Version 4.6.0

This commit is contained in:
Neo committed 2025-12-19 05:55:31 -08:00
1 parent f79dcf067a
commit 517a5e1f70
2036 files changed
+110041 -26162

No files matched your search

@@ -23,9 +23,22 @@ try
/* Get attachment */
$attachment = \IPS\Db::i()->select( '*', 'core_attachments', array( 'attach_id=?', \IPS\Request::i()->id ) )->first();
/* If the user isn't logged in, and this attachment has a security key attached to it, check that. */
if ( $attachment['attach_security_key'] )
{
/* Key doesn't exist or doesn't match */
if ( !isset( \IPS\Request::i()->key ) OR !\IPS\Login::compareHashes( $attachment['attach_security_key'], \IPS\Request::i()->key ) )
{
throw new \UnexpectedValueException;
}
/* Key passes, so do normal permission checks. */
}
if( $member->member_id )
{
/* If there is a member logged in, and they posted the attachment, they have permission to view. */
if ( $member->member_id == $attachment['attach_member_id'] )
{
$permission = TRUE;
@@ -101,17 +114,24 @@ try
$file->printFile();
exit;
}
catch ( \UnderflowException $e )
catch ( \UnexpectedValueException | \UnderflowException | \ErrorException $e )
{
switch( get_class( $e ) )
{
case 'UnexpectedValueException':
$code = '2S328/2';
break;
case 'UnderflowException':
$code = '2S328/1';
break;
case 'ErrorException':
$code = '2C327/1';
break;
}
/* Remove previously sent headers, so that the browser doesn't try to download this error as a file */
header_remove();
\IPS\Dispatcher\External::i();
\IPS\Output::i()->error( 'node_error', '2S328/1', 404, '' );
}
catch ( \ErrorException $e )
{
/* Remove previously sent headers, so that the browser doesn't try to download this error as a file */
header_remove();
\IPS\Dispatcher\External::i();
\IPS\Output::i()->error( 'node_error', '2C327/1', 404, '' );
\IPS\Output::i()->error( 'node_error', $code, 404, '' );
}