-
Notifications
You must be signed in to change notification settings - Fork 252
/
getAttachmentLocal.php
executable file
·91 lines (74 loc) · 2.7 KB
/
getAttachmentLocal.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
<?php
/*
* CATS
* AJAX Attachment retrieval function
*
* Copyright (C) 2005 - 2007 Cognizo Technologies, Inc.
*
*
* The contents of this file are subject to the CATS Public License
* Version 1.1a (the "License"); you may not use this file except in
* compliance with the License. You may obtain a copy of the License at
* http://www.catsone.com/.
*
* Software distributed under the License is distributed on an "AS IS"
* basis, WITHOUT WARRANTY OF ANY KIND, either express or implied. See the
* License for the specific language governing rights and limitations
* under the License.
*
* The Original Code is "CATS Standard Edition".
*
* The Initial Developer of the Original Code is Cognizo Technologies, Inc.
* Portions created by the Initial Developer are Copyright (C) 2005 - 2007
* (or from the year in which this file was created to the year 2007) by
* Cognizo Technologies, Inc. All Rights Reserved.
*
*
* $Id: getAttachmentLocal.php 3078 2007-09-21 20:25:28Z will $
*/
$interface = new SecureAJAXInterface();
include_once(LEGACY_ROOT . '/lib/CommonErrors.php');
include_once(LEGACY_ROOT . '/lib/Attachments.php');
@ini_set('memory_limit', '256M');
if (!isset($_POST['id']) || !$interface->isRequiredIDValid('id'))
{
$interface->outputXMLErrorPage(-2, 'No attachment ID specified.');
die();
}
$attachmentID = $_POST['id'];
$attachments = new Attachments(-1);
$rs = $attachments->get($attachmentID, false);
if (!isset($rs['directoryName']) ||
!isset($rs['storedFilename']) ||
md5($rs['directoryName']) != $_POST['directoryNameHash'])
{
$interface->outputXMLErrorPage(-2, 'Invalid directory name hash.');
die();
}
$directoryName = $rs['directoryName'];
$fileName = $rs['storedFilename'];
/* Check for the existence of the backup. If it is gone, send the user to a page informing them to press back and generate the backup again. */
if ($rs['contentType'] == 'catsbackup')
{
if (!file_exists('attachments/'.$directoryName.'/'.$fileName))
{
$interface->outputXMLErrorPage(-2, 'The specified backup file no longer exists. Please press back and regenerate the backup before downloading. We are sorry for the inconvenience.');
die();
}
}
$url = 'attachments/'.$directoryName.'/'.$fileName;
if (!eval(Hooks::get('ATTACHMENT_RETRIEVAL'))) return;
if (!file_exists('attachments/'.$directoryName.'/'.$fileName))
{
$interface->outputXMLErrorPage(-2, 'The file is temporarily unavailable for download. Please try again.');
die();
}
$output =
"<data>\n" .
" <errorcode>0</errorcode>\n" .
" <errormessage></errormessage>\n" .
" <success>1</success>\n" .
"</data>\n";
/* Send back the XML data. */
$interface->outputXMLPage($output);
?>