&nbsp;
	        <span>unset</span><span>&#40;</span><span>$arrProject</span><span>&#41;</span><span>;</span>
	        <span>$objUserProjectList</span><span>-&gt;</span><span>rReset</span><span>&#40;</span><span>&#41;</span><span>;</span>
	    <span>&#125;</span>
	<span>&#125;</span>
&nbsp;
	<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
&nbsp;
	<span>// --- filter: user ---</span>
	<span>$pUser</span> <span>=</span> <span>intval</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sUser'</span><span>&#93;</span><span>&#41;</span><span>;</span>
	<span>if</span> <span>&#40;</span><span>!</span><span>isset</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sUser'</span><span>&#93;</span><span>&#41;</span> <span>&amp;&amp;</span> <span>@</span><span>constant</span><span>&#40;</span><span>'FRK_DEFAULT_VIEW_OWN_TASKS'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
		<span>// default view is own tasks only</span>
		<span>$pUser</span> <span>=</span> <span>$objUser</span><span>-&gt;</span><span>id</span><span>;</span>
	<span>&#125;</span>
&nbsp;
	<span>if</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sUser'</span><span>&#93;</span> <span>==</span> <span>'myprojects'</span> <span>&amp;&amp;</span> <span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span><span>&#41;</span><span>&#123;</span>
	   <span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'ii.authorId='</span><span>.</span><span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span><span>&#41;</span><span>;</span>
	<span>&#125;</span>
	<span>elseif</span> <span>&#40;</span><span>$pUser</span><span>&#41;</span> <span>&#123;</span>
		<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'ii.memberId = \''</span><span>.</span><span>$pUser</span><span>.</span><span>'\''</span><span>&#41;</span><span>;</span>
	    <span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span> <span>=</span> <span>$pUser</span><span>;</span>
	    <span>$pDefaultUserId</span> <span>=</span> <span>$pUser</span><span>;</span>
	<span>&#125;</span> <span>else</span> <span>&#123;</span>
	    <span>unset</span><span>&#40;</span><span>$_SESSION</span><span>&#91;</span><span>'selUser'</span><span>&#93;</span><span>&#41;</span><span>;</span>
	    <span>session_unregister</span><span>&#40;</span><span>'selUser'</span><span>&#41;</span><span>;</span>
	    <span>$pDefaultUserId</span> <span>=</span> <span>$objUser</span><span>-&gt;</span><span>id</span><span>;</span>
	    <span>// by default, show own tasks</span>
	    <span>/*
	    if (!$objUser-&gt;checkLevel(1)) { // admin can see all
		    $objItemList-&gt;addWhere('(ii.memberId='.$objUser-&gt;id
	    		.' OR ii.authorId='.$objUser-&gt;id.')');
	    }
	    */</span>
	<span>&#125;</span>
&nbsp;
	<span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'sUser='</span><span>.</span><span>$pUser</span><span>&#41;</span><span>;</span>
&nbsp;
	<span>// --- private tasks --------------------------------------------------------</span>
&nbsp;
	<span>$arrFilter</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'showPrivate=0'</span><span>;</span>
&nbsp;
	<span>if</span> <span>&#40;</span><span>$objUser</span><span>-&gt;</span><span>checkLevel</span><span>&#40;</span><span>12</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
		<span>// show internal tasks</span>
		<span>$arrFilter</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'showPrivate=1'</span><span>;</span>
	<span>&#125;</span>
&nbsp;
	<span>$arrFilter</span><span>&#91;</span><span>&#93;</span> <span>=</span> <span>'(showPrivate=2 AND (ii.memberId='</span><span>.</span><span>$objUser</span><span>-&gt;</span><span>id</span>
		<span>.</span><span>' OR ii.authorId='</span><span>.</span><span>$objUser</span><span>-&gt;</span><span>id</span><span>.</span><span>'))'</span><span>;</span>
&nbsp;
	<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'('</span><span>.</span><span>implode</span><span>&#40;</span><span>' OR '</span><span>,</span><span>$arrFilter</span><span>&#41;</span><span>.</span><span>')'</span><span>&#41;</span><span>;</span>
&nbsp;
	<span>// --- filter: context ---</span>
&nbsp;
	<span>if</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sContext'</span><span>&#93;</span><span>&#41;</span> <span>&#123;</span>
		<span>$pContext</span> <span>=</span> Tzn<span>::</span><span>getHttp</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'sContext'</span><span>&#93;</span><span>,</span><span>true</span><span>&#41;</span><span>;</span>
		<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>'context = \''</span><span>.</span><span>$pContext</span><span>.</span><span>'\''</span><span>&#41;</span><span>;</span>
	    <span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'sContext='</span><span>.</span><span>$pContext</span><span>&#41;</span><span>;</span>
	<span>&#125;</span>
&nbsp;
	<span>$sqlFilter</span> <span>=</span> <span>''</span><span>;</span>
	<span>$pShow</span> <span>=</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'show'</span><span>&#93;</span><span>&#41;</span>?<span>$_REQUEST</span><span>&#91;</span><span>'show'</span><span>&#93;</span><span>:</span><span>'today'</span><span>;</span>
	<span>$pLink</span><span>=</span>Tzn<span>::</span><span>concatUrl</span><span>&#40;</span><span>$pLink</span><span>,</span><span>'show='</span><span>.</span><span>$pShow</span><span>&#41;</span><span>;</span>
&nbsp;
	<span>$pKeepNoDead</span> <span>=</span> <span>intval</span><span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_NO_DEADLINE_KEEP'</span><span>&#41;</span> <span>-</span><span>1</span><span>&#41;</span> <span>*</span> <span>86400</span><span>;</span>
&nbsp;
	<span>// --- Filter per date -----------------------------------------------------</span>
&nbsp;
	<span>switch</span> <span>&#40;</span><span>$pShow</span><span>&#41;</span> <span>&#123;</span>
		<span>case</span> <span>'all'</span><span>:</span>
			<span>break</span><span>;</span>
		<span>case</span> <span>'future'</span><span>:</span>
			<span>// show coming tasks and late tasks (undone only)</span>
			<span>$sqlFilter</span> <span>=</span> <span>'((deadlineDate &gt;= \''</span>
				<span>.</span><span>strftime</span><span>&#40;</span>TZN_DATE_SQL<span>,</span>PRJ_DTE_NOW<span>&#41;</span><span>.</span><span>'\' AND statusKey &lt; '</span>
				<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>.</span><span>' OR statusKey &lt; '</span><span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
	        <span>// show uncompleted tasks with no deadline</span>
			<span>$sqlFilter</span> <span>.=</span> <span>' OR (deadlineDate = \'9999-00-00\' AND statusKey &lt; '</span>
				<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
			<span>break</span><span>;</span>
		<span>case</span> <span>'past'</span><span>:</span>
			<span>// show past tasks and already done</span>
			<span>$sqlFilter</span> <span>=</span> <span>'(deadlineDate &lt; \''</span>
				<span>.</span><span>strftime</span><span>&#40;</span>TZN_DATE_SQL<span>,</span>PRJ_DTE_NOW<span>&#41;</span><span>.</span><span>'\' OR statusKey = '</span>
				<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
			<span>break</span><span>;</span>
		<span>case</span> <span>'today'</span><span>:</span>
			<span>// show all future tasks (done + undone) and late tasks</span>
			<span>$pKeepNoDead</span> <span>=</span> <span>intval</span><span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_NO_DEADLINE_KEEP'</span><span>&#41;</span> <span>-</span><span>1</span><span>&#41;</span> <span>*</span> <span>86400</span><span>;</span>
			<span>$sqlFilter</span> <span>=</span> <span>'(statusKey = '</span><span>.</span>FRK_STATUS_LEVELS<span>.</span><span>' AND statusDate &gt; \''</span>
				<span>.</span><span>gmdate</span><span>&#40;</span><span>'Y-m-d 00:00:00'</span><span>,</span><span>time</span><span>&#40;</span><span>&#41;</span><span>-</span><span>$pKeepNoDead</span><span>&#41;</span><span>.</span><span>'\') '</span><span>;</span>
&nbsp;
			<span>// hide far future tasks ?</span>
			<span>$tmpFilter</span> <span>=</span> <span>''</span><span>;</span>
			<span>if</span> <span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_DEFAULT_FAR_FUTURE_HIDE'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
				<span>$tmp</span> <span>=</span> <span>intval</span><span>&#40;</span>FRK_DEFAULT_FAR_FUTURE_HIDE<span>&#41;</span> <span>*</span> <span>86400</span><span>;</span>
				<span>$tmpFilter</span> <span>.=</span> <span>'deadlineDate &lt; \''</span>
					<span>.</span><span>gmdate</span><span>&#40;</span><span>'Y-m-d 00:00:00'</span><span>,</span><span>time</span><span>&#40;</span><span>&#41;</span><span>+</span><span>$tmp</span><span>&#41;</span><span>.</span><span>'\''</span><span>;</span>
			<span>&#125;</span>
&nbsp;
			<span>// show tasks with no deadline ?</span>
			<span>if</span> <span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_NO_DEADLINE_TOO'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
				<span>// yes</span>
				<span>if</span> <span>&#40;</span><span>$tmpFilter</span><span>&#41;</span> <span>&#123;</span>
					<span>$sqlFilter</span> <span>.=</span> <span>'OR ('</span><span>.</span><span>$tmpFilter</span>
						<span>.</span><span>' OR deadlineDate = \'9999-00-00\')'</span>
						<span>.</span> <span>' AND statusKey &lt; '</span><span>.</span>FRK_STATUS_LEVELS<span>;</span>
				<span>&#125;</span> <span>else</span> <span>&#123;</span>
					<span>$sqlFilter</span> <span>.=</span> <span>' OR statusKey &lt; '</span><span>.</span>FRK_STATUS_LEVELS<span>;</span>
				<span>&#125;</span>
			<span>&#125;</span> <span>else</span> <span>&#123;</span>
				<span>// don't show uncompleted non planned tasks</span>
				<span>if</span> <span>&#40;</span><span>$tmpFilter</span><span>&#41;</span> <span>&#123;</span>
					<span>$sqlFilter</span> <span>.=</span> <span>' OR ('</span><span>.</span><span>$tmpFilter</span><span>.</span><span>' AND statusKey &lt; '</span>
	    	        	<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
				<span>&#125;</span> <span>else</span> <span>&#123;</span>
		            <span>$sqlFilter</span> <span>.=</span> <span>' OR (deadlineDate &lt;&gt; \'9999-00-00\' AND statusKey &lt; '</span>
	    	        	<span>.</span>FRK_STATUS_LEVELS<span>.</span><span>')'</span><span>;</span>
				<span>&#125;</span>
			<span>&#125;</span>
&nbsp;
	        <span>if</span> <span>&#40;</span><span>@</span><span>constant</span><span>&#40;</span><span>'FRK_DEFAULT_CURRENT_TASKS'</span><span>&#41;</span><span>&#41;</span> <span>&#123;</span>
	            <span>$objItemList</span><span>-&gt;</span><span>setPagination</span><span>&#40;</span>FRK_DEFAULT_CURRENT_TASKS<span>&#41;</span><span>;</span>
	        <span>&#125;</span>
			<span>break</span><span>;</span>
		<span>default</span><span>:</span>
			<span>break</span><span>;</span>
	<span>&#125;</span>
&nbsp;
	<span>// -TODO- Add filter current project only (no completed, no cancelled)</span>
&nbsp;
	<span>// echo '&lt;p&gt;&amp;&lt;/p&gt;&lt;p&gt;-&lt;/p&gt;&lt;p&gt;-&lt;/p&gt;'.$sqlFilter;</span>
&nbsp;
	<span>if</span> <span>&#40;</span><span>$sqlFilter</span><span>&#41;</span> <span>&#123;</span>
		<span>$objItemList</span><span>-&gt;</span><span>addDateFilter</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
	<span>&#125;</span>
<span>&#125;</span></pre></td></tr></table></div>

<h4>Solution &#8211; Add Ability to Also Search within Task Comments</h4>
<hr />
<p>Edit the &#8220;index.php&#8221; located in the root of TaskFreak! as follows. We will be working in just below the heading section of the &#8220;Load Tasks&#8221;. This solution was posted by davidlmansfield at <a href="http://forum.taskfreak.com/index.php?topic=911.0">[PATCH] [Search Plugin] include tasks matching in comment fields</a>.</p>
<h5>Code Before</h5>

<div><table><tr><td><pre>39
40
41
42
43
44
</pre></td><td><pre><span>// search filter</span>
<span>$pSearch</span> <span>=</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'search'</span><span>&#93;</span><span>&#41;</span><span>;</span>
<span>if</span> <span>&#40;</span><span>$pSearch</span><span>&#41;</span> <span>&#123;</span>
	<span>$sqlFilter</span> <span>=</span> <span>'(ii.title LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\' OR ii.description LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\')'</span><span>;</span>
	<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
<span>&#125;</span></pre></td></tr></table></div>

<h5>Code After</h5>

<div><table><tr><td><pre>39
40
41
42
43
44
</pre></td><td><pre><span>// search filter</span>
<span>$pSearch</span> <span>=</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'search'</span><span>&#93;</span><span>&#41;</span><span>;</span>
<span>if</span> <span>&#40;</span><span>$pSearch</span><span>&#41;</span> <span>&#123;</span>
	<span>$sqlFilter</span> <span>=</span> <span>'(ii.title LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\' OR ii.description LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\' OR ii.itemId in (select itemId from '</span><span>.</span><span>$objItemList</span><span>-&gt;</span><span>gTable</span><span>&#40;</span><span>'itemComment'</span><span>&#41;</span><span>.</span><span>' where body LIKE \'%'</span><span>.</span><span>$pSearch</span><span>.</span><span>'%\'))'</span><span>;</span>
	<span>$objItemList</span><span>-&gt;</span><span>addWhere</span><span>&#40;</span><span>$sqlFilter</span><span>&#41;</span><span>;</span>
<span>&#125;</span></pre></td></tr></table></div>

<h4>Solution &#8211; Stop SQL Injections</h4>
<hr />
<p>Edit the &#8220;index.php&#8221; located in the root of TaskFreak! as follows. We will be working in just below the heading section of the &#8220;Load Tasks&#8221;. This solution was posted by bchristie at <a href="http://forum.taskfreak.com/index.php?topic=729.msg8546#msg8546">Re: Quick &#8216;n&#8217; Dirty Search Plugin</a>.</p>
<h5>Code Before</h5>

<div><table><tr><td><pre>39
40
</pre></td><td><pre><span>// search filter</span>
<span>$pSearch</span> <span>=</span> <span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'search'</span><span>&#93;</span><span>&#41;</span><span>;</span></pre></td></tr></table></div>

<h5>Code After</h5>

<div><table><tr><td><pre>39
40
</pre></td><td><pre><span>// search filter</span>
<span>$pSearch</span> <span>=</span> <span>isset</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'search'</span><span>&#93;</span><span>&#41;</span>?<span>mysql_real_escape_string</span><span>&#40;</span><span>$_REQUEST</span><span>&#91;</span><span>'search'</span><span>&#93;</span><span>&#41;</span><span>:</span><span>false</span><span>;</span></pre></td></tr></table></div><br/>PlanetMySQL Voting:
	 <a href="http://planet.mysql.com/entry/vote/?entry_id=25314&vote=1&apivote=1">Vote UP</a> /
	 <a href="http://planet.mysql.com/entry/vote/?entry_id=25314&vote=-1&apivote=1">Vote DOWN</a>]]></content:encoded>
			<wfw:commentRss>http://www.adamsdesk.com/be/archives/2010/07/15/taskfreak-v0-6-2-alter-search-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When the ALTER TABLE privilege is not enough to run ALTER TABLE</title>
		<link>http://www.pythian.com/news/9007/when-the-alter-table-privilege-is-not-enough-to-run-alter-table/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=when-the-alter-table-privilege-is-not-enough-to-run-alter-table</link>
		<comments>http://www.pythian.com/news/9007/when-the-alter-table-privilege-is-not-enough-to-run-alter-table/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 15:06:44 +0000</pubDate>
		<dc:creator>Singer Wang</dc:creator>
				<category><![CDATA[ALTER TABLE]]></category>
		<category><![CDATA[Pythian]]></category>
		<category><![CDATA[Technical Blog]]></category>
		<category><![CDATA[alter]]></category>
		<category><![CDATA[documentation]]></category>
		<category><![CDATA[grant]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[privilege]]></category>
		<category><![CDATA[rename]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.pythian.com/news/?p=9007</guid>
		<description><![CDATA[I recently granted ALTER access in MySQL so a user could run the ALTER TABLE command . However after I granted the necessary privileges, the user was still not able to perform the tasks needed. Reproducing the issue using a test instance, I granted a test user the required privileges and MySQL reported no errors or warnings when the ALTER TABLE was run:


Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 15
Server version: 5.1.41-log MySQL Community Server (GPL)

Type 'help;' or '\h' for help. Type '\c' to clear the buffer.

mysql&#62; grant alter,create,insert on *.* to 'test'@localhost;
Query OK, 0 rows affected (0.00 sec)

mysql&#62; show warnings;
Empty set (0.00 sec)

mysql&#62; show errors;
Empty set (0.00 sec)

mysql&#62;

The reason I granted the addition CREATE and INSERT privileges is that according to the MySQL documentation (http://dev.mysql.com/doc/refman/5.1/en/privileges-provided.html), they are required by the ALTER privilege:
The ALTER privilege enables use of ALTER TABLE to change the structure of or rename tables. (ALTER TABLE also requires the INSERT and CREATE privileges.)
The user was attempting to rename a table with the ALTER TABLE [NAME] RENAME [NAME2] command and seeing the following error:

mysql&#62; alter table test1 rename test2;
ERROR 1142 (42000): DROP command denied to user 'test'@'localhost' for table 'test1'

mysql&#62; show grants;
+----------------------------------------------------------+
&#124; Grants for test@localhost                                &#124;
+----------------------------------------------------------+
&#124; GRANT INSERT, CREATE, ALTER ON *.* TO 'test'@'localhost' &#124;
+----------------------------------------------------------+
1 row in set (0.00 sec)

mysql&#62; show tables;
+----------------+
&#124; Tables_in_test &#124;
+----------------+
&#124; test1          &#124;
+----------------+
1 row in set (0.00 sec)

Of course I immediately realized what the issue was. In MySQL,  ALTER TABLE [NAME] RENAME [NEW_NAME] is done as a DROP (which requires the DROP privilege and CREATE TABLE (which requires the CREATE privilege).  So I granted the user the DROP privilege.  This time  the user was able to successful rename the table as shown below:

mysql&#62; show tables;
+----------------+
&#124; Tables_in_test &#124;
+----------------+
&#124; test1          &#124;
+----------------+
1 row in set (0.00 sec)

mysql&#62; alter table test1 rename test2;
Query OK, 0 rows affected (0.00 sec)

mysql&#62; show grants;
+----------------------------------------------------------------+
&#124; Grants for test@localhost                                      &#124;
+----------------------------------------------------------------+
&#124; GRANT INSERT, CREATE, DROP, ALTER ON *.* TO 'test'@'localhost' &#124;
+----------------------------------------------------------------+
1 row in set (0.00 sec)

mysql&#62; show tables;
+----------------+
&#124; Tables_in_test &#124;
+----------------+
&#124; test2          &#124;
+----------------+
1 row in set (0.00 sec)

The MySQL documentation on the ALTER privilege states that it only need CREATE and INSERT but makes no mention of the requirement for DROP privilege. The RENAME TABLE documentation at http://dev.mysql.com/doc/refman/5.1/en/rename-table.html does mention:
When you execute RENAME, you cannot have any locked tables or active transactions. You must also have the ALTER and DROP privileges on the original table, and the CREATE and INSERT privileges on the new table.
However, that should be explicit in the ALTER TABLE documentation, because if you use ALTER TABLE...RENAME you will not necessarily read the documentation for the RENAME TABLE syntax.
To make the documentation better for everyone, I have filed a MySQL Bug Report on this documentation  &#8211; Bug 51593.]]></description>
			<content:encoded><![CDATA[<p>I recently granted <code>ALTER</code> access in MySQL so a user could run the <code>ALTER TABLE</code> command . However after I granted the necessary privileges, the user was still not able to perform the tasks needed. Reproducing the issue using a test instance, I granted a test user the required privileges and MySQL reported no errors or warnings when the <code>ALTER TABLE</code> was run:<br />
<span></span></p>
<pre>
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 15
Server version: 5.1.41-log MySQL Community Server (GPL)

Type 'help;' or '\h' for help. Type '\c' to clear the buffer.

mysql&gt; grant alter,create,insert on *.* to 'test'@localhost;
Query OK, 0 rows affected (0.00 sec)

mysql&gt; show warnings;
Empty set (0.00 sec)

mysql&gt; show errors;
Empty set (0.00 sec)

mysql&gt;
</pre>
<p>The reason I granted the addition <code>CREATE</code> and <code>INSERT</code> privileges is that according to the MySQL documentation (<a href="http://dev.mysql.com/doc/refman/5.1/en/privileges-provided.html">http://dev.mysql.com/doc/refman/5.1/en/privileges-provided.html</a>), they are required by the <code>ALTER</code> privilege:</p>
<blockquote><p>The ALTER privilege enables use of ALTER TABLE to change the structure of or rename tables. (ALTER TABLE also requires the INSERT and CREATE privileges.)</p></blockquote>
<p>The user was attempting to rename a table with the <code>ALTER TABLE [NAME] RENAME [NAME2]</code> command and seeing the following error:</p>
<pre>
mysql&gt; alter table test1 rename test2;
ERROR 1142 (42000): DROP command denied to user 'test'@'localhost' for table 'test1'

mysql&gt; show grants;
+----------------------------------------------------------+
| Grants for test@localhost                                |
+----------------------------------------------------------+
| GRANT INSERT, CREATE, ALTER ON *.* TO 'test'@'localhost' |
+----------------------------------------------------------+
1 row in set (0.00 sec)

mysql&gt; show tables;
+----------------+
| Tables_in_test |
+----------------+
| test1          |
+----------------+
1 row in set (0.00 sec)
</pre>
<p>Of course I immediately realized what the issue was. In MySQL,  <code>ALTER TABLE [NAME] RENAME [NEW_NAME]</code> is done as a <code>DROP</code> (which requires the <code>DROP</code> privilege and <code>CREATE TABLE</code> (which requires the <code>CREATE</code> privilege).  So I granted the user the <code>DROP</code> privilege.  This time  the user was able to successful rename the table as shown below:</p>
<pre>
mysql&gt; show tables;
+----------------+
| Tables_in_test |
+----------------+
| test1          |
+----------------+
1 row in set (0.00 sec)

mysql&gt; alter table test1 rename test2;
Query OK, 0 rows affected (0.00 sec)

mysql&gt; show grants;
+----------------------------------------------------------------+
| Grants for test@localhost                                      |
+----------------------------------------------------------------+
| GRANT INSERT, CREATE, DROP, ALTER ON *.* TO 'test'@'localhost' |
+----------------------------------------------------------------+
1 row in set (0.00 sec)

mysql&gt; show tables;
+----------------+
| Tables_in_test |
+----------------+
| test2          |
+----------------+
1 row in set (0.00 sec)
</pre>
<p>The MySQL documentation on the <code>ALTER</code> privilege states that it only need <code>CREATE</code> and <code>INSERT</code> but makes no mention of the requirement for <code>DROP</code> privilege. The <code>RENAME TABLE</code> documentation at <a href="http://dev.mysql.com/doc/refman/5.1/en/rename-table.html">http://dev.mysql.com/doc/refman/5.1/en/rename-table.html</a> does mention:</p>
<blockquote><p>When you execute RENAME, you cannot have any locked tables or active transactions. You must also have the ALTER and DROP privileges on the original table, and the CREATE and INSERT privileges on the new table.</p></blockquote>
<p>However, that should be explicit in the <code>ALTER TABLE</code> documentation, because if you use <code>ALTER TABLE...RENAME</code> you will not necessarily read the documentation for the <code>RENAME TABLE</code> syntax.</p>
<p>To make the documentation better for everyone, I have filed a MySQL Bug Report on this documentation  &#8211; <a href="http://bugs.mysql.com/bug.php?id=51593">Bug 51593</a>.</p><br/>PlanetMySQL Voting:
	 <a href="http://planet.mysql.com/entry/vote/?entry_id=23689&vote=1&apivote=1">Vote UP</a> /
	 <a href="http://planet.mysql.com/entry/vote/?entry_id=23689&vote=-1&apivote=1">Vote DOWN</a>]]></content:encoded>
			<wfw:commentRss>http://www.pythian.com/news/9007/when-the-alter-table-privilege-is-not-enough-to-run-alter-table/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
