123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215 |
- <?php
- use ChamiloSession as Session;
- require_once '../../../../../inc/global.inc.php';
- api_protect_course_script();
- api_block_anonymous_users();
- if (!isset($_POST['output_svg']) && !isset($_POST['output_png'])) {
- api_not_allowed();
- die();
- }
- $file = '';
- $suffix = isset($_POST['output_svg']) ? 'svg' : 'png';
- $_course = api_get_course_info();
- if (isset($_POST['filename']) && strlen($_POST['filename']) > 0) {
- $file = $_POST['filename'];
- } else {
- $file = 'image';
- }
- if ($suffix == 'svg') {
- $mime = 'image/svg+xml';
- $contents = rawurldecode($_POST['output_svg']);
- } else {
- $mime = 'image/png';
- $contents = $_POST['output_png'];
- $pos = (strpos($contents, 'base64,') + 7);
- $contents = base64_decode(substr($contents, $pos));
- }
- $filename = $file;
- $extension = $suffix;
- $content = $contents;
- $title = Database::escape_string(str_replace('_',' ',$filename));
- $relativeUrlPath = Session::read('draw_dir');
- if (empty($relativeUrlPath)) {
- api_not_allowed();
- die();
- }
- $current_session_id = api_get_session_id();
- $groupId = api_get_group_id();
- $groupInfo = GroupManager::get_group_properties($groupId);
- $dirBaseDocuments = api_get_path(SYS_COURSE_PATH).$_course['path'].'/document';
- $saveDir = $dirBaseDocuments.$relativeUrlPath;
- $filename = addslashes(trim($filename));
- $filename = Security::remove_XSS($filename);
- $filename = api_replace_dangerous_char($filename);
- $filename = disable_dangerous_file($filename);
- if ($suffix != 'svg' && $suffix != 'png') {
- die();
- }
- if (file_exists($saveDir.'/'.$filename.'.'.$extension) && $currentTool=='document/createdraw') {
- $message = get_lang('FileExistsChangeToSave');
- $params = array(
- 'message' => $message,
- 'url' => ''
- );
- echo json_encode($params);
- exit;
- } else {
- $drawFileName = $filename.'.'.$extension;
- $title = $title.'.'.$extension;
- }
- $documentPath = $saveDir.'/'.$drawFileName;
- file_put_contents($documentPath, $contents);
- if ($currentTool == 'document/createdraw') {
-
- $doc_id = add_document(
- $_course,
- $relativeUrlPath.'/'.$drawFileName,
- 'file',
- filesize($documentPath),
- $title
- );
- api_item_property_update(
- $_course,
- TOOL_DOCUMENT,
- $doc_id,
- 'DocumentAdded',
- $_user['user_id'],
- $groupInfo,
- null,
- null,
- null,
- $current_session_id
- );
- } elseif ($currentTool == 'document/editdraw') {
-
- if (!isset($_SESSION['draw_file'])) {
- api_not_allowed();
- die();
- }
- if ($_SESSION['draw_file'] == $drawFileName) {
- $document_id = DocumentManager::get_document_id(
- $_course,
- $relativeUrlPath.'/'.$drawFileName
- );
- update_existing_document(
- $_course,
- $document_id,
- filesize($documentPath),
- null
- );
- api_item_property_update(
- $_course,
- TOOL_DOCUMENT,
- $document_id,
- 'DocumentUpdated',
- $_user['user_id'],
- $groupInfo,
- null,
- null,
- null,
- $current_session_id
- );
- } else {
-
- $doc_id = add_document(
- $_course,
- $relativeUrlPath.'/'.$drawFileName,
- 'file',
- filesize($documentPath),
- $title
- );
- api_item_property_update(
- $_course,
- TOOL_DOCUMENT,
- $doc_id,
- 'DocumentAdded',
- $_user['user_id'],
- $groupInfo,
- null,
- null,
- null,
- $current_session_id
- );
- }
- }
- Session::erase('draw_dir');
- Session::erase('draw_file');
- if ($suffix != 'png') {
- if ($relativeUrlPath == '') {
- $relativeUrlPath = '/';
- };
- $url = api_get_path(WEB_CODE_PATH).'document/document.php?'.api_get_cidreq().'&curdirpath='.urlencode($relativeUrlPath);
- $message = get_lang('FileSavedAs').': '.$title;
-
-
- } else {
- $url = '';
- $message = get_lang('FileExportAs').': '.$title;
- }
- $params = array(
- 'message' => $message,
- 'url' => $url
- );
- echo json_encode($params);
- exit;
|