123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249 |
- <?php
- /* For licensing terms, see /license.txt */
- /**
- * This file allows creating new svg and png documents with an online editor.
- *
- * @package chamilo.document
- *
- * @author Juan Carlos Raña Trabado
- * @since 30/january/2011
- */
- /**
- * Code
- */
- require_once '../inc/global.inc.php';
- api_protect_course_script();
- api_block_anonymous_users();
- if ($_user['user_id'] != api_get_user_id() || api_get_user_id() == 0 || $_user['user_id'] == 0) {
- api_not_allowed();
- die();
- }
- if (!isset($_GET['title']) || !isset($_GET['type']) || !isset($_GET['image'])) {
- api_not_allowed();
- die();
- }
- if (!isset($_SESSION['paint_dir']) || !isset($_SESSION['whereami'])) {
- api_not_allowed();
- die();
- }
- //pixlr return
- $filename = Security::remove_XSS($_GET['title']); //The user preferred file name of the image.
- $extension = Security::remove_XSS($_GET['type']); //The image type, "pdx", "jpg", "bmp" or "png".
- $urlcontents = Security::remove_XSS(
- $_GET['image']
- ); //A URL to the image on Pixlr.com server or the raw file post of the saved image.
- //make variables
- $title = Database::escape_string(str_replace('_', ' ', $filename));
- $current_session_id = api_get_session_id();
- $groupId = api_get_group_id();
- $relativeUrlPath = $_SESSION['paint_dir'];
- $currentTool = $_SESSION['whereami'];
- $dirBaseDocuments = api_get_path(SYS_COURSE_PATH).$_course['path'].'/document';
- $saveDir = $dirBaseDocuments.$_SESSION['paint_dir'];
- $contents = file_get_contents($urlcontents);
- //Security. Verify that the URL is pointing to a file @ pixlr.com domain or an ip @ pixlr.com. Comment because sometimes return a ip number
- /*
- if (strpos($urlcontents, "pixlr.com") === 0){
- echo "Invalid referrer";
- exit;
- }
- */
- //Security. Allway get from pixlr.com. Comment because for now this does not run
- /*
- $urlcontents1='http://pixlr.com/';
- $urlcontents2 = strstr($urlcontents, '_temp');
- $urlcontents_to_save=$urlcontents1.$urlcontents2;
- $contents = file_get_contents($urlcontents_to_save);//replace line 45.
- */
- //a bit title security
- $filename = addslashes(trim($filename));
- $filename = Security::remove_XSS($filename);
- $filename = api_replace_dangerous_char($filename, 'strict');
- $filename = FileManager::disable_dangerous_file($filename);
- if (strlen(trim($filename)) == 0) {
- echo "The title is empty"; //if title is empty, headers Content-Type = application/octet-stream, then not create a new title here please
- exit;
- }
- //check file_get_contents
- if ($contents === false) {
- echo "I cannot read: ".$urlcontents;
- exit;
- }
- // Extension security
- if ($extension != 'jpg' && $extension != 'png' && $extension != 'pxd') {
- die();
- }
- if ($extension == 'pxd') {
- echo "pxd file type does not supported"; // not secure because check security headers and finfo() return Content-Type = application/octet-stream
- exit;
- }
- //Verify that the file is an image. Headers method
- $headers = get_headers($urlcontents, 1);
- $content_type = explode("/", $headers['Content-Type']);
- if ($content_type[0] != "image") {
- echo "Invalid file type";
- exit;
- }
- //Verify that the file is an image. Fileinfo method
- $finfo = new finfo(FILEINFO_MIME);
- $current_mime = $finfo->buffer($contents);
- finfo_close($finfo);
- if (strpos($current_mime, 'image') === false) {
- echo "Invalid mime type file";
- exit;
- }
- //make a temporal file for get the file size
- $tmpfname = tempnam("/tmp", "CTF");
- $handle = fopen($tmpfname, "w");
- fwrite($handle, $contents);
- fclose($handle);
- // Check if there is enough space in the course to save the file
- if (!DocumentManager::enough_space(filesize($tmpfname), DocumentManager::get_course_quota())) {
- unlink($tmpfname);
- die(get_lang('UplNotEnoughSpace'));
- }
- //erase temporal file
- unlink($tmpfname);
- //path, file and title
- $paintFileName = $filename.'.'.$extension;
- $title = $title.'.'.$extension;
- if ($currentTool == 'document/createpaint') {
- //check save as and prevent rewrite an older file with same name
- if (0 != $groupId) {
- $group_properties = GroupManager :: get_group_properties($groupId);
- $groupPath = $group_properties['directory'];
- } else {
- $groupPath = '';
- }
- if (file_exists($saveDir.'/'.$filename.'.'.$extension)) {
- $i = 1;
- while (file_exists($saveDir.'/'.$filename.'_'.$i.'.'.$extension)) {
- $i++;
- }
- $paintFileName = $filename.'_'.$i.'.'.$extension;
- $title = $filename.'_'.$i.'.'.$extension;
- }
- //
- $documentPath = $saveDir.'/'.$paintFileName;
- //add new document to disk
- file_put_contents($documentPath, $contents);
- //add document to database
- $doc_id = FileManager::add_document(
- $_course,
- $relativeUrlPath.'/'.$paintFileName,
- 'file',
- filesize($documentPath),
- $title
- );
- api_item_property_update(
- $_course,
- TOOL_DOCUMENT,
- $doc_id,
- 'DocumentAdded',
- $_user['user_id'],
- $groupId,
- null,
- null,
- null,
- $current_session_id
- );
- } elseif ($currentTool == 'document/editpaint') {
- $documentPath = $saveDir.'/'.$paintFileName;
- //add new document to disk
- file_put_contents($documentPath, $contents);
- //check path
- if (!isset($_SESSION['paint_file'])) {
- api_not_allowed();
- die();
- }
- if ($_SESSION['paint_file'] == $paintFileName) {
- $document_id = DocumentManager::get_document_id($_course, $relativeUrlPath.'/'.$paintFileName);
- FileManager::update_existing_document($_course, $document_id, filesize($documentPath), null);
- api_item_property_update(
- $_course,
- TOOL_DOCUMENT,
- $document_id,
- 'DocumentUpdated',
- $_user['user_id'],
- $groupId,
- null,
- null,
- null,
- $current_session_id
- );
- } else {
- //add a new document
- $doc_id = FileManager::add_document(
- $_course,
- $relativeUrlPath.'/'.$paintFileName,
- 'file',
- filesize($documentPath),
- $title
- );
- api_item_property_update(
- $_course,
- TOOL_DOCUMENT,
- $doc_id,
- 'DocumentAdded',
- $_user['user_id'],
- $groupId,
- null,
- null,
- null,
- $current_session_id
- );
- }
- }
- //delete temporal file
- $temp_file_2delete = $_SESSION['temp_realpath_image'];
- unlink($temp_file_2delete);
- //Clean sessions and return to Chamilo file list
- unset($_SESSION['paint_dir']);
- unset($_SESSION['paint_file']);
- unset($_SESSION['whereami']);
- unset($_SESSION['temp_realpath_image']);
- if (!isset($_SESSION['exit_pixlr'])) {
- $location = api_get_path(WEB_CODE_PATH).'document/document.php';
- echo '<script>window.parent.location.href="'.$location.'"</script>';
- api_not_allowed(true);
- } else {
- echo '<div align="center" style="padding-top:150; font-family:Arial, Helvetica, Sans-serif;font-size:25px;color:#aaa;font-weight:bold;">'.get_lang(
- 'PleaseStandBy'
- ).'</div>';
- $location = api_get_path(WEB_CODE_PATH).'document/document.php?id='.Security::remove_XSS($_SESSION['exit_pixlr']);
- echo '<script>window.parent.location.href="'.$location.'"</script>';
- unset($_SESSION['exit_pixlr']);
- }
|