2005-12-19 18:58:38 +00:00
|
|
|
<?php
|
|
|
|
// +-----------------------------------------------------------------------+
|
2011-01-18 00:02:52 +00:00
|
|
|
// | Piwigo - a PHP based photo gallery |
|
2008-04-04 22:57:23 +00:00
|
|
|
// +-----------------------------------------------------------------------+
|
2011-01-18 00:02:52 +00:00
|
|
|
// | Copyright(C) 2008-2011 Piwigo Team http://piwigo.org |
|
2008-04-04 22:57:23 +00:00
|
|
|
// | Copyright(C) 2003-2008 PhpWebGallery Team http://phpwebgallery.net |
|
|
|
|
// | Copyright(C) 2002-2003 Pierrick LE GALL http://le-gall.net/pierrick |
|
|
|
|
// +-----------------------------------------------------------------------+
|
|
|
|
// | This program is free software; you can redistribute it and/or modify |
|
2005-12-19 18:58:38 +00:00
|
|
|
// | it under the terms of the GNU General Public License as published by |
|
|
|
|
// | the Free Software Foundation |
|
|
|
|
// | |
|
|
|
|
// | This program is distributed in the hope that it will be useful, but |
|
|
|
|
// | WITHOUT ANY WARRANTY; without even the implied warranty of |
|
|
|
|
// | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU |
|
|
|
|
// | General Public License for more details. |
|
|
|
|
// | |
|
|
|
|
// | You should have received a copy of the GNU General Public License |
|
|
|
|
// | along with this program; if not, write to the Free Software |
|
|
|
|
// | Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, |
|
|
|
|
// | USA. |
|
|
|
|
// +-----------------------------------------------------------------------+
|
|
|
|
|
2006-10-10 21:23:06 +00:00
|
|
|
define('PHPWG_ROOT_PATH','./');
|
|
|
|
include_once(PHPWG_ROOT_PATH.'include/common.inc.php');
|
|
|
|
|
|
|
|
// Check Access and exit when user status is not ok
|
|
|
|
check_status(ACCESS_GUEST);
|
|
|
|
|
2006-11-17 04:26:10 +00:00
|
|
|
function guess_mime_type($ext)
|
2005-12-19 18:58:38 +00:00
|
|
|
{
|
2006-11-17 04:26:10 +00:00
|
|
|
switch ( strtolower($ext) )
|
2006-10-10 21:23:06 +00:00
|
|
|
{
|
2006-11-17 04:26:10 +00:00
|
|
|
case "jpe": case "jpeg":
|
|
|
|
case "jpg": $ctype="image/jpeg"; break;
|
|
|
|
case "png": $ctype="image/png"; break;
|
|
|
|
case "gif": $ctype="image/gif"; break;
|
|
|
|
case "tiff":
|
|
|
|
case "tif": $ctype="image/tiff"; break;
|
|
|
|
case "txt": $ctype="text/plain"; break;
|
|
|
|
case "html":
|
|
|
|
case "htm": $ctype="text/html"; break;
|
|
|
|
case "xml": $ctype="text/xml"; break;
|
|
|
|
case "pdf": $ctype="application/pdf"; break;
|
|
|
|
case "zip": $ctype="application/zip"; break;
|
|
|
|
case "ogg": $ctype="application/ogg"; break;
|
|
|
|
default: $ctype="application/octet-stream";
|
2006-10-10 21:23:06 +00:00
|
|
|
}
|
2006-11-17 04:26:10 +00:00
|
|
|
return $ctype;
|
|
|
|
}
|
2005-12-19 18:58:38 +00:00
|
|
|
|
2006-11-17 04:26:10 +00:00
|
|
|
function do_error( $code, $str )
|
|
|
|
{
|
2006-12-08 00:12:44 +00:00
|
|
|
set_status_header( $code );
|
2006-11-17 04:26:10 +00:00
|
|
|
echo $str ;
|
|
|
|
exit();
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2007-02-14 22:53:02 +00:00
|
|
|
if (!isset($_GET['id'])
|
|
|
|
or !is_numeric($_GET['id'])
|
2006-11-17 04:26:10 +00:00
|
|
|
or !isset($_GET['part'])
|
|
|
|
or !in_array($_GET['part'], array('t','e','i','h') ) )
|
|
|
|
{
|
|
|
|
do_error(400, 'Invalid request - id/part');
|
|
|
|
}
|
|
|
|
|
|
|
|
$query = '
|
|
|
|
SELECT * FROM '. IMAGES_TABLE.'
|
2007-02-14 22:53:02 +00:00
|
|
|
WHERE id='.$_GET['id'].'
|
2006-11-17 04:26:10 +00:00
|
|
|
;';
|
|
|
|
|
|
|
|
$result = pwg_query($query);
|
2009-11-20 14:17:04 +00:00
|
|
|
$element_info = pwg_db_fetch_assoc($result);
|
2006-11-17 04:26:10 +00:00
|
|
|
if ( empty($element_info) )
|
|
|
|
{
|
|
|
|
do_error(404, 'Requested id not found');
|
|
|
|
}
|
2006-12-21 23:49:12 +00:00
|
|
|
|
|
|
|
// $filter['visible_categories'] and $filter['visible_images']
|
2006-12-21 21:38:20 +00:00
|
|
|
// are not used because it's not necessary (filter <> restriction)
|
2006-11-22 02:57:41 +00:00
|
|
|
$query='
|
2007-02-14 22:53:02 +00:00
|
|
|
SELECT id
|
|
|
|
FROM '.CATEGORIES_TABLE.'
|
|
|
|
INNER JOIN '.IMAGE_CATEGORY_TABLE.' ON category_id = id
|
|
|
|
WHERE image_id = '.$_GET['id'].'
|
|
|
|
'.get_sql_condition_FandF(
|
2007-09-11 02:24:51 +00:00
|
|
|
array(
|
|
|
|
'forbidden_categories' => 'category_id',
|
|
|
|
'forbidden_images' => 'image_id',
|
|
|
|
),
|
2007-02-14 22:53:02 +00:00
|
|
|
' AND'
|
|
|
|
).'
|
2006-11-22 02:57:41 +00:00
|
|
|
LIMIT 1
|
|
|
|
;';
|
2009-11-20 14:17:04 +00:00
|
|
|
if ( pwg_db_num_rows(pwg_query($query))<1 )
|
2006-11-22 02:57:41 +00:00
|
|
|
{
|
|
|
|
do_error(401, 'Access denied');
|
|
|
|
}
|
2006-11-17 04:26:10 +00:00
|
|
|
|
|
|
|
include_once(PHPWG_ROOT_PATH.'include/functions_picture.inc.php');
|
|
|
|
$file='';
|
|
|
|
switch ($_GET['part'])
|
|
|
|
{
|
|
|
|
case 't':
|
|
|
|
$file = get_thumbnail_path($element_info);
|
|
|
|
break;
|
|
|
|
case 'e':
|
|
|
|
$file = get_element_path($element_info);
|
|
|
|
break;
|
|
|
|
case 'i':
|
|
|
|
$file = get_image_path($element_info);
|
|
|
|
break;
|
|
|
|
case 'h':
|
2006-11-22 02:57:41 +00:00
|
|
|
if ( $user['enabled_high']!='true' )
|
|
|
|
{
|
|
|
|
do_error(401, 'Access denied h');
|
|
|
|
}
|
2006-11-17 04:26:10 +00:00
|
|
|
$file = get_high_path($element_info);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( empty($file) )
|
|
|
|
{
|
|
|
|
do_error(404, 'Requested file not found');
|
|
|
|
}
|
|
|
|
|
2007-02-14 22:53:02 +00:00
|
|
|
if ($_GET['part'] == 'h') {
|
2007-02-20 23:40:02 +00:00
|
|
|
pwg_log($_GET['id'], 'high');
|
|
|
|
}
|
|
|
|
else if ($_GET['part'] == 'e')
|
|
|
|
{
|
|
|
|
pwg_log($_GET['id'], 'other');
|
2007-02-14 22:53:02 +00:00
|
|
|
}
|
|
|
|
|
2006-11-17 04:26:10 +00:00
|
|
|
$http_headers = array();
|
2005-12-19 18:58:38 +00:00
|
|
|
|
2006-11-17 04:26:10 +00:00
|
|
|
$ctype = null;
|
|
|
|
if (!url_is_remote($file))
|
|
|
|
{
|
|
|
|
if ( !@is_readable($file) )
|
2006-10-10 21:23:06 +00:00
|
|
|
{
|
2006-11-17 04:26:10 +00:00
|
|
|
do_error(404, "Requested file not found - $file");
|
2006-10-10 21:23:06 +00:00
|
|
|
}
|
2006-11-17 04:26:10 +00:00
|
|
|
$http_headers[] = 'Content-Length: '.@filesize($file);
|
|
|
|
if ( function_exists('mime_content_type') )
|
2006-09-20 21:24:34 +00:00
|
|
|
{
|
2006-11-17 04:26:10 +00:00
|
|
|
$ctype = mime_content_type($file);
|
2006-09-20 21:24:34 +00:00
|
|
|
}
|
2006-11-22 02:57:41 +00:00
|
|
|
|
|
|
|
$gmt_mtime = gmdate('D, d M Y H:i:s', filemtime($file)).' GMT';
|
|
|
|
$http_headers[] = 'Last-Modified: '.$gmt_mtime;
|
|
|
|
|
|
|
|
// following lines would indicate how the client should handle the cache
|
|
|
|
/* $max_age=300;
|
|
|
|
$http_headers[] = 'Expires: '.gmdate('D, d M Y H:i:s', time()+$max_age).' GMT';
|
|
|
|
// HTTP/1.1 only
|
|
|
|
$http_headers[] = 'Cache-Control: private, must-revalidate, max-age='.$max_age;*/
|
|
|
|
|
|
|
|
if ( isset( $_SERVER['HTTP_IF_MODIFIED_SINCE'] ) )
|
|
|
|
{
|
2006-12-08 00:12:44 +00:00
|
|
|
set_status_header(304);
|
2006-11-22 02:57:41 +00:00
|
|
|
foreach ($http_headers as $header)
|
|
|
|
{
|
|
|
|
header( $header );
|
|
|
|
}
|
|
|
|
exit();
|
|
|
|
}
|
2006-11-17 04:26:10 +00:00
|
|
|
}
|
2006-11-22 02:57:41 +00:00
|
|
|
|
2006-11-17 04:26:10 +00:00
|
|
|
if (!isset($ctype))
|
|
|
|
{ // give it a guess
|
|
|
|
$ctype = guess_mime_type( get_extension($file) );
|
|
|
|
}
|
2006-09-20 21:24:34 +00:00
|
|
|
|
2006-11-17 04:26:10 +00:00
|
|
|
$http_headers[] = 'Content-Type: '.$ctype;
|
|
|
|
|
|
|
|
if (!isset($_GET['view']))
|
|
|
|
{
|
2010-02-19 09:46:42 +00:00
|
|
|
$http_headers[] = 'Content-Disposition: attachment; filename="'.$element_info['file'].'";';
|
2006-11-17 04:26:10 +00:00
|
|
|
$http_headers[] = 'Content-Transfer-Encoding: binary';
|
2005-12-19 18:58:38 +00:00
|
|
|
}
|
2006-11-22 02:57:41 +00:00
|
|
|
else
|
|
|
|
{
|
|
|
|
$http_headers[] = 'Content-Disposition: inline; filename="'
|
|
|
|
.basename($file).'";';
|
|
|
|
}
|
2006-11-17 04:26:10 +00:00
|
|
|
|
|
|
|
foreach ($http_headers as $header)
|
2005-12-19 18:58:38 +00:00
|
|
|
{
|
2006-11-17 04:26:10 +00:00
|
|
|
header( $header );
|
2005-12-19 18:58:38 +00:00
|
|
|
}
|
2006-11-17 04:26:10 +00:00
|
|
|
|
|
|
|
// Looking at the safe_mode configuration for execution time
|
|
|
|
if (ini_get('safe_mode') == 0)
|
|
|
|
{
|
|
|
|
@set_time_limit(0);
|
|
|
|
}
|
|
|
|
|
|
|
|
@readfile($file);
|
2005-12-19 18:58:38 +00:00
|
|
|
|
2006-11-17 04:26:10 +00:00
|
|
|
?>
|