index-file.php 2.2 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586
  1. <?php
  2. define('DS', DIRECTORY_SEPARATOR);
  3. define('APP_PATH_ROOT', dirname(__FILE__));
  4. define('APP_PATH_LIB', APP_PATH_ROOT . '/se-lib');
  5. define('APP_PATH_WWW', APP_PATH_ROOT);
  6. define('APP_PATH_CONFIG', APP_PATH_ROOT . DS . 'config');
  7. session_start();
  8. date_default_timezone_set('Europe/Warsaw');// PHP 5 >= 5.1.0 required by date functions
  9. error_reporting(1);
  10. ini_set('error_reporting', 1);
  11. ini_set('display_startup_errors','1');
  12. //display_startup_errors(0);
  13. #TEST $_SESSION['DEBUG'] = 3;// TODO: TEST
  14. if (!isset($_SESSION['DEBUG'])) $_SESSION['DEBUG'] = 0;// set default value
  15. if (file_exists(APP_PATH_ROOT . "/config/.config_{$_SERVER['SERVER_NAME']}.php")) {
  16. require APP_PATH_ROOT . "/config/.config_{$_SERVER['SERVER_NAME']}.php";
  17. }
  18. if (file_exists(APP_PATH_ROOT . "/.config.php")) include APP_PATH_ROOT . "/.config.php";
  19. require_once APP_PATH_ROOT . "/superedit-SEF.php";
  20. SEF('DEBUG_S');
  21. require_once APP_PATH_LIB . '/' . 'Lib.php';
  22. Lib::loadClass('V');
  23. Lib::loadClass('DB');
  24. Lib::loadClass('User');
  25. Lib::loadClass('S');
  26. User::auth();// die if not logged in
  27. /* example:
  28. [zasobID] => 636
  29. [id] => 2773
  30. [file] => 2014-07-11_wizytowki_michal_zaleski_wzor_bn2.bcard/Screen Shot 2014-07-11 at 15.58.15.png
  31. */
  32. $zasobID = V::get('zasobID', 0, $_GET, 'int');
  33. $recordID = V::get('id', 0, $_GET, 'int');
  34. $fileName = V::get('file', '', $_GET);
  35. if (!$zasobID || !$recordID || empty($fileName)) {
  36. header('HTTP/1.0 406 Not Acceptable');
  37. exit;
  38. }
  39. if (false !== strpos($fileName, '../')) {
  40. header('HTTP/1.0 403 Forbidden');
  41. echo '..';
  42. exit;
  43. }
  44. $userAcl = User::getAcl();
  45. $tblAcl = $userAcl->getTableAcl($zasobID);
  46. if (!$tblAcl->isInitialized()) {
  47. echo'<p class="red">'."Brak konfiguracji dla ".$tblAcl->getName()."!".'</p>';
  48. return;
  49. }
  50. Lib::loadClass('TableAjax');
  51. if (!class_exists('TableAjax')) {
  52. die('Error: cls not exists TableAjax');
  53. }
  54. $tblObj = new TableAjax($tblAcl);
  55. try {
  56. $tblObj->sendFileContent($recordID, $fileName);
  57. }
  58. catch (Exception $e) {
  59. switch ($e->getCode()) {
  60. case 404: header('HTTP/1.0 404 Not Found'); break;
  61. case 403: header('HTTP/1.0 403 Forbidden'); break;
  62. case 4033: header('HTTP/1.0 403.3 - Write access forbidden'); break;
  63. default:
  64. }
  65. header('Content-Type: text/html; charset=utf-8');
  66. echo $e->getMessage();
  67. }