123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232 |
- <?php
- use ChamiloSession as Session;
- require_once __DIR__.'/../inc/global.inc.php';
- api_protect_course_script();
- api_block_anonymous_users();
- if (!isset($_GET['title']) || !isset($_GET['type']) || !isset($_GET['image'])) {
- echo 'No title';
- exit;
- }
- $paintDir = Session::read('paint_dir');
- if (empty($paintDir)) {
- echo 'No directory to save';
- exit;
- }
- $courseInfo = api_get_course_info();
- if (empty($courseInfo)) {
- echo 'Course not set';
- exit;
- }
- $filename = Security::remove_XSS($_GET['title']);
- $extension = Security::remove_XSS($_GET['type']);
- $urlcontents = Security::remove_XSS($_GET['image']);
- $title = Database::escape_string(str_replace('_', ' ', $filename));
- $sessionId = api_get_session_id();
- $groupId = api_get_group_id();
- $groupInfo = GroupManager::get_group_properties($groupId);
- $dirBaseDocuments = api_get_path(SYS_COURSE_PATH).$courseInfo['path'].'/document';
- $saveDir = $dirBaseDocuments.$paintDir;
- $contents = file_get_contents($urlcontents);
- $filename = addslashes(trim($filename));
- $filename = Security::remove_XSS($filename);
- $filename = api_replace_dangerous_char($filename);
- $filename = disable_dangerous_file($filename);
- if (strlen(trim($filename)) == 0) {
- echo "The title is empty";
-
- exit;
- }
- if ($contents === false) {
- echo "I cannot read: ".$urlcontents;
- exit;
- }
- if ($extension != 'jpg' && $extension != 'png' && $extension != 'pxd') {
- die();
- }
- if ($extension == 'pxd') {
- echo "pxd file type does not supported";
-
- exit;
- }
- $headers = get_headers($urlcontents, 1);
- $content_type = explode("/", $headers['Content-Type']);
- if ($content_type[0] != "image") {
- echo "Invalid file type";
- exit;
- }
- $finfo = new finfo(FILEINFO_MIME);
- $current_mime = $finfo->buffer($contents);
- if (strpos($current_mime, 'image') === false) {
- echo "Invalid mime type file";
- exit;
- }
- $paintFileName = $filename.'.'.$extension;
- $title = $title.'.'.$extension;
- $temp_file_2delete = Session::read('temp_realpath_image');
- if (empty($temp_file_2delete)) {
-
- if (0 != $groupId) {
- $group_properties = GroupManager :: get_group_properties($groupId);
- $groupPath = $group_properties['directory'];
- } else {
- $groupPath = '';
- }
- if (file_exists($saveDir.'/'.$filename.'.'.$extension)) {
- $i = 1;
- while (file_exists($saveDir.'/'.$filename.'_'.$i.'.'.$extension)) {
- $i++;
- }
- $paintFileName = $filename.'_'.$i.'.'.$extension;
- $title = $filename.'_'.$i.'.'.$extension;
- }
- $documentPath = $saveDir.'/'.$paintFileName;
-
- file_put_contents($documentPath, $contents);
-
- $documentId = add_document($courseInfo, $paintDir.$paintFileName, 'file', filesize($documentPath), $title);
- if ($documentId) {
- api_item_property_update(
- $courseInfo,
- TOOL_DOCUMENT,
- $documentId,
- 'DocumentAdded',
- api_get_user_id(),
- $groupInfo,
- null,
- null,
- null,
- $sessionId
- );
- Display::addFlash(Display::return_message(get_lang('Saved')));
- }
- } else {
-
- $documentPath = $saveDir.'/'.$paintFileName;
- file_put_contents($documentPath, $contents);
- $paintFile = Session::read('paint_file');
-
- if (empty($paintFile)) {
- echo 'No attribute paint_file';
- exit;
- }
- if ($paintFile == $paintFileName) {
- $documentId = DocumentManager::get_document_id($courseInfo, $paintDir.$paintFileName);
- update_existing_document($courseInfo, $documentId, filesize($documentPath), null);
- api_item_property_update(
- $courseInfo,
- TOOL_DOCUMENT,
- $documentId,
- 'DocumentUpdated',
- $_user['user_id'],
- $groupInfo,
- null,
- null,
- null,
- $sessionId
- );
- } else {
-
- $documentId = add_document(
- $courseInfo,
- $paintDir.$paintFileName,
- 'file',
- filesize($documentPath),
- $title
- );
- if ($documentId) {
- api_item_property_update(
- $courseInfo,
- TOOL_DOCUMENT,
- $documentId,
- 'DocumentAdded',
- api_get_user_id(),
- $groupInfo,
- null,
- null,
- null,
- $sessionId
- );
- Display::addFlash(Display::return_message(get_lang('Updated')));
- }
- }
- }
- if (!empty($temp_file_2delete)) {
-
- unlink($temp_file_2delete);
- }
- Session::erase('paint_dir');
- Session::erase('paint_file');
- Session::erase('temp_realpath_image');
- $exit = Session::read('exit_pixlr');
- if (empty($exit)) {
- $location = api_get_path(WEB_CODE_PATH).'document/document.php?'.api_get_cidreq();
- echo '<script>window.parent.location.href="'.$location.'"</script>';
- exit;
- } else {
- echo '<div align="center" style="padding-top:150; font-family:Arial, Helvetica, Sans-serif;font-size:25px;color:#aaa;font-weight:bold;">'.get_lang('PleaseStandBy').'</div>';
- $location = api_get_path(WEB_CODE_PATH).'document/document.php?id='.Security::remove_XSS($exit).'&'.api_get_cidreq();
- echo '<script>window.parent.location.href="'.$location.'"</script>';
- Session::erase('exit_pixlr');
- }
|