Version 4.6.0
This commit is contained in:
1 parent
f79dcf067a
commit
517a5e1f70
2036 files changed
+110041
-26162
No files matched your search
@@ -23,9 +23,22 @@ try
|
||||
|
||||
/* Get attachment */
|
||||
$attachment = \IPS\Db::i()->select( '*', 'core_attachments', array( 'attach_id=?', \IPS\Request::i()->id ) )->first();
|
||||
|
||||
/* If the user isn't logged in, and this attachment has a security key attached to it, check that. */
|
||||
if ( $attachment['attach_security_key'] )
|
||||
{
|
||||
/* Key doesn't exist or doesn't match */
|
||||
if ( !isset( \IPS\Request::i()->key ) OR !\IPS\Login::compareHashes( $attachment['attach_security_key'], \IPS\Request::i()->key ) )
|
||||
{
|
||||
throw new \UnexpectedValueException;
|
||||
}
|
||||
|
||||
/* Key passes, so do normal permission checks. */
|
||||
}
|
||||
|
||||
if( $member->member_id )
|
||||
{
|
||||
/* If there is a member logged in, and they posted the attachment, they have permission to view. */
|
||||
if ( $member->member_id == $attachment['attach_member_id'] )
|
||||
{
|
||||
$permission = TRUE;
|
||||
@@ -101,17 +114,24 @@ try
|
||||
$file->printFile();
|
||||
exit;
|
||||
}
|
||||
catch ( \UnderflowException $e )
|
||||
catch ( \UnexpectedValueException | \UnderflowException | \ErrorException $e )
|
||||
{
|
||||
switch( get_class( $e ) )
|
||||
{
|
||||
case 'UnexpectedValueException':
|
||||
$code = '2S328/2';
|
||||
break;
|
||||
|
||||
case 'UnderflowException':
|
||||
$code = '2S328/1';
|
||||
break;
|
||||
|
||||
case 'ErrorException':
|
||||
$code = '2C327/1';
|
||||
break;
|
||||
}
|
||||
/* Remove previously sent headers, so that the browser doesn't try to download this error as a file */
|
||||
header_remove();
|
||||
\IPS\Dispatcher\External::i();
|
||||
\IPS\Output::i()->error( 'node_error', '2S328/1', 404, '' );
|
||||
}
|
||||
catch ( \ErrorException $e )
|
||||
{
|
||||
/* Remove previously sent headers, so that the browser doesn't try to download this error as a file */
|
||||
header_remove();
|
||||
\IPS\Dispatcher\External::i();
|
||||
\IPS\Output::i()->error( 'node_error', '2C327/1', 404, '' );
|
||||
\IPS\Output::i()->error( 'node_error', $code, 404, '' );
|
||||
}
|
||||
Reference in new issue
Block a user