X-Git-Url: https://git.p6c8.net/jirafeau_project.git/blobdiff_plain/3e47e7c2308813736cb9461d2d4a3164fbffc849..6924499c6530c40b3eb78c3f257ee895a5b10be2:/file.php?ds=inline
diff --git a/file.php b/file.php
index a8d42e4..0a6e32c 100644
--- a/file.php
+++ b/file.php
@@ -17,113 +17,137 @@
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see .
*/
+define ('JIRAFEAU_ROOT', dirname (__FILE__) . '/');
-define('JIRAFEAU_ROOT', dirname(__FILE__) . '/');
+require (JIRAFEAU_ROOT . 'lib/lang.php');
+require (JIRAFEAU_ROOT . 'lib/config.php');
+require (JIRAFEAU_ROOT . 'lib/settings.php');
+require (JIRAFEAU_ROOT . 'lib/functions.php');
-require(JIRAFEAU_ROOT . 'lib/config.php');
-require(JIRAFEAU_ROOT . 'lib/settings.php');
-require(JIRAFEAU_ROOT . 'lib/functions.php');
+if (isset ($_GET['h']) && !empty ($_GET['h']))
+{
+ $link_name = $_GET['h'];
-if(isset($_GET['h']) && !empty($_GET['h'])) {
- $link_name = $_GET['h'];
+ $delete_code = '';
+ if (isset ($_GET['d']) && !empty ($_GET['d']))
+ $delete_code = $_GET['d'];
- if(!ereg('[0-9a-f]{32}$', $link_name)) {
- header("HTTP/1.0 404 Not Found");
+ if (!preg_match ('/[0-9a-f]{32}$/', $link_name))
+ {
+ header ("HTTP/1.0 404 Not Found");
- require(JIRAFEAU_ROOT . 'lib/template/header.php');
- echo '
';
- require(JIRAFEAU_ROOT . 'lib/template/footer.php');
- exit;
- }
+ require (JIRAFEAU_ROOT.'lib/template/header.php');
+ echo '';
+ require (JIRAFEAU_ROOT.'lib/template/footer.php');
+ exit;
+ }
- $link_file = VAR_LINKS . $link_name;
- if(file_exists($link_file)) {
- $content = file($link_file);
- $file_name = trim($content[0]);
- $mime_type = trim($content[1]);
- $file_size = trim($content[2]);
- $key = trim($content[3], NL);
- $time = trim($content[4]);
- $md5 = trim($content[5]);
- $onetime = trim($content[6]);
-
- if(!file_exists(VAR_FILES . $md5)) {
- jirafeau_delete($link_name);
+ $link_file = VAR_LINKS.$link_name;
+ if (file_exists ($link_file))
+ {
+ $content = file ($link_file);
+ $file_name = trim ($content[0]);
+ $mime_type = trim ($content[1]);
+ $file_size = trim ($content[2]);
+ $key = trim ($content[3], NL);
+ $time = trim ($content[4]);
+ $md5 = trim ($content[5]);
+ $onetime = trim ($content[6]);
+ $link_code = trim ($content[9]);
- require(JIRAFEAU_ROOT . 'lib/template/header.php');
- echo '' . _('File not available.') . '
';
- require(JIRAFEAU_ROOT . 'lib/template/footer.php');
- exit;
- }
+ if (!file_exists (VAR_FILES.$md5))
+ {
+ jirafeau_delete ($link_name);
+ require (JIRAFEAU_ROOT.'lib/template/header.php');
+ echo ''._('File not available.').
+ '
';
+ require (JIRAFEAU_ROOT.'lib/template/footer.php');
+ exit;
+ }
- if($time != JIRAFEAU_INFINITY) {
- if(time() > $time) {
- jirafeau_delete($link_name);
+ if (!empty ($delete_code) && $delete_code == $link_code)
+ {
+ jirafeau_delete ($link_name);
+ require (JIRAFEAU_ROOT.'lib/template/header.php');
+ echo ''._('File has been deleted.').
+ '
';
+ require (JIRAFEAU_ROOT.'lib/template/footer.php');
+ exit;
+ }
- require(JIRAFEAU_ROOT . 'lib/template/header.php');
- echo '' . _('The time limit of this file has expired. It has been deleted.') . '
';
- require(JIRAFEAU_ROOT . 'lib/template/footer.php');
- exit;
- }
- }
+ if ($time != JIRAFEAU_INFINITY && time ()> $time)
+ {
+ jirafeau_delete ($link_name);
+ require (JIRAFEAU_ROOT.'lib/template/header.php');
+ echo ''.
+ _('The time limit of this file has expired.' .
+ 'It has been deleted.') . '
';
+ require (JIRAFEAU_ROOT.'lib/template/footer.php');
+ exit;
+ }
- if(!empty($key)) {
- if(!isset($_POST['key'])) {
- require(JIRAFEAU_ROOT . 'lib/template/header.php');
-?>
-
-
+ Error 403: Forbidden
';
- require(JIRAFEAU_ROOT . 'lib/template/footer.php');
- exit;
+ require (JIRAFEAU_ROOT.'lib/template/header.php');
+ echo '';
+ require (JIRAFEAU_ROOT.'lib/template/footer.php');
+ exit;
+ }
+ }
}
- }
- }
- header('Content-Length: ' . $file_size);
- header('Content-Type: ' . $mime_type);
- if(!jirafeau_is_viewable($mime_type)) {
- header('Content-Disposition: attachment; filename="' . $file_name . '"');
- }
- readfile(VAR_FILES . $md5);
+ header ('Content-Length: ' . $file_size);
+ header ('Content-Type: ' . $mime_type);
+ if (!jirafeau_is_viewable ($mime_type))
+ {
+ header ('Content-Disposition: attachment; filename="' .
+ $file_name . '"');
+ }
+ readfile (VAR_FILES.$md5);
- if($onetime == 'O') {
- jirafeau_delete($link_name);
+ if ($onetime == 'O')
+ jirafeau_delete ($link_name);
+ exit;
}
- exit;
- } else {
- header("HTTP/1.0 404 Not Found");
+ else
+ {
+ header ("HTTP/1.0 404 Not Found");
- require(JIRAFEAU_ROOT . 'lib/template/header.php');
- echo '';
- require(JIRAFEAU_ROOT . 'lib/template/footer.php');
+ require (JIRAFEAU_ROOT.'lib/template/header.php');
+ echo '';
+ require (JIRAFEAU_ROOT.'lib/template/footer.php');
+ exit;
+ }
+}
+else
+{
+ header ('Location: '.$cfg['web_root']);
exit;
- }
-} else {
- header('Location: ' . $cfg['web_root']);
- exit;
}
?>