#!/usr/bin/env python

"""
Copyright (c) 2006-2026 sqlmap developers (https://sqlmap.org)
See the file 'LICENSE' for copying permission
"""

import re

from lib.core.enums import PRIORITY

__priority__ = PRIORITY.HIGHEST

def dependencies():
    pass

def tamper(payload, **kwargs):
    """
    Replaces all occurrences of operator equal ('=') with 'LIKE' counterpart

    Requirement:
        * MySQL
        * MariaDB
        * SQLite
        * Microsoft SQL Server
        * Oracle

    Tested against:
        * MySQL 8.4.9
        * MariaDB 11.8.8
        * SQLite 3.45.1
        * Microsoft SQL Server 2022
        * Oracle 23ai

    Notes:
        * Useful to bypass weak and bespoke web application firewalls that
          filter the equal character ('=')
        * NOT usable against PostgreSQL, which refuses to compare a numeric
          operand with LIKE (e.g. '1 LIKE 1' raises 'operator does not exist:
          integer ~~ integer'), unlike the engines listed above which coerce
          the operands to text

    >>> tamper('SELECT * FROM users WHERE id=1')
    'SELECT * FROM users WHERE id LIKE 1'
    """

    retVal = payload

    if payload:
        retVal = re.sub(r"\s*(?<![<>!=])=(?!=)\s*", " LIKE ", retVal)  # Note: skipping compound operators (e.g. >=, <=, !=)

    return retVal
