savefile_config.php 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159
  1. <?php
  2. use ChamiloSession as Session;
  3. /*
  4. * filesave.php
  5. * To be used with ext-server_opensave.js for SVG-edit
  6. *
  7. * Licensed under the Apache License, Version 2
  8. *
  9. * Copyright(c) 2010 Alexis Deveria
  10. *
  11. * Integrate svg-edit with Chamilo
  12. * @author Juan Carlos Raña Trabado
  13. * @since 25/september/2010
  14. */
  15. require_once '../../../../../inc/global.inc.php';
  16. // Add security from Chamilo
  17. api_protect_course_script();
  18. api_block_anonymous_users();
  19. if (!isset($_POST['output_svg']) && !isset($_POST['output_png'])) {
  20. api_not_allowed();
  21. }
  22. $file = '';
  23. $suffix = isset($_POST['output_svg']) ? 'svg' : 'png';
  24. if (isset($_POST['filename']) && strlen($_POST['filename']) > 0) {
  25. $file = $_POST['filename'];
  26. } else {
  27. $file = 'image';
  28. }
  29. if ($suffix == 'svg') {
  30. $mime = 'image/svg+xml';
  31. $contents = rawurldecode($_POST['output_svg']);
  32. } else {
  33. $mime = 'image/png';
  34. $contents = $_POST['output_png'];
  35. $pos = (strpos($contents, 'base64,') + 7);
  36. $contents = base64_decode(substr($contents, $pos));
  37. }
  38. //get SVG-Edit values
  39. $filename = $file;//from svg-edit
  40. $extension = $suffix;// from svg-edit
  41. $content = $contents;//from svg-edit
  42. $title = Database::escape_string(str_replace('_', ' ', $filename));
  43. $_course = api_get_course_info();
  44. $relativeUrlPath = Session::read('draw_dir');
  45. $_course = api_get_course_info();
  46. $sessionId = api_get_session_id();
  47. $groupId = api_get_group_id();
  48. $groupInfo = GroupManager::get_group_properties($groupId);
  49. $dirBaseDocuments = api_get_path(SYS_COURSE_PATH).$_course['path'].'/document/';
  50. $saveDir = $dirBaseDocuments.$relativeUrlPath;
  51. // a bit title security
  52. $filename = addslashes(trim($filename));
  53. $filename = Security::remove_XSS($filename);
  54. $filename = api_replace_dangerous_char($filename);
  55. $filename = disable_dangerous_file($filename);
  56. // a bit extension
  57. if ($suffix != 'svg' && $suffix != 'png') {
  58. die();
  59. }
  60. $drawFileNameFromSession = Session::read('draw_file');
  61. //checks if the file exists, then rename the new
  62. if (file_exists($saveDir.'/'.$filename.'.'.$extension) &&
  63. empty($drawFileNameFromSession)
  64. ) {
  65. $message = get_lang('This file name already exists, choose another to save your image.');
  66. $params = array(
  67. 'message' => $message,
  68. 'url' => ''
  69. );
  70. echo json_encode($params);
  71. exit;
  72. } else {
  73. $drawFileName = $filename.'.'.$extension;
  74. $title = $title.'.'.$extension;
  75. }
  76. $documentPath = $saveDir.'/'.$drawFileName;
  77. //add new document to disk
  78. file_put_contents($documentPath, $contents);
  79. if (empty($drawFileNameFromSession)) {
  80. //add document to database
  81. $doc_id = DocumentManager::addDocument(
  82. $_course,
  83. $relativeUrlPath.'/'.$drawFileName,
  84. 'file',
  85. filesize($documentPath),
  86. $title
  87. );
  88. } else {
  89. if ($drawFileNameFromSession == $drawFileName) {
  90. $document_id = DocumentManager::get_document_id(
  91. $_course,
  92. $relativeUrlPath.'/'.$drawFileName
  93. );
  94. update_existing_document(
  95. $_course,
  96. $document_id,
  97. filesize($documentPath),
  98. null
  99. );
  100. api_item_property_update(
  101. $_course,
  102. TOOL_DOCUMENT,
  103. $document_id,
  104. 'DocumentUpdated',
  105. api_get_user_id(),
  106. $groupInfo,
  107. null,
  108. null,
  109. null,
  110. $sessionId
  111. );
  112. } else {
  113. //add a new document
  114. $doc_id = DocumentManager::addDocument(
  115. $_course,
  116. $relativeUrlPath.'/'.$drawFileName,
  117. 'file',
  118. filesize($documentPath),
  119. $title
  120. );
  121. }
  122. }
  123. //clean sessions and add messages and return to current document list
  124. Session::erase('draw_dir');
  125. Session::erase('draw_file');
  126. if ($suffix != 'png') {
  127. if ($relativeUrlPath == '') {
  128. $relativeUrlPath = '/';
  129. };
  130. $url = api_get_path(WEB_CODE_PATH).'document/document.php?'.api_get_cidreq().'&curdirpath='.urlencode($relativeUrlPath);
  131. $message = get_lang('File saved as').': '.$title;
  132. } else {
  133. $url = '';
  134. $message = get_lang('File export as').': '.$title;
  135. }
  136. $params = array(
  137. 'message' => $message,
  138. 'url' => $url
  139. );
  140. echo json_encode($params);
  141. exit;