document.php 78 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117
  1. <?php
  2. /* For licensing terms, see /license.txt */
  3. use ChamiloSession as Session;
  4. /**
  5. * Homepage script for the documents tool
  6. *
  7. * This script allows the user to manage files and directories on a remote http
  8. * server.
  9. * The user can : - navigate through files and directories.
  10. * - upload a file
  11. * - delete, copy a file or a directory
  12. * - edit properties & content (name, comments, html content)
  13. * The script is organised in four sections.
  14. *
  15. * 1) Execute the command called by the user
  16. * Note: somme commands of this section are organised in two steps.
  17. * The script always begins with the second step,
  18. * so it allows to return more easily to the first step.
  19. *
  20. * Note (March 2004) some editing functions (renaming, commenting)
  21. * are moved to a separate page, edit_document.php. This is also
  22. * where xml and other stuff should be added.
  23. * 2) Define the directory to display
  24. * 3) Read files and directories from the directory defined in part 2
  25. * 4) Display all of that on an HTML page
  26. *
  27. * @package chamilo.document
  28. */
  29. //require_once __DIR__.'/../inc/global.inc.php';
  30. $allowDownloadDocumentsByApiKey = api_get_setting('allow_download_documents_by_api_key') === 'true';
  31. $current_course_tool = TOOL_DOCUMENT;
  32. $this_section = SECTION_COURSES;
  33. $to_user_id = null;
  34. $parent_id = null;
  35. $lib_path = api_get_path(LIBRARY_PATH);
  36. $actionsRight = '';
  37. $action = isset($_REQUEST['action']) ? $_REQUEST['action'] : null;
  38. $allowUseTool = false;
  39. if ($allowDownloadDocumentsByApiKey) {
  40. try {
  41. if ($action != 'download') {
  42. throw new Exception(get_lang('SelectAnAction'));
  43. }
  44. $username = isset($_GET['username']) ? Security::remove_XSS($_GET['username']) : null;
  45. $apiKey = isset($_GET['api_key']) ? Security::remove_XSS($_GET['api_key']) : null;
  46. $restApi = Rest::validate($username, $apiKey);
  47. $allowUseTool = $restApi ? true : false;
  48. } catch (Exception $e) {
  49. $allowUseTool = false;
  50. }
  51. }
  52. if (!$allowUseTool) {
  53. api_protect_course_script(true);
  54. api_protect_course_group(GroupManager::GROUP_TOOL_DOCUMENTS);
  55. }
  56. DocumentManager::removeGeneratedAudioTempFile();
  57. if (
  58. isset($_SESSION['temp_realpath_image']) &&
  59. !empty($_SESSION['temp_realpath_image']) &&
  60. file_exists($_SESSION['temp_realpath_image'])
  61. ) {
  62. unlink($_SESSION['temp_realpath_image']);
  63. }
  64. $_user = api_get_user_info();
  65. $courseInfo = api_get_course_info();
  66. $courseId = $courseInfo['real_id'];
  67. $course_dir = $courseInfo['directory'] . '/document';
  68. $sys_course_path = api_get_path(SYS_COURSE_PATH);
  69. $base_work_dir = $sys_course_path . $course_dir;
  70. $http_www = api_get_path(WEB_COURSE_PATH).$courseInfo['directory'] . '/document';
  71. $document_path = $base_work_dir;
  72. $usePpt2lp = api_get_setting('ppt_to_lp.active') == 'true';
  73. $course_dir = $courseInfo['directory'].'/document';
  74. $sys_course_path = api_get_path(SYS_COURSE_PATH);
  75. $base_work_dir = $sys_course_path.$course_dir;
  76. $http_www = api_get_path(WEB_COURSE_PATH).$courseInfo['directory'].'/document';
  77. $document_path = $base_work_dir;
  78. $currentUrl = api_get_self().'?'.api_get_cidreq();
  79. // Removing sessions
  80. unset($_SESSION['draw_dir']);
  81. unset($_SESSION['paint_dir']);
  82. unset($_SESSION['temp_audio_nanogong']);
  83. $plugin = new AppPlugin();
  84. $pluginList = $plugin->get_installed_plugins();
  85. $capturePluginInstalled = in_array('jcapture', $pluginList);
  86. if ($capturePluginInstalled) {
  87. $jcapturePath = api_get_path(WEB_PLUGIN_PATH).'jcapture/plugin_applet.php';
  88. $htmlHeadXtra[] = '<script>
  89. $(function() {
  90. function insertAtCarret() {
  91. }
  92. $("#jcapture").click(function(){
  93. $("#appletplace").load("'.$jcapturePath.'");
  94. });
  95. });
  96. </script>';
  97. }
  98. // Create directory certificates.
  99. DocumentManager::create_directory_certificate_in_course(api_get_course_id());
  100. if (empty($courseInfo)) {
  101. api_not_allowed(true);
  102. }
  103. // Used for avoiding double-click.
  104. $dbl_click_id = 0;
  105. $selectcat = isset($_GET['selectcat']) ? Security::remove_XSS($_GET['selectcat']) : null;
  106. $moveTo = isset($_POST['move_to']) ? Security::remove_XSS($_POST['move_to']) : null;
  107. /* Constants and variables */
  108. $userId = api_get_user_id();
  109. $userInfo = api_get_user_info();
  110. $sessionId = api_get_session_id();
  111. $course_code = api_get_course_id();
  112. $groupId = api_get_group_id();
  113. $is_allowed_to_edit = api_is_allowed_to_edit(null, true);
  114. $group_member_with_upload_rights = false;
  115. // If the group id is set, we show them group documents
  116. $group_properties = array();
  117. $group_properties['directory'] = null;
  118. // For sessions we should check the parameters of visibility
  119. if (api_get_session_id() != 0) {
  120. $group_member_with_upload_rights = $group_member_with_upload_rights && api_is_allowed_to_session_edit(false, true);
  121. }
  122. $group_properties = GroupManager::get_group_properties($groupId);
  123. $groupIid = isset($group_properties['iid']) ? $group_properties['iid'] : 0;
  124. $groupMemberWithEditRights = $is_allowed_to_edit || GroupManager::is_tutor_of_group($userId, $group_properties['iid'], $courseId);
  125. // Setting group variables.
  126. if (!empty($groupId)) {
  127. // Get group info
  128. // Let's assume the user cannot upload files for the group
  129. $group_member_with_upload_rights = false;
  130. if ($group_properties['doc_state'] == 2) {
  131. // Documents are private
  132. if ($is_allowed_to_edit || GroupManager::is_user_in_group($userId, $group_properties['iid'])) {
  133. // Only courseadmin or group members (members + tutors) allowed
  134. $interbreadcrumb[] = array(
  135. 'url' => api_get_path(WEB_CODE_PATH).'group/group.php?'.api_get_cidreq(),
  136. 'name' => get_lang('Groups')
  137. );
  138. $interbreadcrumb[] = array(
  139. 'url' => api_get_path(WEB_CODE_PATH).'group/group_space.php?'.api_get_cidreq(),
  140. 'name' => get_lang('GroupSpace').' '.$group_properties['name']
  141. );
  142. //they are allowed to upload
  143. $group_member_with_upload_rights = true;
  144. } else {
  145. $groupId = 0;
  146. }
  147. } elseif ($group_properties['doc_state'] == 1) {
  148. // Documents are public
  149. $interbreadcrumb[] = array(
  150. 'url' => api_get_path(WEB_CODE_PATH).'group/group.php?'.api_get_cidreq(),
  151. 'name' => get_lang('Groups')
  152. );
  153. $interbreadcrumb[] = array(
  154. 'url' => api_get_path(WEB_CODE_PATH).'group/group_space.php?'.api_get_cidreq(),
  155. 'name' => get_lang('GroupSpace').' '.$group_properties['name']
  156. );
  157. // Allowed to upload?
  158. if ($is_allowed_to_edit ||
  159. GroupManager::is_subscribed($userId, $group_properties['iid']) ||
  160. GroupManager::is_tutor_of_group($userId, $group_properties['iid'], $courseId)
  161. ) {
  162. // Only course admin or group members can upload
  163. $group_member_with_upload_rights = true;
  164. }
  165. }
  166. Session::write(
  167. 'group_member_with_upload_rights',
  168. $group_member_with_upload_rights
  169. );
  170. } else {
  171. Session::write('group_member_with_upload_rights', false);
  172. }
  173. // Actions.
  174. $document_id = isset($_REQUEST['id']) ? intval($_REQUEST['id']) : null;
  175. $currentUrl = api_get_self().'?'.api_get_cidreq().'&id='.$document_id;
  176. if (Portfolio::controller()->accept()) {
  177. Portfolio::controller()->run();
  178. }
  179. $curdirpath = isset($_GET['curdirpath']) ? Security::remove_XSS($_GET['curdirpath']) : null;
  180. switch ($action) {
  181. case 'delete_item':
  182. if ($is_allowed_to_edit ||
  183. $group_member_with_upload_rights ||
  184. DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId) ||
  185. DocumentManager::is_my_shared_folder(api_get_user_id(), $moveTo, $sessionId)
  186. ) {
  187. if (isset($_GET['deleteid'])) {
  188. if (!$is_allowed_to_edit) {
  189. if (api_is_coach()) {
  190. if (!DocumentManager::is_visible_by_id(
  191. $_GET['deleteid'],
  192. $courseInfo,
  193. $sessionId,
  194. api_get_user_id()
  195. )
  196. ) {
  197. api_not_allowed();
  198. }
  199. }
  200. if (DocumentManager::check_readonly(
  201. $courseInfo,
  202. api_get_user_id(),
  203. '',
  204. $_GET['deleteid'],
  205. true
  206. )
  207. ) {
  208. api_not_allowed();
  209. }
  210. }
  211. $documentInfo = DocumentManager::get_document_data_by_id(
  212. $_GET['deleteid'],
  213. $courseInfo['code'],
  214. false,
  215. $sessionId
  216. );
  217. // Check whether the document is in the database.
  218. if (!empty($documentInfo)) {
  219. $deleteDocument = DocumentManager::delete_document(
  220. $courseInfo,
  221. null,
  222. $base_work_dir,
  223. $sessionId,
  224. $_GET['deleteid'],
  225. $groupIid
  226. );
  227. if ($deleteDocument) {
  228. $certificateId = isset($_GET['delete_certificate_id']) ? $_GET['delete_certificate_id'] : null;
  229. DocumentManager::remove_attach_certificate(
  230. api_get_course_id(),
  231. $certificateId
  232. );
  233. Display::addFlash(Display::return_message(
  234. get_lang('DocDeleted') . ': ' . $documentInfo['title'],
  235. 'success'
  236. ));
  237. } else {
  238. Display::addFlash(Display::return_message(get_lang('DocDeleteError'), 'warning'));
  239. }
  240. } else {
  241. Display::addFlash(Display::return_message(get_lang('FileNotFound'), 'warning'));
  242. }
  243. header("Location: $currentUrl");
  244. exit;
  245. }
  246. }
  247. break;
  248. case 'download':
  249. // Get the document data from the ID
  250. $document_data = DocumentManager::get_document_data_by_id(
  251. $document_id,
  252. api_get_course_id(),
  253. false,
  254. $sessionId
  255. );
  256. if ($sessionId != 0 && !$document_data) {
  257. // If there is a session defined and asking for the document *from
  258. // the session* didn't work, try it from the course (out of a
  259. // session context)
  260. $document_data = DocumentManager::get_document_data_by_id(
  261. $document_id,
  262. api_get_course_id(),
  263. false,
  264. 0
  265. );
  266. }
  267. // Check whether the document is in the database
  268. if (empty($document_data)) {
  269. api_not_allowed();
  270. }
  271. // Launch event
  272. Event::event_download($document_data['url']);
  273. // Check visibility of document and paths
  274. if (!($is_allowed_to_edit || $group_member_with_upload_rights)
  275. && !DocumentManager::is_visible_by_id($document_id, $courseInfo, $sessionId, api_get_user_id())) {
  276. api_not_allowed(true);
  277. }
  278. $full_file_name = $base_work_dir.$document_data['path'];
  279. if (Security::check_abs_path($full_file_name, $base_work_dir.'/')) {
  280. $result = DocumentManager::file_send_for_download($full_file_name, true);
  281. if ($result === false) {
  282. api_not_allowed(true);
  283. }
  284. }
  285. exit;
  286. break;
  287. case 'downloadfolder':
  288. if (api_get_setting('document.students_download_folders') == 'true'
  289. || api_is_allowed_to_edit()
  290. || api_is_platform_admin()
  291. ) {
  292. // Get the document data from the ID
  293. $document_data = DocumentManager::get_document_data_by_id(
  294. $document_id,
  295. api_get_course_id(),
  296. false,
  297. $sessionId
  298. );
  299. if ($sessionId != 0 && !$document_data) {
  300. // If there is a session defined and asking for the
  301. // document * from the session* didn't work, try it from the
  302. // course (out of a session context)
  303. $document_data = DocumentManager::get_document_data_by_id(
  304. $document_id,
  305. api_get_course_id(),
  306. false,
  307. 0
  308. );
  309. }
  310. //filter when I am into shared folder, I can download only my shared folder
  311. if (DocumentManager::is_any_user_shared_folder($document_data['path'], $sessionId)) {
  312. if (DocumentManager::is_my_shared_folder(api_get_user_id(), $document_data['path'], $sessionId)
  313. || api_is_allowed_to_edit()
  314. || api_is_platform_admin()) {
  315. require 'downloadfolder.inc.php';
  316. }
  317. } else {
  318. require 'downloadfolder.inc.php';
  319. }
  320. // Launch event
  321. Event::event_download($document_data['url']);
  322. exit;
  323. }
  324. break;
  325. case 'export_to_pdf':
  326. if (api_get_setting('document.students_export2pdf') == 'true' || api_is_allowed_to_edit() || api_is_platform_admin()) {
  327. DocumentManager::export_to_pdf($document_id, $course_code);
  328. }
  329. break;
  330. case 'copytomyfiles':
  331. // Copy a file to general my files user's
  332. if (api_get_setting('social.allow_social_tool') == 'true' &&
  333. api_get_setting('document.users_copy_files') == 'true'
  334. && api_get_user_id() != 0
  335. && !api_is_anonymous()
  336. ) {
  337. // Get the document data from the ID
  338. $document_info = DocumentManager::get_document_data_by_id(
  339. $document_id,
  340. api_get_course_id(),
  341. true,
  342. $sessionId
  343. );
  344. if ($sessionId != 0 && !$document_info) {
  345. /* If there is a session defined and asking for the document
  346. from the session didn't work, try it from the course
  347. (out of a session context)*/
  348. $document_info = DocumentManager::get_document_data_by_id(
  349. $document_id,
  350. api_get_course_id(),
  351. 0
  352. );
  353. }
  354. $parent_id = $document_info['parent_id'];
  355. $my_path = UserManager::getUserPathById(api_get_user_id(), 'system');
  356. $user_folder = $my_path.'my_files/';
  357. $my_path = null;
  358. if (!file_exists($user_folder)) {
  359. $perm = api_get_permissions_for_new_directories();
  360. @mkdir($user_folder, $perm, true);
  361. }
  362. $file = $sys_course_path.$courseInfo['directory'].'/document'.$document_info['path'];
  363. $copyfile = $user_folder.basename($document_info['path']);
  364. $cidReq = Security::remove_XSS($_GET['cidReq']);
  365. $id_session = Security::remove_XSS($_GET['id_session']);
  366. $gidReq = Security::remove_XSS($_GET['gidReq']);
  367. $id = Security::remove_XSS($_GET['id']);
  368. if (empty($parent_id)) {
  369. $parent_id = 0;
  370. }
  371. $file_link = Display::url(
  372. get_lang('SeeFile'),
  373. api_get_path(WEB_CODE_PATH).'social/myfiles.php?'.api_get_cidreq_params($cidReq, $id_session, $gidReq).
  374. '&parent_id='.$parent_id
  375. );
  376. if (api_get_setting('platform.allow_my_files') === 'false') {
  377. $file_link = '';
  378. }
  379. if (file_exists($copyfile)) {
  380. $message = get_lang('CopyAlreadyDone').'</p><p>';
  381. $message .= '<a class = "btn btn-default" '.
  382. 'href="'.api_get_self().'?'.api_get_cidreq().'&amp;id='.$parent_id.'">'.
  383. get_lang("No").
  384. '</a>'.
  385. '&nbsp;&nbsp;|&nbsp;&nbsp;'.
  386. '<a class = "btn btn-default" href="'.api_get_self().'?'.
  387. api_get_cidreq().'&amp;action=copytomyfiles&amp;id='.$document_info['id'].
  388. '&amp;copy=yes">'.
  389. get_lang('Yes').
  390. '</a></p>';
  391. if (!isset($_GET['copy'])) {
  392. Display::addFlash(Display::return_message($message, 'warning', false));
  393. }
  394. if ($_GET['copy'] === 'yes') {
  395. if (!copy($file, $copyfile)) {
  396. Display::addFlash(Display::return_message(get_lang('CopyFailed'), 'error'));
  397. } else {
  398. Display::addFlash(Display::return_message(
  399. get_lang('OverwritenFile').' '.$file_link,
  400. 'confirmation',
  401. false
  402. ));
  403. }
  404. }
  405. } else {
  406. if (!copy($file, $copyfile)) {
  407. Display::addFlash(Display::return_message(get_lang('CopyFailed'), 'error'));
  408. } else {
  409. Display::addFlash(
  410. Display::return_message(get_lang('CopyMade').' '.$file_link, 'confirmation', false)
  411. );
  412. }
  413. }
  414. }
  415. break;
  416. case 'convertToPdf':
  417. // PDF format as target by default
  418. $formatTarget = $_REQUEST['formatTarget'] ?
  419. strtolower(Security::remove_XSS($_REQUEST['formatTarget'])) :
  420. 'pdf';
  421. $formatType = $_REQUEST['formatType'] ?
  422. strtolower(Security::remove_XSS($_REQUEST['formatType'])) :
  423. 'text';
  424. // Get the document data from the ID
  425. $document_info = DocumentManager::get_document_data_by_id(
  426. $document_id,
  427. api_get_course_id(),
  428. true,
  429. $session_id
  430. );
  431. $file = $sys_course_path . $courseInfo['directory'] .
  432. '/document' . $document_info['path'];
  433. $fileInfo = pathinfo($file);
  434. if ($fileInfo['extension'] == $formatTarget) {
  435. Display::addFlash(Display::return_message(
  436. get_lang('ConversionToSameFileFormat'),
  437. 'warning'
  438. ));
  439. } elseif (
  440. !(
  441. in_array(
  442. $fileInfo['extension'],
  443. DocumentManager::getJodconverterExtensionList(
  444. 'from',
  445. $formatType
  446. )
  447. )
  448. ) || !(
  449. in_array(
  450. $formatTarget,
  451. DocumentManager::getJodconverterExtensionList(
  452. 'to',
  453. $formatType
  454. )
  455. )
  456. )
  457. ) {
  458. Display::addFlash(Display::return_message(
  459. get_lang('FileFormatNotSupported'),
  460. 'warning'
  461. ));
  462. } else {
  463. $convertedFile = $fileInfo['dirname'] . DIRECTORY_SEPARATOR .
  464. $fileInfo['filename'] . '_from_' . $fileInfo['extension'] .
  465. '.' . $formatTarget;
  466. $convertedTitle = $document_info['title'];
  467. $obj = new OpenofficePresentation(true);
  468. if (file_exists($convertedFile)) {
  469. Display::addFlash(Display::return_message(
  470. get_lang('FileExists'),
  471. 'error'
  472. ));
  473. } else {
  474. $result = $obj->convertCopyDocument(
  475. $file,
  476. $convertedFile,
  477. $convertedTitle
  478. );
  479. if (empty($result)) {
  480. Display::addFlash(Display::return_message(
  481. get_lang('CopyFailed'),
  482. 'error'
  483. ));
  484. } else {
  485. $cidReq = Security::remove_XSS($_GET['cidReq']);
  486. $id_session = api_get_session_id();
  487. $gidReq = Security::remove_XSS($_GET['gidReq']);
  488. $file_link = Display::url(
  489. get_lang('SeeFile'),
  490. api_get_path(WEB_CODE_PATH) .
  491. 'document/showinframes.php?'.api_get_cidreq_params($cidReq, $id_session, $gidReq).'&id=' . current($result)
  492. );
  493. Display::addFlash(Display::return_message(
  494. get_lang('CopyMade') . ' ' . $file_link,
  495. 'confirmation',
  496. false
  497. ));
  498. }
  499. }
  500. }
  501. break;
  502. }
  503. // I'm in the certification module?
  504. $is_certificate_mode = false;
  505. if (isset($_GET['curdirpath'])) {
  506. $is_certificate_mode = DocumentManager::is_certificate_mode($_GET['curdirpath']);
  507. }
  508. if (isset($_REQUEST['certificate']) && $_REQUEST['certificate'] == 'true') {
  509. $is_certificate_mode = true;
  510. }
  511. // If no actions we proceed to show the document (Hack in order to use document.php?id=X)
  512. if (isset($document_id) && empty($action)) {
  513. // Get the document data from the ID
  514. $document_data = DocumentManager::get_document_data_by_id(
  515. $document_id,
  516. api_get_course_id(),
  517. true,
  518. $sessionId
  519. );
  520. if ($sessionId != 0 && !$document_data) {
  521. // If there is a session defined and asking for the
  522. // document * from the session* didn't work, try it from the course
  523. // (out of a session context)
  524. $document_data = DocumentManager::get_document_data_by_id(
  525. $document_id,
  526. api_get_course_id(),
  527. true,
  528. 0
  529. );
  530. }
  531. // If the document is not a folder we show the document.
  532. if ($document_data) {
  533. $parent_id = $document_data['parent_id'];
  534. $visibility = DocumentManager::check_visibility_tree(
  535. $document_id,
  536. api_get_course_id(),
  537. $sessionId,
  538. api_get_user_id(),
  539. $groupIid
  540. );
  541. if (!empty($document_data['filetype']) && $document_data['filetype'] == 'file') {
  542. if ($visibility && api_is_allowed_to_session_edit()) {
  543. $url = api_get_path(WEB_COURSE_PATH).
  544. $courseInfo['path'].'/document'.$document_data['path'].'?'
  545. .api_get_cidreq();
  546. header("Location: $url");
  547. }
  548. exit;
  549. } else {
  550. if (!$visibility && !api_is_allowed_to_edit()) {
  551. api_not_allowed();
  552. }
  553. }
  554. $_GET['curdirpath'] = $document_data['path'];
  555. }
  556. // What's the current path?
  557. // We will verify this a bit further down
  558. if (isset($_GET['curdirpath']) && $_GET['curdirpath'] != '') {
  559. $curdirpath = Security::remove_XSS($_GET['curdirpath']);
  560. } elseif (isset($_POST['curdirpath']) && $_POST['curdirpath'] != '') {
  561. $curdirpath = Security::remove_XSS($_POST['curdirpath']);
  562. } else {
  563. $curdirpath = '/';
  564. }
  565. $curdirpathurl = urlencode($curdirpath);
  566. } else {
  567. // What's the current path?
  568. // We will verify this a bit further down
  569. if (isset($_GET['curdirpath']) && $_GET['curdirpath'] != '') {
  570. $curdirpath = Security::remove_XSS($_GET['curdirpath']);
  571. } elseif (isset($_POST['curdirpath']) && $_POST['curdirpath'] != '') {
  572. $curdirpath = Security::remove_XSS($_POST['curdirpath']);
  573. } else {
  574. $curdirpath = '/';
  575. }
  576. $curdirpathurl = urlencode($curdirpath);
  577. // Check the path
  578. // If the path is not found (no document id), set the path to /
  579. $document_id = DocumentManager::get_document_id($courseInfo, $curdirpath);
  580. if (!$document_id) {
  581. $document_id = DocumentManager::get_document_id($courseInfo, $curdirpath, 0);
  582. }
  583. $document_data = DocumentManager::get_document_data_by_id(
  584. $document_id,
  585. api_get_course_id(),
  586. true
  587. );
  588. $parent_id = $document_data['parent_id'];
  589. }
  590. if (isset($document_data) && $document_data['path'] == '/certificates') {
  591. $is_certificate_mode = true;
  592. }
  593. if (!$parent_id) {
  594. $parent_id = 0;
  595. }
  596. $current_folder_id = $document_id;
  597. // Show preview
  598. if (isset($_GET['curdirpath']) &&
  599. $_GET['curdirpath'] == '/certificates' &&
  600. isset($_GET['set_preview']) &&
  601. $_GET['set_preview'] == strval(intval($_GET['set_preview']))
  602. ) {
  603. if (isset($_GET['set_preview'])) {
  604. // Generate document HTML
  605. $content_html = DocumentManager::replace_user_info_into_html(
  606. api_get_user_id(),
  607. api_get_course_id(),
  608. api_get_session_id(),
  609. true
  610. );
  611. $filename = 'certificate_preview/'.api_get_unique_id().'.png';
  612. $qr_code_filename = api_get_path(SYS_ARCHIVE_PATH).$filename;
  613. $temp_folder = api_get_path(SYS_ARCHIVE_PATH).'certificate_preview';
  614. if (!is_dir($temp_folder)) {
  615. mkdir($temp_folder, api_get_permissions_for_new_directories());
  616. }
  617. $qr_code_web_filename = api_get_path(WEB_ARCHIVE_PATH).$filename;
  618. $certificate = new Certificate();
  619. $text = $certificate->parse_certificate_variables($content_html['variables']);
  620. $result = $certificate->generate_qr($text, $qr_code_filename);
  621. $new_content_html = $content_html['content'];
  622. $path_image = api_get_path(WEB_COURSE_PATH).api_get_course_path().'/document/images/gallery';
  623. $new_content_html = str_replace('../images/gallery', $path_image, $new_content_html);
  624. $path_image_in_default_course = api_get_path(WEB_CODE_PATH).'default_course_document';
  625. $new_content_html = str_replace(
  626. '/main/default_course_document',
  627. $path_image_in_default_course,
  628. $new_content_html
  629. );
  630. $new_content_html = str_replace(
  631. SYS_CODE_PATH . 'img/',
  632. api_get_path(WEB_IMG_PATH),
  633. $new_content_html
  634. );
  635. Display::display_reduced_header();
  636. echo '<style>body {background:none;}</style>
  637. <style media="print" type="text/css"> #print_div { visibility:hidden; } </style>';
  638. echo '<a href="javascript:window.print();" style="float:right; padding:4px;" id="print_div">';
  639. echo Display::return_icon('printmgr.gif', get_lang('Print'));
  640. echo '</a>';
  641. if (is_file($qr_code_filename) && is_readable($qr_code_filename)) {
  642. $new_content_html = str_replace(
  643. '((certificate_barcode))',
  644. Display::img($qr_code_web_filename),
  645. $new_content_html
  646. );
  647. }
  648. print_r($new_content_html);
  649. exit;
  650. }
  651. }
  652. // Is the document tool visible?
  653. // Check whether the tool is actually visible
  654. /*$table_course_tool = Database::get_course_table(TABLE_TOOL_LIST);
  655. $course_id = api_get_course_int_id();
  656. $tool_sql = 'SELECT visibility FROM '.$table_course_tool.'
  657. WHERE c_id = '.$course_id.' AND name = "'.TOOL_DOCUMENT.'"
  658. LIMIT 1';
  659. $tool_result = Database::query($tool_sql);
  660. $tool_row = Database::fetch_array($tool_result);
  661. $tool_visibility = $tool_row['visibility'];*/
  662. $htmlHeadXtra[] = '<script>
  663. function confirmation (name) {
  664. if (confirm(" '.get_lang('AreYouSureToDeleteJS').' "+ name + " ?")) {
  665. return true;
  666. } else {
  667. return false;
  668. }
  669. }
  670. $(document).ready(function() {
  671. $(".convertAction").click(function() {
  672. var id = $(this).attr("data-documentId");
  673. var format = $(this).attr("data-formatType");
  674. convertModal(id, format);
  675. });
  676. });
  677. function convertModal (id, format) {
  678. $("#convertModal").modal("show");
  679. $("." + format + "FormatType").show();
  680. $("#convertSelect").change(function() {
  681. var formatTarget = $(this).val();
  682. window.location.href = "'.
  683. api_get_self() . '?' . api_get_cidreq() .
  684. '&curdirpath=' . $curdirpath .
  685. '&action=convertToPdf&formatTarget=' .
  686. '" + formatTarget + "&id=" + id + "&' .
  687. api_get_cidreq() . '&formatType=" + format;
  688. });
  689. $("#convertModal").on("hidden", function(){
  690. $("." + format + "FormatType").hide();
  691. });
  692. }
  693. </script>';
  694. // If they are looking at group documents they can't see the root
  695. if ($groupId != 0 && $curdirpath == '/') {
  696. $curdirpath = $group_properties['directory'];
  697. $curdirpathurl = urlencode($group_properties['directory']);
  698. }
  699. // Check visibility of the current dir path. Don't show anything if not allowed
  700. //@todo check this validation for coaches
  701. //if (!$is_allowed_to_edit || api_is_coach()) { before
  702. if (!$is_allowed_to_edit && api_is_coach()) {
  703. if ($curdirpath != '/' && !(DocumentManager::is_visible($curdirpath, $courseInfo, $sessionId, 'folder'))) {
  704. api_not_allowed(true);
  705. }
  706. }
  707. /* Create shared folders */
  708. if ($sessionId == 0) {
  709. //Create shared folder. Necessary for recycled courses.
  710. // session_id should always be zero and should always be created from a
  711. // base course, never from a session.
  712. if (!file_exists($base_work_dir.'/shared_folder')) {
  713. $usf_dir_title = get_lang('UserFolders');
  714. $usf_dir_name = '/shared_folder';
  715. //$groupId = 0;
  716. $visibility = 0;
  717. create_unexisting_directory(
  718. $courseInfo,
  719. api_get_user_id(),
  720. $sessionId,
  721. 0,
  722. $to_user_id,
  723. $base_work_dir,
  724. $usf_dir_name,
  725. $usf_dir_title,
  726. $visibility
  727. );
  728. }
  729. // Create dynamic user shared folder
  730. if (!file_exists($base_work_dir.'/shared_folder/sf_user_'.$userId)) {
  731. $usf_dir_title = $userInfo['complete_name'];
  732. $usf_dir_name = '/shared_folder/sf_user_'.$userId;
  733. //$groupId = 0;
  734. $visibility = 1;
  735. create_unexisting_directory(
  736. $courseInfo,
  737. api_get_user_id(),
  738. $sessionId,
  739. 0,
  740. $to_user_id,
  741. $base_work_dir,
  742. $usf_dir_name,
  743. $usf_dir_title,
  744. $visibility
  745. );
  746. }
  747. } else {
  748. // Create shared folder session.
  749. if (!file_exists($base_work_dir.'/shared_folder_session_'.$sessionId)) {
  750. $usf_dir_title = get_lang('UserFolders').' ('.api_get_session_name($sessionId).')';
  751. $usf_dir_name = '/shared_folder_session_'.$sessionId;
  752. //$groupId = 0;
  753. $visibility = 0;
  754. create_unexisting_directory(
  755. $courseInfo,
  756. api_get_user_id(),
  757. $sessionId,
  758. 0,
  759. $to_user_id,
  760. $base_work_dir,
  761. $usf_dir_name,
  762. $usf_dir_title,
  763. $visibility
  764. );
  765. }
  766. //Create dynamic user shared folder into a shared folder session
  767. if (!file_exists($base_work_dir.'/shared_folder_session_'.$sessionId.'/sf_user_'.$userId)) {
  768. $usf_dir_title = $userInfo['complete_name'].'('.api_get_session_name($sessionId).')';
  769. $usf_dir_name = '/shared_folder_session_'.$sessionId.'/sf_user_'.$userId;
  770. //$groupId = 0;
  771. $visibility = 1;
  772. create_unexisting_directory(
  773. $courseInfo,
  774. $userId,
  775. $sessionId,
  776. 0,
  777. $to_user_id,
  778. $base_work_dir,
  779. $usf_dir_name,
  780. $usf_dir_title,
  781. $visibility
  782. );
  783. }
  784. }
  785. /* MAIN SECTION */
  786. // Slideshow inititalisation
  787. $_SESSION['image_files_only'] = '';
  788. $image_files_only = '';
  789. if ($is_certificate_mode) {
  790. $interbreadcrumb[] = array('url' => '../gradebook/index.php', 'name' => get_lang('Gradebook'));
  791. } else {
  792. if ((isset($_GET['id']) && $_GET['id'] != 0) || isset($_GET['curdirpath']) || isset($_GET['createdir'])) {
  793. $interbreadcrumb[] = array('url' => 'document.php', 'name' => get_lang('Documents'));
  794. } else {
  795. $interbreadcrumb[] = array('url' => '#', 'name' => get_lang('Documents'));
  796. }
  797. }
  798. // Interbreadcrumb for the current directory root path
  799. if (empty($document_data['parents'])) {
  800. if (isset($_GET['createdir'])) {
  801. $interbreadcrumb[] = array(
  802. 'url' => $document_data['document_url'],
  803. 'name' => $document_data['title'],
  804. );
  805. } else {
  806. $interbreadcrumb[] = array('url' => '#', 'name' => $document_data['title']);
  807. }
  808. } else {
  809. $counter = 0;
  810. foreach ($document_data['parents'] as $document_sub_data) {
  811. //fixing double group folder in breadcrumb
  812. if ($groupId) {
  813. if ($counter == 0) {
  814. $counter++;
  815. continue;
  816. }
  817. }
  818. if (!isset($_GET['createdir']) && $document_sub_data['id'] == $document_data['id']) {
  819. $document_sub_data['document_url'] = '#';
  820. }
  821. $interbreadcrumb[] = array(
  822. 'url' => $document_sub_data['document_url'],
  823. 'name' => $document_sub_data['title'],
  824. );
  825. $counter++;
  826. }
  827. }
  828. if (isset($_GET['createdir'])) {
  829. $interbreadcrumb[] = array('url' => '#', 'name' => get_lang('CreateDir'));
  830. }
  831. $js_path = api_get_path(WEB_LIBRARY_PATH).'javascript/';
  832. $htmlHeadXtra[] = '<link rel="stylesheet" href="'.$js_path.'jquery-jplayer/skin/chamilo/jplayer.blue.monday.css" type="text/css">';
  833. $htmlHeadXtra[] = '<script type="text/javascript" src="'.$js_path.'jquery-jplayer/jplayer/jquery.jplayer.min.js"></script>';
  834. $mediaplayer_path = api_get_path(WEB_LIBRARY_PATH).'mediaplayer/player.swf';
  835. $documentAndFolders = DocumentManager::get_all_document_data(
  836. $courseInfo,
  837. $curdirpath,
  838. $groupIid,
  839. null,
  840. $is_allowed_to_edit || $group_member_with_upload_rights,
  841. false
  842. );
  843. $count = 1;
  844. $jquery = null;
  845. if (!empty($documentAndFolders)) {
  846. foreach ($documentAndFolders as $file) {
  847. if ($file['filetype'] == 'file') {
  848. $path_info = pathinfo($file['path']);
  849. $extension = '';
  850. if (!empty($path_info['extension'])) {
  851. $extension = strtolower($path_info['extension']);
  852. }
  853. //@todo use a js loop to auto generate this code
  854. if (in_array($extension, array('ogg', 'mp3', 'wav'))) {
  855. // Get the document data from the ID
  856. $document_data = DocumentManager::get_document_data_by_id(
  857. $file['id'],
  858. api_get_course_id(),
  859. false,
  860. $sessionId
  861. );
  862. if ($sessionId != 0 && !$document_data) {
  863. /* If there is a session defined and asking for the document
  864. * from the session* didn't work, try it from the
  865. course (out of a session context) */
  866. $document_data = DocumentManager::get_document_data_by_id(
  867. $file['id'],
  868. api_get_course_id(),
  869. false,
  870. 0
  871. );
  872. }
  873. if ($extension == 'ogg') {
  874. $extension = 'oga';
  875. }
  876. $params = array('url' => $document_data['direct_url'],
  877. 'extension' => $extension,
  878. 'count' => $count
  879. );
  880. $jquery .= DocumentManager::generate_jplayer_jquery($params);
  881. $count++;
  882. }
  883. }
  884. }
  885. }
  886. $htmlHeadXtra[] = '<script>
  887. $(document).ready( function() {
  888. //Experimental changes to preview mp3, ogg files
  889. '.$jquery.'
  890. });
  891. </script>';
  892. // Lib for event log, stats & tracking & record of the access
  893. Event::event_access_tool(TOOL_DOCUMENT);
  894. /* DISPLAY */
  895. if ($groupId != 0) { // Add group name after for group documents
  896. $add_group_to_title = ' ('.$group_properties['name'].')';
  897. }
  898. $moveForm = '';
  899. /* MOVE FILE OR DIRECTORY */
  900. //Only teacher and all users into their group and each user into his/her shared folder
  901. if ($is_allowed_to_edit ||
  902. $group_member_with_upload_rights ||
  903. DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId) ||
  904. DocumentManager::is_my_shared_folder(api_get_user_id(), $moveTo, $sessionId)
  905. ) {
  906. if (isset($_GET['move']) && $_GET['move'] != '') {
  907. $my_get_move = intval($_REQUEST['move']);
  908. if (api_is_coach()) {
  909. if (!DocumentManager::is_visible_by_id($my_get_move, $courseInfo, $sessionId, api_get_user_id())) {
  910. api_not_allowed(true);
  911. }
  912. }
  913. if (!$is_allowed_to_edit) {
  914. if (DocumentManager::check_readonly($courseInfo, api_get_user_id(), $my_get_move)) {
  915. api_not_allowed(true);
  916. }
  917. }
  918. // Get the document data from the ID
  919. $document_to_move = DocumentManager::get_document_data_by_id(
  920. $my_get_move,
  921. api_get_course_id(),
  922. false,
  923. $sessionId
  924. );
  925. $move_path = $document_to_move['path'];
  926. if (!empty($document_to_move)) {
  927. $folders = DocumentManager::get_all_document_folders(
  928. $courseInfo,
  929. $groupIid,
  930. $is_allowed_to_edit || $group_member_with_upload_rights
  931. );
  932. // filter if is my shared folder. TODO: move this code to build_move_to_selector function
  933. if (DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId) &&
  934. !$is_allowed_to_edit
  935. ) {
  936. //only main user shared folder
  937. $main_user_shared_folder_main = '/shared_folder/sf_user_'.api_get_user_id();
  938. $main_user_shared_folder_sub = '/shared_folder\/sf_user_'.api_get_user_id().'\//'; //all subfolders
  939. $user_shared_folders = array();
  940. foreach ($folders as $fold) {
  941. if ($main_user_shared_folder_main == $fold || preg_match($main_user_shared_folder_sub, $fold)) {
  942. $user_shared_folders[] = $fold;
  943. }
  944. }
  945. $moveForm .= '<legend>'.get_lang('Move').'</legend>';
  946. $moveForm .= DocumentManager::build_move_to_selector(
  947. $user_shared_folders,
  948. $move_path,
  949. $my_get_move,
  950. $group_properties['directory']
  951. );
  952. } else {
  953. $moveForm .= '<legend>'.get_lang('Move').'</legend>';
  954. $moveForm .= DocumentManager::build_move_to_selector(
  955. $folders,
  956. $move_path,
  957. $my_get_move,
  958. $group_properties['directory']
  959. );
  960. }
  961. }
  962. }
  963. if (!empty($moveTo) && isset($_POST['move_file'])) {
  964. if (!$is_allowed_to_edit) {
  965. if (DocumentManager::check_readonly($courseInfo, api_get_user_id(), $_POST['move_file'])) {
  966. api_not_allowed(true);
  967. }
  968. }
  969. if (api_is_coach()) {
  970. if (!DocumentManager::is_visible_by_id($_POST['move_file'], $courseInfo, $sessionId, api_get_user_id())) {
  971. api_not_allowed(true);
  972. }
  973. }
  974. // Get the document data from the ID
  975. $document_to_move = DocumentManager::get_document_data_by_id(
  976. $_POST['move_file'],
  977. api_get_course_id(),
  978. false,
  979. $sessionId
  980. );
  981. // Security fix: make sure they can't move files that are not in the document table
  982. if (!empty($document_to_move)) {
  983. $real_path_target = $base_work_dir.$moveTo.'/'.basename($document_to_move['path']);
  984. $fileExist = false;
  985. if (file_exists($real_path_target)) {
  986. $fileExist = true;
  987. }
  988. if (move($base_work_dir.$document_to_move['path'], $base_work_dir.$moveTo)) {
  989. DocumentManager::updateDbInfo(
  990. 'update',
  991. $document_to_move['path'],
  992. $moveTo . '/' . basename($document_to_move['path'])
  993. );
  994. //update database item property
  995. $doc_id = $_POST['move_file'];
  996. if (is_dir($real_path_target)) {
  997. api_item_property_update(
  998. $courseInfo,
  999. TOOL_DOCUMENT,
  1000. $doc_id,
  1001. 'FolderMoved',
  1002. api_get_user_id(),
  1003. $groupIid,
  1004. null,
  1005. null,
  1006. null,
  1007. $sessionId
  1008. );
  1009. Display::addFlash(Display::return_message(get_lang('DirMv'), 'confirmation'));
  1010. } elseif (is_file($real_path_target)) {
  1011. api_item_property_update(
  1012. $courseInfo,
  1013. TOOL_DOCUMENT,
  1014. $doc_id,
  1015. 'DocumentMoved',
  1016. api_get_user_id(),
  1017. $groupIid,
  1018. null,
  1019. null,
  1020. null,
  1021. $sessionId
  1022. );
  1023. Display::addFlash(Display::return_message(get_lang('DocMv'), 'confirmation'));
  1024. }
  1025. // Set the current path
  1026. $curdirpath = $_POST['move_to'];
  1027. $curdirpathurl = urlencode($_POST['move_to']);
  1028. } else {
  1029. if ($fileExist) {
  1030. if (is_dir($real_path_target)) {
  1031. $message = Display::return_message(get_lang('DirExists'), 'error');
  1032. } elseif (is_file($real_path_target)) {
  1033. $message = Display::return_message(get_lang('FileExists'), 'v');
  1034. }
  1035. Display::addFlash($message);
  1036. } else {
  1037. Display::addFlash(Display::return_message(get_lang('Impossible'), 'error'));
  1038. }
  1039. }
  1040. } else {
  1041. Display::addFlash(Display::return_message(get_lang('Impossible'), 'error'));
  1042. }
  1043. }
  1044. }
  1045. /* DELETE FILE OR DIRECTORY */
  1046. //Only teacher and all users into their group
  1047. if ($is_allowed_to_edit ||
  1048. $group_member_with_upload_rights ||
  1049. DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId)
  1050. ) {
  1051. if (isset($_POST['action']) && isset($_POST['ids'])) {
  1052. $files = $_POST['ids'];
  1053. $readonlyAlreadyChecked = false;
  1054. $messages = '';
  1055. $items = array(
  1056. '/audio',
  1057. '/flash',
  1058. '/images',
  1059. '/shared_folder',
  1060. '/video',
  1061. '/chat_files',
  1062. '/certificates'
  1063. );
  1064. foreach ($files as $documentId) {
  1065. $data = DocumentManager::get_document_data_by_id($documentId, $courseInfo['code']);
  1066. if (in_array($data['path'], $items)) {
  1067. // exclude system directories (do not allow deletion)
  1068. continue;
  1069. } else {
  1070. switch ($_POST['action']) {
  1071. case 'set_invisible':
  1072. $visibilityCommand = 'invisible';
  1073. if (api_item_property_update(
  1074. $courseInfo,
  1075. TOOL_DOCUMENT,
  1076. $documentId,
  1077. $visibilityCommand,
  1078. api_get_user_id(),
  1079. null,
  1080. null,
  1081. null,
  1082. null,
  1083. $sessionId
  1084. )) {
  1085. $messages .= Display::return_message(get_lang('VisibilityChanged').': '.$data['title'], 'confirmation');
  1086. } else {
  1087. $messages .= Display::return_message(get_lang('ViModProb'), 'error');
  1088. }
  1089. break;
  1090. case 'set_visible':
  1091. $visibilityCommand = 'visible';
  1092. if (api_item_property_update(
  1093. $courseInfo,
  1094. TOOL_DOCUMENT,
  1095. $documentId,
  1096. $visibilityCommand,
  1097. api_get_user_id(),
  1098. null,
  1099. null,
  1100. null,
  1101. null,
  1102. $sessionId
  1103. )) {
  1104. $messages .= Display::return_message(get_lang('VisibilityChanged').': '.$data['title'], 'confirmation');
  1105. } else {
  1106. $messages .= Display::return_message(get_lang('ViModProb'), 'error');
  1107. }
  1108. break;
  1109. case 'delete':
  1110. // Check all documents scheduled for deletion
  1111. // If one of them is read-only, abandon deletion
  1112. // Note: this is only executed once
  1113. if (!$readonlyAlreadyChecked) {
  1114. foreach ($files as $id) {
  1115. if (!$is_allowed_to_edit) {
  1116. if (DocumentManager::check_readonly(
  1117. $courseInfo,
  1118. api_get_user_id(),
  1119. null,
  1120. $id,
  1121. false,
  1122. $sessionId
  1123. )) {
  1124. $messages .= Display::return_message(
  1125. get_lang('CantDeleteReadonlyFiles'),
  1126. 'error'
  1127. );
  1128. break 2;
  1129. }
  1130. }
  1131. }
  1132. $readonlyAlreadyChecked = true;
  1133. }
  1134. $deleteDocument = DocumentManager::delete_document(
  1135. $courseInfo,
  1136. null,
  1137. $base_work_dir,
  1138. $sessionId,
  1139. $documentId,
  1140. $groupIid
  1141. );
  1142. if (!empty($deleteDocument)) {
  1143. $messages .= Display::return_message(
  1144. get_lang('DocDeleted').': '.$data['title'],
  1145. 'confirmation'
  1146. );
  1147. }
  1148. break;
  1149. }
  1150. }
  1151. } // endforeach
  1152. Display::addFlash($messages);
  1153. header('Location: '.$currentUrl);
  1154. exit;
  1155. }
  1156. }
  1157. $dirForm = null;
  1158. /* CREATE DIRECTORY */
  1159. //Only teacher and all users into their group and any user into his/her shared folder
  1160. if ($is_allowed_to_edit ||
  1161. $group_member_with_upload_rights ||
  1162. DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId)
  1163. ) {
  1164. // Create directory with $_POST data
  1165. if (isset($_POST['create_dir']) && $_POST['dirname'] != '') {
  1166. // Needed for directory creation
  1167. $post_dir_name = $_POST['dirname'];
  1168. if ($post_dir_name == '../' || $post_dir_name == '.' || $post_dir_name == '..') {
  1169. $message = Display::return_message(get_lang('CannotCreateDir'), 'error');
  1170. } else {
  1171. // dir_id is the parent folder id.
  1172. if (!empty($_POST['dir_id'])) {
  1173. // Get the document data from the ID
  1174. $document_data = DocumentManager::get_document_data_by_id(
  1175. $_POST['dir_id'],
  1176. api_get_course_id(),
  1177. false,
  1178. $sessionId
  1179. );
  1180. if ($sessionId != 0 && !$document_data) {
  1181. // If there is a session defined and asking for the
  1182. // document * from the session* didn't work, try it from
  1183. // the course (out of a session context)
  1184. $document_data = DocumentManager::get_document_data_by_id(
  1185. $_POST['dir_id'],
  1186. api_get_course_id(),
  1187. false,
  1188. 0
  1189. );
  1190. }
  1191. $curdirpath = $document_data['path'];
  1192. }
  1193. $added_slash = ($curdirpath == '/') ? '' : '/';
  1194. $dir_name = $curdirpath.$added_slash.api_replace_dangerous_char($post_dir_name);
  1195. $dir_name = disable_dangerous_file($dir_name);
  1196. $dir_check = $base_work_dir.$dir_name;
  1197. $visibility = empty($groupId) ? null : 1;
  1198. $newFolderData = create_unexisting_directory(
  1199. $courseInfo,
  1200. api_get_user_id(),
  1201. $sessionId,
  1202. $groupId,
  1203. $to_user_id,
  1204. $base_work_dir,
  1205. $dir_name,
  1206. $post_dir_name,
  1207. $visibility
  1208. );
  1209. if (!empty($newFolderData)) {
  1210. $message = Display::return_message(
  1211. get_lang('DirCr') . ' ' . $newFolderData['title'],
  1212. 'confirmation'
  1213. );
  1214. } else {
  1215. $message = Display::return_message(
  1216. get_lang('CannotCreateDir'),
  1217. 'error'
  1218. );
  1219. }
  1220. }
  1221. Display::addFlash($message);
  1222. }
  1223. // Show them the form for the directory name
  1224. if (isset($_GET['createdir'])) {
  1225. $dirForm = DocumentManager::create_dir_form($document_id);
  1226. }
  1227. }
  1228. /* VISIBILITY COMMANDS */
  1229. if ($is_allowed_to_edit) {
  1230. if ((isset($_GET['set_invisible']) && !empty($_GET['set_invisible'])) ||
  1231. (isset($_GET['set_visible']) && !empty($_GET['set_visible']))
  1232. ) {
  1233. // Make visible or invisible?
  1234. if (isset($_GET['set_visible'])) {
  1235. $update_id = intval($_GET['set_visible']);
  1236. $visibility_command = 'visible';
  1237. } else {
  1238. $update_id = intval($_GET['set_invisible']);
  1239. $visibility_command = 'invisible';
  1240. }
  1241. if (!$is_allowed_to_edit) {
  1242. if (api_is_coach()) {
  1243. if (!DocumentManager::is_visible_by_id($update_id, $courseInfo, $sessionId, api_get_user_id())) {
  1244. api_not_allowed(true);
  1245. }
  1246. }
  1247. if (DocumentManager::check_readonly($courseInfo, api_get_user_id(), '', $update_id)) {
  1248. api_not_allowed(true);
  1249. }
  1250. }
  1251. // Update item_property to change visibility
  1252. if (api_item_property_update(
  1253. $courseInfo,
  1254. TOOL_DOCUMENT,
  1255. $update_id,
  1256. $visibility_command,
  1257. api_get_user_id(),
  1258. null,
  1259. null,
  1260. null,
  1261. null,
  1262. $sessionId)
  1263. ) {
  1264. Display::addFlash(
  1265. Display::return_message(get_lang('VisibilityChanged'), 'confirmation')
  1266. );
  1267. } else {
  1268. Display::addFlash(
  1269. Display::return_message(get_lang('ViModProb'), 'error')
  1270. );
  1271. }
  1272. header('Location: '.$currentUrl);
  1273. exit;
  1274. }
  1275. }
  1276. $templateForm = null;
  1277. /* TEMPLATE ACTION */
  1278. //Only teacher and all users into their group
  1279. if ($is_allowed_to_edit ||
  1280. $group_member_with_upload_rights ||
  1281. DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId)
  1282. ) {
  1283. if (isset($_GET['add_as_template']) && !isset($_POST['create_template'])) {
  1284. $document_id_for_template = intval($_GET['add_as_template']);
  1285. // Create the form that asks for the directory name
  1286. $templateForm .= '
  1287. <form name="set_document_as_new_template" class="form-horizontal" enctype="multipart/form-data" action="' . api_get_self() . '?add_as_template=' . $document_id_for_template . '" method="post">
  1288. <fieldset>
  1289. <legend>' . get_lang('AddAsTemplate') . '</legend>
  1290. <div class="form-group">
  1291. <label for="template_title" class="col-sm-2 control-label">' . get_lang('TemplateName') . '</label>
  1292. <div class="col-sm-10">
  1293. <input type="text" class="form-control" id="template_title" name="template_title">
  1294. </div>
  1295. </div>
  1296. <div class="form-group">
  1297. <label for="template_image" class="col-sm-2 control-label">' . get_lang('TemplateImage') . '</label>
  1298. <div class="col-sm-10">
  1299. <input type="file" name="template_image" id="template_image">
  1300. </div>
  1301. </div>
  1302. <div class="form-group">
  1303. <div class="col-sm-offset-2 col-sm-10">
  1304. <button type="submit" name="create_template" class="btn btn-primary">' . get_lang('CreateTemplate') . '</button>
  1305. </div>
  1306. </div>
  1307. <input type="hidden" name="curdirpath" value="' . $curdirpath . '" />
  1308. </fieldset>
  1309. </form>
  1310. <hr>
  1311. ';
  1312. } elseif (isset($_GET['add_as_template']) && isset($_POST['create_template'])) {
  1313. $document_id_for_template = intval($_GET['add_as_template']);
  1314. $title = Security::remove_XSS($_POST['template_title']);
  1315. $user_id = api_get_user_id();
  1316. // Create the template_thumbnails folder in the upload folder (if needed)
  1317. if (!is_dir(api_get_path(SYS_COURSE_PATH).$courseInfo['directory'].'/upload/template_thumbnails/')) {
  1318. @mkdir(
  1319. api_get_path(SYS_COURSE_PATH).$courseInfo['directory'].'/upload/template_thumbnails/',
  1320. api_get_permissions_for_new_directories()
  1321. );
  1322. }
  1323. // Upload the file
  1324. if (!empty($_FILES['template_image']['name'])) {
  1325. $upload_ok = process_uploaded_file($_FILES['template_image']);
  1326. if ($upload_ok) {
  1327. // Try to add an extension to the file if it hasn't one
  1328. $new_file_name = $courseInfo['code'].'-'.add_ext_on_mime(
  1329. stripslashes($_FILES['template_image']['name']),
  1330. $_FILES['template_image']['type']
  1331. );
  1332. // Upload dir
  1333. $upload_dir = api_get_path(SYS_COURSE_PATH).$courseInfo['directory'].'/upload/template_thumbnails/';
  1334. // Resize image to max default and end upload
  1335. $temp = new Image($_FILES['template_image']['tmp_name']);
  1336. $picture_info = $temp->get_image_info();
  1337. $max_width_for_picture = 100;
  1338. if ($picture_info['width'] > $max_width_for_picture) {
  1339. $temp->resize($max_width_for_picture);
  1340. }
  1341. $temp->send_image($upload_dir.$new_file_name);
  1342. }
  1343. }
  1344. DocumentManager::set_document_as_template(
  1345. $title,
  1346. '',
  1347. $document_id_for_template,
  1348. $course_code,
  1349. $user_id,
  1350. $new_file_name
  1351. );
  1352. Display::addFlash(
  1353. Display::return_message(get_lang('DocumentSetAsTemplate'), 'confirmation')
  1354. );
  1355. }
  1356. if (isset($_GET['remove_as_template'])) {
  1357. $document_id_for_template = intval($_GET['remove_as_template']);
  1358. $user_id = api_get_user_id();
  1359. DocumentManager::unset_document_as_template(
  1360. $document_id_for_template,
  1361. $course_code,
  1362. $user_id
  1363. );
  1364. Display::addFlash(
  1365. Display::return_message(get_lang('DocumentUnsetAsTemplate'), 'confirmation')
  1366. );
  1367. }
  1368. }
  1369. // END ACTION MENU
  1370. // Attach certificate in the gradebook
  1371. if (isset($_GET['curdirpath']) &&
  1372. $_GET['curdirpath'] == '/certificates' &&
  1373. isset($_GET['set_certificate']) &&
  1374. $_GET['set_certificate'] == strval(intval($_GET['set_certificate']))
  1375. ) {
  1376. if (isset($_GET['cidReq'])) {
  1377. $course_id = Security::remove_XSS($_GET['cidReq']); // course id
  1378. $document_id = Security::remove_XSS($_GET['set_certificate']); // document id
  1379. DocumentManager::attach_gradebook_certificate($course_id, $document_id);
  1380. $message = Display::return_message(get_lang('IsDefaultCertificate'), 'normal');
  1381. Display::addFlash(
  1382. $message
  1383. );
  1384. }
  1385. }
  1386. /* GET ALL DOCUMENT DATA FOR CURDIRPATH */
  1387. if (isset($_GET['keyword']) && !empty($_GET['keyword'])) {
  1388. $documentAndFolders = DocumentManager::get_all_document_data(
  1389. $courseInfo,
  1390. $curdirpath,
  1391. $groupIid,
  1392. null,
  1393. $is_allowed_to_edit || $group_member_with_upload_rights,
  1394. true
  1395. );
  1396. } else {
  1397. $documentAndFolders = DocumentManager::get_all_document_data(
  1398. $courseInfo,
  1399. $curdirpath,
  1400. $groupIid,
  1401. null,
  1402. $is_allowed_to_edit || $group_member_with_upload_rights,
  1403. false
  1404. );
  1405. }
  1406. if ($groupId != 0) {
  1407. $userAccess = GroupManager::user_has_access(
  1408. api_get_user_id(),
  1409. $groupIid,
  1410. GroupManager::GROUP_TOOL_DOCUMENTS
  1411. );
  1412. if ($userAccess) {
  1413. $folders = DocumentManager::get_all_document_folders(
  1414. $courseInfo,
  1415. $groupIid,
  1416. $is_allowed_to_edit || $group_member_with_upload_rights
  1417. );
  1418. }
  1419. } else {
  1420. $folders = DocumentManager::get_all_document_folders(
  1421. $courseInfo,
  1422. $groupIid,
  1423. $is_allowed_to_edit || $group_member_with_upload_rights
  1424. );
  1425. }
  1426. if (!isset($folders) || $folders === false) {
  1427. $folders = array();
  1428. }
  1429. $btngroup = array('class' => 'btn btn-default');
  1430. /* GO TO PARENT DIRECTORY */
  1431. $actionsLeft = '';
  1432. if ($curdirpath != '/' && $curdirpath != $group_properties['directory'] && !$is_certificate_mode) {
  1433. $actionsLeft = '<a href="'.api_get_self().'?'.api_get_cidreq().'&id='.$parent_id.'">';
  1434. $actionsLeft .= Display::return_icon('folder_up.png', get_lang('Up'), '', ICON_SIZE_MEDIUM);
  1435. $actionsLeft .= '</a>';
  1436. }
  1437. if ($is_certificate_mode && $curdirpath != '/certificates') {
  1438. $actionsLeft .= Display::url(
  1439. Display::return_icon('folder_up.png', get_lang('Up'), '', ICON_SIZE_MEDIUM),
  1440. api_get_self().'?'.api_get_cidreq().'&curdirpath='.$curdirpath
  1441. );
  1442. }
  1443. $column_show = array();
  1444. if ($is_allowed_to_edit ||
  1445. $group_member_with_upload_rights ||
  1446. DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId)
  1447. ) {
  1448. // TODO:check enable more options for shared folders
  1449. /* CREATE NEW DOCUMENT OR NEW DIRECTORY / GO TO UPLOAD / DOWNLOAD ZIPPED FOLDER */
  1450. // Create new document
  1451. if (!$is_certificate_mode) {
  1452. $actionsLeft .= Display::url(
  1453. Display::return_icon('new_document.png', get_lang('CreateDoc'), '', ICON_SIZE_MEDIUM),
  1454. api_get_path(WEB_CODE_PATH).'document/create_document.php?'.api_get_cidreq().'&id='.$document_id
  1455. );
  1456. // Create new draw
  1457. if (api_get_setting('editor.enabled_support_svg') == 'true') {
  1458. if (api_browser_support('svg')) {
  1459. $actionsLeft .= Display::url(
  1460. Display::return_icon('new_draw.png', get_lang('Draw'), '', ICON_SIZE_MEDIUM),
  1461. api_get_path(WEB_CODE_PATH).'document/create_draw.php?'.api_get_cidreq().'&id='.$document_id
  1462. );
  1463. } else {
  1464. $actionsLeft .= Display::return_icon('new_draw_na.png', get_lang('BrowserDontSupportsSVG'), '', ICON_SIZE_MEDIUM);
  1465. }
  1466. }
  1467. // Create new paint
  1468. if (api_get_setting('editor.enabled_support_pixlr') == 'true') {
  1469. $actionsLeft .= Display::url(
  1470. Display::return_icon('new_paint.png', get_lang('PhotoRetouching'), '', ICON_SIZE_MEDIUM),
  1471. api_get_path(WEB_CODE_PATH).'document/create_paint.php?'.api_get_cidreq().'&id='.$document_id
  1472. );
  1473. }
  1474. // Record an image clip from my webcam
  1475. if (api_get_setting('document.enable_webcam_clip') == 'true') {
  1476. $actionsLeft .= Display::url(
  1477. Display::return_icon('webcam.png', get_lang('WebCamClip'), '', ICON_SIZE_MEDIUM),
  1478. api_get_path(WEB_CODE_PATH).'document/webcam_clip.php?'.api_get_cidreq().'&id='.$document_id
  1479. );
  1480. }
  1481. // Record audio (nanogong)
  1482. if (api_get_setting('document.enable_nanogong') == 'true') {
  1483. $actionsLeft .= Display::url(
  1484. Display::return_icon('new_recording.png', get_lang('RecordMyVoice'), '', ICON_SIZE_MEDIUM),
  1485. api_get_path(WEB_CODE_PATH).'document/record_audio.php?'.api_get_cidreq().'&id='.$document_id
  1486. );
  1487. }
  1488. // Record audio (wami record)
  1489. if (api_get_setting('document.enable_wami_record') == 'true') {
  1490. $actionsLeft .= Display::url(
  1491. Display::return_icon('new_recording.png', get_lang('RecordMyVoice'), '', ICON_SIZE_MEDIUM),
  1492. api_get_path(WEB_CODE_PATH).'document/record_audio_wami.php?'.api_get_cidreq().'&id='.$document_id
  1493. );
  1494. }
  1495. // Create new audio from text
  1496. if (api_get_setting('document.enabled_text2audio') == 'true') {
  1497. $dt2a = 'google';
  1498. $req_dt2a = '&amp;dt2a='.$dt2a;
  1499. $actionsLeft .= Display::url(
  1500. Display::return_icon('new_sound.png', get_lang('CreateAudio'), '', ICON_SIZE_MEDIUM),
  1501. api_get_path(WEB_CODE_PATH).'document/create_audio.php?'.api_get_cidreq().'&id='.$document_id.$req_dt2a
  1502. );
  1503. }
  1504. }
  1505. // Create new certificate
  1506. if ($is_certificate_mode) {
  1507. $actionsLeft .= Display::url(
  1508. Display::return_icon('new_certificate.png', get_lang('CreateCertificate'), '', ICON_SIZE_MEDIUM),
  1509. api_get_path(WEB_CODE_PATH).'document/create_document.php?'.api_get_cidreq().'&id='.$document_id.'&certificate=true&selectcat='.$selectcat
  1510. );
  1511. }
  1512. // File upload link
  1513. if ($is_certificate_mode) {
  1514. $actionsLeft .= Display::url(
  1515. Display::return_icon('upload_certificate.png', get_lang('UploadCertificate'), '', ICON_SIZE_MEDIUM),
  1516. api_get_path(WEB_CODE_PATH).'document/upload.php?'.api_get_cidreq().'&id='.$current_folder_id.'&certificate=true'
  1517. );
  1518. } else {
  1519. $actionsLeft .= Display::url(
  1520. Display::return_icon('upload_file.png', get_lang('UplUploadDocument'), '', ICON_SIZE_MEDIUM),
  1521. api_get_path(WEB_CODE_PATH).'document/upload.php?'.api_get_cidreq().'&id='.$current_folder_id
  1522. );
  1523. }
  1524. /*echo '<a href="#" id="jcapture">';
  1525. echo Display::display_icon('capture.png', get_lang('CatchScreenCasts'), '', ICON_SIZE_MEDIUM).'</a>';*/
  1526. if ($capturePluginInstalled) {
  1527. $actionsLeft .= '<span id="appletplace"></span>';
  1528. $actionsLeft .= Display::url(
  1529. Display::return_icon('capture.png', get_lang('CatchScreenCasts'), '', ICON_SIZE_MEDIUM),
  1530. '#',
  1531. array('id' => 'jcapture')
  1532. );
  1533. }
  1534. // Create directory
  1535. if (!$is_certificate_mode) {
  1536. $actionsLeft .= Display::url(
  1537. Display::return_icon('new_folder.png', get_lang('CreateDir'), '', ICON_SIZE_MEDIUM),
  1538. api_get_path(WEB_CODE_PATH).'document/document.php?'.api_get_cidreq().'&id='.$document_id.'&createdir=1'
  1539. );
  1540. }
  1541. }
  1542. require 'document_slideshow.inc.php';
  1543. if ($image_present && !isset($_GET['keyword'])) {
  1544. $actionsLeft .= Display::url(
  1545. Display::return_icon('slideshow.png', get_lang('ViewSlideshow'), '', ICON_SIZE_MEDIUM),
  1546. api_get_path(WEB_CODE_PATH).'document/slideshow.php?'.api_get_cidreq().'&curdirpath='.$curdirpathurl
  1547. );
  1548. }
  1549. if (api_is_allowed_to_edit(null, true)) {
  1550. $actionsLeft .= Display::url(
  1551. Display::return_icon('percentage.png', get_lang('DocumentQuota'), '', ICON_SIZE_MEDIUM),
  1552. api_get_path(WEB_CODE_PATH).'document/document_quota.php?'.api_get_cidreq()
  1553. );
  1554. }
  1555. if (!$is_certificate_mode) {
  1556. /* BUILD SEARCH FORM */
  1557. $form = new FormValidator(
  1558. 'search_document',
  1559. 'get',
  1560. api_get_self().'?'.api_get_cidreq(),
  1561. '',
  1562. array(),
  1563. FormValidator::LAYOUT_INLINE
  1564. );
  1565. $form->addText('keyword', '', false, array('class' => 'col-md-2'));
  1566. $form->addElement('hidden', 'cidReq', api_get_course_id());
  1567. $form->addElement('hidden', 'id_session', api_get_session_id());
  1568. $form->addElement('hidden', 'gidReq', $groupId);
  1569. $form->addButtonSearch(get_lang('Search'));
  1570. $actionsRight = $form->returnForm();
  1571. }
  1572. $table_footer = '';
  1573. $total_size = 0;
  1574. $sortable_data = array();
  1575. if (isset($documentAndFolders) && is_array($documentAndFolders)) {
  1576. if ($groupId == 0 ||
  1577. GroupManager::user_has_access(
  1578. $userId,
  1579. $groupIid,
  1580. GroupManager::GROUP_TOOL_DOCUMENTS
  1581. )
  1582. ) {
  1583. $count = 1;
  1584. $countedPaths = array();
  1585. $countedPaths = array();
  1586. foreach ($documentAndFolders as $key => $document_data) {
  1587. $row = array();
  1588. $row['id'] = $document_data['id'];
  1589. $row['type'] = $document_data['filetype'];
  1590. // If the item is invisible, wrap it in a span with class invisible.
  1591. $is_visible = DocumentManager::is_visible_by_id(
  1592. $document_data['id'],
  1593. $courseInfo,
  1594. $sessionId,
  1595. api_get_user_id(),
  1596. false
  1597. );
  1598. $invisibility_span_open = ($is_visible == 0) ? '<span class="muted">' : '';
  1599. $invisibility_span_close = ($is_visible == 0) ? '</span>' : '';
  1600. // Size (or total size of a directory)
  1601. $size = $document_data['filetype'] == 'folder' ? get_total_folder_size($document_data['path'], $is_allowed_to_edit) : $document_data['size'];
  1602. // Get the title or the basename depending on what we're using
  1603. if ($document_data['title'] != '') {
  1604. $document_name = $document_data['title'];
  1605. } else {
  1606. $document_name = basename($document_data['path']);
  1607. }
  1608. $row['name'] = $document_name;
  1609. // Data for checkbox
  1610. if (($is_allowed_to_edit || $group_member_with_upload_rights) && count($documentAndFolders) > 1) {
  1611. $row[] = $document_data['id'];
  1612. }
  1613. if (DocumentManager::is_folder_to_avoid($document_data['path'], $is_certificate_mode)) {
  1614. continue;
  1615. }
  1616. // Show the owner of the file only in groups
  1617. $user_link = '';
  1618. if (!empty($groupId)) {
  1619. if (!empty($document_data['insert_user_id'])) {
  1620. $user_info = api_get_user_info($document_data['insert_user_id']);
  1621. $user_link = '<div class="document_owner">'.
  1622. get_lang('Owner').': '.UserManager::getUserProfileLink($user_info).'</div>';
  1623. }
  1624. }
  1625. // Icons (clickable)
  1626. $row[] = DocumentManager::create_document_link(
  1627. $document_data,
  1628. true,
  1629. $count,
  1630. $is_visible
  1631. );
  1632. $path_info = pathinfo($document_data['path']);
  1633. if (isset($path_info['extension']) &&
  1634. in_array($path_info['extension'], array('ogg', 'mp3', 'wav'))
  1635. ) {
  1636. $count++;
  1637. }
  1638. // Validation when belongs to a session
  1639. $session_img = api_get_session_image($document_data['session_id'], $_user['status']);
  1640. // Document title with link
  1641. $row[] = DocumentManager::create_document_link($document_data, false, null, $is_visible).
  1642. $session_img.'<br />'.$invisibility_span_open.
  1643. '<i>'.nl2br(htmlspecialchars($document_data['comment'], ENT_QUOTES, $charset)).'</i>'.
  1644. $invisibility_span_close.
  1645. $user_link;
  1646. // Comments => display comment under the document name
  1647. $display_size = format_file_size($size);
  1648. $row[] = '<span style="display:none;">'.$size.'</span>'.
  1649. $invisibility_span_open.
  1650. $display_size.
  1651. $invisibility_span_close;
  1652. // Last edit date
  1653. $last_edit_date = api_get_local_time($document_data['lastedit_date']);
  1654. $display_date = date_to_str_ago($document_data['lastedit_date']).
  1655. ' <div class="muted"><small>'.$last_edit_date."</small></div>";
  1656. $row[] = $invisibility_span_open.$display_date.$invisibility_span_close;
  1657. // Admins get an edit column
  1658. if ($is_allowed_to_edit ||
  1659. $groupMemberWithEditRights ||
  1660. DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId) ||
  1661. $document_data['insert_user_id'] == api_get_user_id()
  1662. ) {
  1663. $is_template = isset($document_data['is_template']) ? $document_data['is_template'] : false;
  1664. // If readonly, check if it the owner of the file or if the user is an admin
  1665. if ($document_data['insert_user_id'] == api_get_user_id() || api_is_platform_admin()) {
  1666. $edit_icons = DocumentManager::build_edit_icons(
  1667. $document_data,
  1668. $key,
  1669. $is_template,
  1670. 0,
  1671. $is_visible
  1672. );
  1673. } else {
  1674. $edit_icons = DocumentManager::build_edit_icons(
  1675. $document_data,
  1676. $key,
  1677. $is_template,
  1678. $document_data['readonly'],
  1679. $is_visible
  1680. );
  1681. }
  1682. $row[] = $edit_icons;
  1683. } else {
  1684. $row[] = '';
  1685. }
  1686. $row[] = $last_edit_date;
  1687. $row[] = $size;
  1688. $row[] = $document_name;
  1689. $total_size = $total_size + $size;
  1690. if (!isset($countedPaths[$document_data['path']])) {
  1691. $total_size = $total_size + $size;
  1692. $countedPaths[$document_data['path']] = true;
  1693. }
  1694. if ((isset($_GET['keyword']) &&
  1695. DocumentManager::search_keyword($document_name, $_GET['keyword'])) ||
  1696. !isset($_GET['keyword']) || empty($_GET['keyword'])
  1697. ) {
  1698. $sortable_data[] = $row;
  1699. }
  1700. }
  1701. }
  1702. } else {
  1703. $sortable_data = '';
  1704. $table_footer = get_lang('NoDocsInFolder');
  1705. }
  1706. if (!is_null($documentAndFolders)) {
  1707. // Show download zipped folder icon
  1708. global $total_size;
  1709. if (!$is_certificate_mode && $total_size != 0
  1710. && (api_get_setting('document.students_download_folders') == 'true'
  1711. || api_is_allowed_to_edit()
  1712. || api_is_platform_admin()
  1713. )
  1714. ) {
  1715. //for student does not show icon into other shared folder, and does not show into main path (root)
  1716. if (DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId)
  1717. && $curdirpath != '/'
  1718. || api_is_allowed_to_edit()
  1719. || api_is_platform_admin()
  1720. ) {
  1721. $actionsLeft .= Display::url(
  1722. Display::return_icon(
  1723. 'save_pack.png',
  1724. get_lang('Save').' (ZIP)',
  1725. '',
  1726. ICON_SIZE_MEDIUM
  1727. ),
  1728. api_get_path(WEB_CODE_PATH).'document/document.php?'.api_get_cidreq().'&action=downloadfolder&id='.$document_id
  1729. );
  1730. }
  1731. }
  1732. }
  1733. if (api_is_platform_admin()) {
  1734. if (api_get_configuration_value('document_manage_deleted_files')) {
  1735. $actionsLeft .= Display::url(
  1736. get_lang('Recycle'),
  1737. api_get_path(WEB_CODE_PATH).'document/recycle.php?'.api_get_cidreq(),
  1738. array('class' => 'btn btn-default')
  1739. );
  1740. }
  1741. }
  1742. if (!empty($moveTo)) {
  1743. $document_id = DocumentManager::get_document_id($courseInfo, $moveTo);
  1744. }
  1745. if (isset($_GET['createdir']) && isset($_POST['dirname']) && $_POST['dirname'] != '') {
  1746. $post_dir_name = $_POST['dirname'];
  1747. $document_id = DocumentManager::get_document_id($courseInfo, $_POST['dirname']);
  1748. }
  1749. $selector = null;
  1750. if (!$is_certificate_mode) {
  1751. $selector = DocumentManager::build_directory_selector(
  1752. $folders,
  1753. $document_id,
  1754. (isset($group_properties['directory']) ? $group_properties['directory'] : array()),
  1755. true
  1756. );
  1757. }
  1758. if (($is_allowed_to_edit || $group_member_with_upload_rights) &&
  1759. count($documentAndFolders) > 1
  1760. ) {
  1761. $column_show[] = 1;
  1762. }
  1763. $column_show[] = 1;
  1764. $column_show[] = 1;
  1765. $column_show[] = 1;
  1766. $column_show[] = 1;
  1767. if ($is_allowed_to_edit
  1768. || $group_member_with_upload_rights
  1769. || DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId)
  1770. ) {
  1771. $column_show[] = 1;
  1772. }
  1773. $column_show[] = 0;
  1774. $column_show[] = 0;
  1775. $column_order = array();
  1776. if (count($row) == 12) {
  1777. //teacher
  1778. $column_order[2] = 8; //name
  1779. $column_order[3] = 7;
  1780. $column_order[4] = 6;
  1781. } elseif (count($row) == 10) {
  1782. //student
  1783. $column_order[1] = 6;
  1784. $column_order[2] = 5;
  1785. $column_order[3] = 4;
  1786. }
  1787. $default_column = $is_allowed_to_edit ? 2 : 1;
  1788. $tableName = $is_allowed_to_edit ? 'teacher_table' : 'student_table';
  1789. $table = new SortableTableFromArrayConfig(
  1790. $sortable_data,
  1791. $default_column,
  1792. 20,
  1793. $tableName,
  1794. $column_show,
  1795. $column_order,
  1796. 'ASC',
  1797. true
  1798. );
  1799. $query_vars = array();
  1800. if (isset($_GET['keyword'])) {
  1801. $query_vars['keyword'] = Security::remove_XSS($_GET['keyword']);
  1802. } else {
  1803. $query_vars['curdirpath'] = $curdirpath;
  1804. }
  1805. if ($groupId) {
  1806. $query_vars['gidReq'] = $groupId;
  1807. }
  1808. $query_vars['cidReq'] = api_get_course_id();
  1809. $table->set_additional_parameters($query_vars);
  1810. $column = 0;
  1811. if (($is_allowed_to_edit || $group_member_with_upload_rights) && count($documentAndFolders) > 1) {
  1812. $table->set_header($column++, '', false, array('style' => 'width:12px;'));
  1813. }
  1814. $table->set_header($column++, get_lang('Type'), true, array('style' => 'width:30px;'));
  1815. $table->set_header($column++, get_lang('Name'));
  1816. $table->set_header($column++, get_lang('Size'), true, array('style' => 'width:50px;'));
  1817. $table->set_header($column++, get_lang('Date'), true, array('style' => 'width:150px;'));
  1818. // Admins get an edit column
  1819. if ($is_allowed_to_edit
  1820. || $group_member_with_upload_rights
  1821. || DocumentManager::is_my_shared_folder(api_get_user_id(), $curdirpath, $sessionId)) {
  1822. $table->set_header($column++, get_lang('Actions'), false, array('class' => 'td_actions'));
  1823. }
  1824. // Actions on multiple selected documents
  1825. // TODO: Currently only delete action -> take only DELETE permission into account
  1826. if (count($documentAndFolders) > 1) {
  1827. if ($is_allowed_to_edit || $groupMemberWithEditRights) {
  1828. $form_actions = array();
  1829. $form_action['set_invisible'] = get_lang('SetInvisible');
  1830. $form_action['set_visible'] = get_lang('SetVisible');
  1831. $form_action['delete'] = get_lang('Delete');
  1832. $portfolio_actions = Portfolio::actions();
  1833. foreach ($portfolio_actions as $action) {
  1834. $form_action[$action->get_name()] = $action->get_title();
  1835. }
  1836. $table->set_form_actions($form_action, 'ids');
  1837. }
  1838. }
  1839. //Display::display_header('', 'Doc');
  1840. /* Introduction section (editable by course admins) */
  1841. if (!empty($groupId)) {
  1842. Display::display_introduction_section(TOOL_DOCUMENT.$groupId);
  1843. } else {
  1844. Display::display_introduction_section(TOOL_DOCUMENT);
  1845. }
  1846. $toolbar = Display::toolbarAction(
  1847. 'toolbar-document',
  1848. array(0 => $actionsLeft, 1 => $actionsRight)
  1849. );
  1850. echo $toolbar;
  1851. echo $templateForm;
  1852. echo $moveForm;
  1853. echo $dirForm;
  1854. echo $selector;
  1855. $table->display();
  1856. if (count($documentAndFolders) > 1) {
  1857. if ($is_allowed_to_edit || $group_member_with_upload_rights) {
  1858. // Getting the course quota
  1859. $course_quota = DocumentManager::get_course_quota();
  1860. // Calculating the total space
  1861. $already_consumed_space_course = DocumentManager::documents_total_space(
  1862. api_get_course_int_id()
  1863. );
  1864. // Displaying the quota
  1865. DocumentManager::display_simple_quota(
  1866. $course_quota,
  1867. $already_consumed_space_course
  1868. );
  1869. }
  1870. }
  1871. if (!empty($table_footer)) {
  1872. Display::display_warning_message($table_footer);
  1873. }
  1874. echo '
  1875. <div id="convertModal" class="modal fade" tabindex="-1" role="dialog" aria-hidden="true">
  1876. <div class="modal-dialog">
  1877. <div class="modal-content">
  1878. <div class="modal-header" style="text-align: center;">
  1879. <button type="button" class="close" data-dismiss="modal" aria-label="' . get_lang('Close') . '">
  1880. <span aria-hidden="true">&times;</span>
  1881. </button>
  1882. <h4 class="modal-title">' . get_lang('Convert') . '</h4>
  1883. </div>
  1884. <div class="modal-body">
  1885. <form action="#" class="form-horizontal">
  1886. <div class="form-group">
  1887. <label class="col-sm-4 control-label" for="convertSelect">' . get_lang('ConvertFormats') . '</label>
  1888. <div class="col-sm-8">
  1889. <select id="convertSelect">
  1890. <option value="">' . get_lang('Select') . '</option>
  1891. <option value="pdf">
  1892. PDF - Portable Document File
  1893. </option>
  1894. <option value="odt" style="display:none;" class="textFormatType">
  1895. ODT - Open Document Text
  1896. </option>
  1897. <option value="odp" style="display:none;" class="presentationFormatType">
  1898. ODP - Open Document Portable
  1899. </option>
  1900. <option value="ods" style="display:none;" class="spreadsheetFormatType">
  1901. ODS - Open Document Spreadsheet
  1902. </option>
  1903. </select>
  1904. </div>
  1905. </div>
  1906. </form>
  1907. </div>
  1908. <div class="modal-footer">
  1909. <button type="button" class="btn btn-default" data-dismiss="modal">' . get_lang('Close') . '</button>
  1910. </div>
  1911. </div>
  1912. </div>';
  1913. // Footer
  1914. Display::display_footer();