downloadfolder.inc.php 6.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230
  1. <?php
  2. /* For licensing terms, see /license.txt */
  3. /**
  4. * Functions and main code for the download folder feature
  5. * @todo use ids instead of the path like the document tool
  6. * @package chamilo.work
  7. */
  8. $work_id = $_GET['id'];
  9. //require_once '../inc/global.inc.php';
  10. $current_course_tool = TOOL_STUDENTPUBLICATION;
  11. $_course = api_get_course_info();
  12. // Protection
  13. api_protect_course_script(true);
  14. require_once 'work.lib.php';
  15. $work_data = get_work_data_by_id($work_id);
  16. $groupId = api_get_group_id();
  17. if (empty($work_data)) {
  18. exit;
  19. }
  20. // Prevent some stuff.
  21. if (empty($path)) {
  22. $path = '/';
  23. }
  24. if (empty($_course) || empty($_course['path'])) {
  25. api_not_allowed();
  26. }
  27. $sys_course_path = api_get_path(SYS_COURSE_PATH);
  28. // Creating a ZIP file
  29. $temp_zip_file = api_get_path(SYS_ARCHIVE_PATH).api_get_unique_id().".zip";
  30. $zip_folder = new PclZip($temp_zip_file);
  31. $tbl_student_publication = Database::get_course_table(TABLE_STUDENT_PUBLICATION);
  32. $prop_table = Database::get_course_table(TABLE_ITEM_PROPERTY);
  33. $tableUser = Database::get_main_table(TABLE_MAIN_USER);
  34. // Put the files in the zip
  35. // 2 possibilities: admins get all files and folders in the selected folder (except for the deleted ones)
  36. // normal users get only visible files that are in visible folders
  37. //admins are allowed to download invisible files
  38. $files = array();
  39. $course_id = api_get_course_int_id();
  40. $sessionId = api_get_session_id();
  41. $sessionCondition = api_get_session_condition($sessionId, true, false, 'props.session_id');
  42. $filenameCondition = null;
  43. if (array_key_exists('filename', $work_data)) {
  44. $filenameCondition = ", filename";
  45. }
  46. if (api_is_allowed_to_edit() || api_is_coach()) {
  47. //Search for all files that are not deleted => visibility != 2
  48. $sql = "SELECT DISTINCT
  49. url,
  50. title,
  51. description,
  52. insert_user_id,
  53. insert_date,
  54. contains_file
  55. $filenameCondition
  56. FROM $tbl_student_publication AS work
  57. INNER JOIN $prop_table AS props
  58. INNER JOIN $tableUser as u
  59. ON (
  60. props.c_id = $course_id AND
  61. work.c_id = $course_id AND
  62. work.id = props.ref AND
  63. props.tool='work' AND
  64. work.user_id = u.user_id
  65. )
  66. WHERE
  67. work.parent_id = $work_id AND
  68. work.filetype = 'file' AND
  69. props.visibility <> '2' AND
  70. work.active IN (0, 1) AND
  71. work.post_group_id = $groupId
  72. $sessionCondition
  73. ";
  74. } else {
  75. $courseInfo = api_get_course_info();
  76. protectWork($courseInfo, $work_id);
  77. $userCondition = null;
  78. // All users
  79. if ($courseInfo['show_score'] == 0) {
  80. // Do another filter
  81. } else {
  82. // Only teachers
  83. $userCondition = " AND props.insert_user_id = ".api_get_user_id();
  84. }
  85. //for other users, we need to create a zipfile with only visible files and folders
  86. $sql = "SELECT DISTINCT
  87. url,
  88. title,
  89. description,
  90. insert_user_id,
  91. insert_date,
  92. contains_file
  93. $filenameCondition
  94. FROM $tbl_student_publication AS work
  95. INNER JOIN $prop_table AS props
  96. ON (props.c_id = $course_id AND
  97. work.c_id = $course_id AND
  98. work.id = props.ref)
  99. WHERE
  100. props.tool='work' AND
  101. work.accepted = 1 AND
  102. work.active = 1 AND
  103. work.parent_id = $work_id AND
  104. work.filetype = 'file' AND
  105. props.visibility = '1' AND
  106. work.post_group_id = $groupId
  107. $userCondition
  108. ";
  109. }
  110. $query = Database::query($sql);
  111. //add tem to the zip file
  112. while ($not_deleted_file = Database::fetch_assoc($query)) {
  113. $user_info = api_get_user_info($not_deleted_file['insert_user_id']);
  114. $insert_date = api_get_local_time($not_deleted_file['insert_date']);
  115. $insert_date = str_replace(array(':', '-', ' '), '_', $insert_date);
  116. $title = basename($not_deleted_file['title']);
  117. if (!empty($filenameCondition)) {
  118. if (isset($not_deleted_file['filename']) && !empty($not_deleted_file['filename'])) {
  119. $title = $not_deleted_file['filename'];
  120. }
  121. }
  122. $filename = $insert_date.'_'.$user_info['username'].'_'.$title;
  123. // File exists
  124. if (file_exists($sys_course_path.$_course['path'].'/'.$not_deleted_file['url']) &&
  125. !empty($not_deleted_file['url'])
  126. ) {
  127. $files[basename($not_deleted_file['url'])] = $filename;
  128. $addStatus = $zip_folder->add(
  129. $sys_course_path.$_course['path'].'/'.$not_deleted_file['url'],
  130. PCLZIP_OPT_REMOVE_PATH,
  131. $sys_course_path.$_course['path'].'/work',
  132. PCLZIP_CB_PRE_ADD,
  133. 'my_pre_add_callback'
  134. );
  135. } else {
  136. // Convert texts in html files
  137. //if ($not_deleted_file['contains_file'] == 0) {
  138. $filename = trim($filename).".html";
  139. $work_temp = api_get_path(SYS_ARCHIVE_PATH).api_get_unique_id().'_'.$filename;
  140. file_put_contents($work_temp, $not_deleted_file['description']);
  141. $files[basename($work_temp)] = $filename;
  142. $addStatus = $zip_folder->add(
  143. $work_temp,
  144. PCLZIP_OPT_REMOVE_PATH,
  145. api_get_path(SYS_ARCHIVE_PATH),
  146. PCLZIP_CB_PRE_ADD,
  147. 'my_pre_add_callback'
  148. );
  149. @unlink($work_temp);
  150. }
  151. }
  152. if (!empty($files)) {
  153. $fileName = api_replace_dangerous_char($work_data['title']);
  154. // Logging
  155. Event::event_download($fileName .'.zip (folder)');
  156. //start download of created file
  157. $name = $fileName .'.zip';
  158. if (Security::check_abs_path($temp_zip_file, api_get_path(SYS_ARCHIVE_PATH))) {
  159. DocumentManager::file_send_for_download($temp_zip_file, true, $name);
  160. @unlink($temp_zip_file);
  161. exit;
  162. }
  163. } else {
  164. exit;
  165. }
  166. /* Extra function (only used here) */
  167. function my_pre_add_callback($p_event, &$p_header)
  168. {
  169. global $files;
  170. if (isset($files[basename($p_header['stored_filename'])])) {
  171. $p_header['stored_filename'] = $files[basename($p_header['stored_filename'])];
  172. return 1;
  173. }
  174. return 0;
  175. }
  176. /**
  177. * Return the difference between two arrays, as an array of those key/values
  178. * Use this as array_diff doesn't give the
  179. *
  180. * @param array $arr1 first array
  181. * @param array $arr2 second array
  182. *
  183. * @return array difference between the two arrays
  184. */
  185. function diff($arr1, $arr2)
  186. {
  187. $res = array();
  188. $r = 0;
  189. foreach ($arr1 as $av) {
  190. if (!in_array($av, $arr2)) {
  191. $res[$r] = $av;
  192. $r++;
  193. }
  194. }
  195. return $res;
  196. }