Version 5.0.0 beta 1

This commit is contained in:
Neo committed 2025-12-19 16:27:35 -08:00
1 parent 25ddeb65d6
commit 15c7beabc5
6736 files changed
+627902 -497943

No files matched your search

+36 -27
View File
@@ -8,29 +8,39 @@
* @since 30 May 2013
*/
use IPS\Application;
use IPS\Db;
use IPS\Dispatcher\External;
use IPS\File;
use IPS\Login;
use IPS\Member;
use IPS\Output;
use IPS\Request;
use IPS\Session\Front;
define('REPORT_EXCEPTIONS', TRUE);
require_once str_replace( 'applications/core/interface/file/attachment.php', '', str_replace( '\\', '/', __FILE__ ) ) . 'init.php';
\IPS\Session\Front::i();
Front::i();
try
{
/* Load member */
$member = \IPS\Member::loggedIn();
$member = Member::loggedIn();
/* Init */
$permission = FALSE;
$loadedExtensions = array();
/* Get attachment */
$attachment = \IPS\Db::i()->select( '*', 'core_attachments', array( 'attach_id=?', \IPS\Request::i()->id ) )->first();
$attachment = Db::i()->select( '*', 'core_attachments', array( 'attach_id=?', Request::i()->id ) )->first();
/* If the user isn't logged in, and this attachment has a security key attached to it, check that. */
if ( $attachment['attach_security_key'] )
{
/* Key doesn't exist or doesn't match */
if ( !isset( \IPS\Request::i()->key ) OR !\IPS\Login::compareHashes( $attachment['attach_security_key'], \IPS\Request::i()->key ) )
if ( !isset( Request::i()->key ) OR !Login::compareHashes( $attachment['attach_security_key'], Request::i()->key ) )
{
throw new \UnexpectedValueException;
throw new UnexpectedValueException;
}
/* Key passes, so do normal permission checks. */
@@ -47,33 +57,33 @@ try
if( $permission !== TRUE )
{
foreach ( \IPS\Db::i()->select( '*', 'core_attachments_map', array( 'attachment_id=?', $attachment['attach_id'] ) ) as $map )
foreach ( Db::i()->select( '*', 'core_attachments_map', array( 'attachment_id=?', $attachment['attach_id'] ) ) as $map )
{
if ( !isset( $loadedExtensions[ $map['location_key'] ] ) )
{
$exploded = explode( '_', $map['location_key'] );
try
{
$extensions = \IPS\Application::load( $exploded[0] )->extensions( 'core', 'EditorLocations' );
$extensions = Application::load( $exploded[0] )->extensions( 'core', 'EditorLocations' );
if ( isset( $extensions[ $exploded[1] ] ) )
{
$loadedExtensions[ $map['location_key'] ] = $extensions[ $exploded[1] ];
}
}
catch ( \OutOfRangeException $e ) { }
catch (OutOfRangeException $e ) { }
}
if ( isset( $loadedExtensions[ $map['location_key'] ] ) )
{
try
{
if ( method_exists( $loadedExtensions[ $map['location_key'] ], 'attachmentPermissionCheck') AND $loadedExtensions[ $map['location_key'] ]->attachmentPermissionCheck( $member, $map['id1'], $map['id2'], $map['id3'], $attachment ) )
if ( $loadedExtensions[ $map['location_key'] ]->attachmentPermissionCheck( $member, $map['id1'], $map['id2'], $map['id3'], $attachment ) )
{
$permission = TRUE;
break;
}
}
catch ( \OutOfRangeException $e ) { }
catch (OutOfRangeException $e ) { }
}
}
}
@@ -81,42 +91,41 @@ try
/* Permission check */
if ( !$permission )
{
\IPS\Dispatcher\External::i();
\IPS\Output::i()->error( 'no_attachment_permission', '2C171/1', 403, '' );
External::i();
Output::i()->error( 'no_attachment_permission', '2C171/1', 403, '' );
}
/* Get file and data */
$file = \IPS\File::get( 'core_Attachment', $attachment['attach_location'] );
$headers = array_merge( \IPS\Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => \IPS\Output::getContentDisposition( 'attachment', $attachment['attach_file'] ), "X-Content-Type-Options" => "nosniff" ) );
$file = File::get( 'core_Attachment', $attachment['attach_location'] );
$headers = array_merge( Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => Output::getContentDisposition( 'attachment', $attachment['attach_file'] ), "X-Content-Type-Options" => "nosniff" ) );
/* Update download counter */
\IPS\Db::i()->update( 'core_attachments', "attach_hits=attach_hits+1", array( 'attach_id=?', $attachment['attach_id'] ) );
Db::i()->update( 'core_attachments', "attach_hits=attach_hits+1", array( 'attach_id=?', $attachment['attach_id'] ) );
/* If it's an AWS file just redirect to it */
$file->originalFilename = $attachment['attach_file'];
if ( $signedUrl = $file->generateTemporaryDownloadUrl() )
{
\IPS\Output::i()->redirect( $signedUrl );
Output::i()->redirect( $signedUrl );
}
/* Send headers and print file */
\IPS\Output::i()->sendStatusCodeHeader( 200 );
\IPS\Output::i()->sendHeader( "Content-type: " . \IPS\File::getMimeType( $file->originalFilename ) . ";charset=UTF-8" );
\IPS\Output::i()->sendHeader( "Content-Security-Policy: default-src 'none'; sandbox" );
\IPS\Output::i()->sendHeader( "X-Content-Security-Policy: default-src 'none'; sandbox" );
\IPS\Output::i()->sendHeader( "Cross-Origin-Opener-Policy: same-origin" );
Output::i()->sendStatusCodeHeader( 200 );
Output::i()->sendHeader( "Content-type: " . File::getMimeType( $file->originalFilename ) . ";charset=UTF-8" );
Output::i()->sendHeader( "Content-Security-Policy: default-src 'none'; sandbox" );
Output::i()->sendHeader( "X-Content-Security-Policy: default-src 'none'; sandbox" );
foreach( $headers as $key => $header )
{
\IPS\Output::i()->sendHeader( $key . ': ' . $header );
Output::i()->sendHeader( $key . ': ' . $header );
}
\IPS\Output::i()->sendHeader( "Content-Length: " . $file->filesize() );
Output::i()->sendHeader( "Content-Length: " . $file->filesize() );
$file->printFile();
exit;
}
catch ( \UnexpectedValueException | \UnderflowException | \ErrorException $e )
catch (UnexpectedValueException | UnderflowException | ErrorException $e )
{
switch( get_class( $e ) )
{
@@ -134,6 +143,6 @@ catch ( \UnexpectedValueException | \UnderflowException | \ErrorException $e )
}
/* Remove previously sent headers, so that the browser doesn't try to download this error as a file */
header_remove();
\IPS\Dispatcher\External::i();
\IPS\Output::i()->error( 'node_error', $code, 404, '' );
External::i();
Output::i()->error( 'node_error', $code, 404, '' );
}
+22 -19
View File
@@ -8,52 +8,55 @@
* @since 11 Feb 2016
*/
use IPS\Dispatcher\Front;
use IPS\File;
use IPS\Output;
use IPS\Request;
define('REPORT_EXCEPTIONS', TRUE);
require_once str_replace( 'applications/core/interface/file/cfield.php', '', str_replace( '\\', '/', __FILE__ ) ) . 'init.php';
try
{
/* Get the extension */
list( $app, $extension ) = explode( '_', \IPS\Request::i()->storage );
list( $app, $extension ) = explode( '_', Request::i()->storage );
$classname = 'IPS\\' . $app . '\extensions\core\FileStorage\\' . $extension;
if ( !class_exists( $classname ) )
{
throw new \RuntimeException;
throw new RuntimeException;
}
$extension = new $classname;
if ( ! isset( \IPS\Request::i()->fileKey ) )
if ( ! isset( Request::i()->fileKey ) )
{
throw new \RuntimeException;
throw new RuntimeException;
}
/* Get the actual filename from the extension */
$realFileName = \IPS\Text\Encrypt::fromTag( \IPS\Request::i()->fileKey )->decrypt();
$realFileName = \IPS\Text\Encrypt::fromTag( Request::i()->fileKey )->decrypt();
/* Check the file is valid */
$file = \IPS\File::get( \IPS\Request::i()->storage, $realFileName );
$file = File::get( Request::i()->storage, $realFileName );
if ( !$extension->isValidFile( $realFileName ) )
{
throw new \RuntimeException;
throw new RuntimeException;
}
/* Send headers and print file */
\IPS\Output::i()->sendStatusCodeHeader( 200 );
\IPS\Output::i()->sendHeader( "Content-type: " . \IPS\File::getMimeType( \IPS\Request::i()->path ) . ";charset=UTF-8" );
foreach( array_merge( \IPS\Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => \IPS\Output::getContentDisposition( 'attachment', \IPS\Request::i()->path ), "X-Content-Type-Options" => "nosniff" ) ) as $key => $header )
Output::i()->sendStatusCodeHeader( 200 );
Output::i()->sendHeader( "Content-type: " . File::getMimeType( Request::i()->path ) . ";charset=UTF-8" );
foreach( array_merge( Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => Output::getContentDisposition( 'attachment', Request::i()->path ), "X-Content-Type-Options" => "nosniff" ) ) as $key => $header )
{
\IPS\Output::i()->sendHeader( $key . ': ' . $header );
Output::i()->sendHeader( $key . ': ' . $header );
}
\IPS\Output::i()->sendHeader( "Content-Length: " . $file->filesize() );
\IPS\Output::i()->sendHeader( "Content-Security-Policy: default-src 'none'; sandbox" );
\IPS\Output::i()->sendHeader( "X-Content-Security-Policy: default-src 'none'; sandbox" );
\IPS\Output::i()->sendHeader( "Cross-Origin-Opener-Policy: same-origin" );
Output::i()->sendHeader( "Content-Length: " . $file->filesize() );
Output::i()->sendHeader( "Content-Security-Policy: default-src 'none'; sandbox" );
Output::i()->sendHeader( "X-Content-Security-Policy: default-src 'none'; sandbox" );
$file->printFile();
exit;
}
catch ( \Exception $e )
catch (Exception $e )
{
\IPS\Dispatcher\Front::i();
\IPS\Output::i()->sendOutput( '', 404 );
Front::i();
Output::i()->sendOutput( '', 404 );
}
+13 -8
View File
@@ -8,33 +8,38 @@
* @since 07 May 2013
*/
use IPS\Db;
use IPS\File;
use IPS\Output;
use IPS\Request;
define('REPORT_EXCEPTIONS', TRUE);
require_once str_replace( 'applications/core/interface/file/index.php', '', str_replace( '\\', '/', __FILE__ ) ) . 'init.php';
try
{
if ( isset( \IPS\Request::i()->id ) and isset( \IPS\Request::i()->salt ) )
if ( isset( Request::i()->id ) and isset( Request::i()->salt ) )
{
$where = array( 'id=? AND salt=?', \IPS\Request::i()->id, \IPS\Request::i()->salt );
$where = array( 'id=? AND salt=?', Request::i()->id, Request::i()->salt );
}
else
{
$exploded = explode( '/', trim( urldecode( \IPS\Request::i()->file ), '/' ) );
$exploded = explode( '/', trim( urldecode( Request::i()->file ), '/' ) );
$filename = array_pop( $exploded );
$container = implode( '/', $exploded );
$where = array( 'container=? AND filename=?', $container, $filename );
}
$file = \IPS\Db::i()->select( '*', 'core_files', $where )->first();
$file = Db::i()->select( '*', 'core_files', $where )->first();
if ( $file['id'] )
{
$headers = array_merge( \IPS\Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => \IPS\Output::getContentDisposition( 'inline', $file['filename'] ), "X-Content-Type-Options" => "nosniff" ) );
\IPS\Output::i()->sendOutput( $file['contents'], 200, \IPS\File::getMimeType( $file['filename'] ), $headers );
$headers = array_merge( Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => Output::getContentDisposition( 'inline', $file['filename'] ), "X-Content-Type-Options" => "nosniff" ) );
Output::i()->sendOutput( $file['contents'], 200, File::getMimeType( $file['filename'] ), $headers );
}
}
catch ( \UnderflowException $e )
catch (UnderflowException $e )
{
\IPS\Output::i()->sendOutput( '', 404 );
Output::i()->sendOutput( '', 404 );
}