17fb7960fSChristopher Smith<?php 2*24870174SAndreas Gohruse dokuwiki\HTTP\Headers; 3*24870174SAndreas Gohruse dokuwiki\Utf8\PhpString; 47fb7960fSChristopher Smith/** 57fb7960fSChristopher Smith * Functions used by lib/exe/fetch.php 67fb7960fSChristopher Smith * (not included by other parts of dokuwiki) 77fb7960fSChristopher Smith */ 87fb7960fSChristopher Smith 97fb7960fSChristopher Smith/** 107fb7960fSChristopher Smith * Set headers and send the file to the client 117fb7960fSChristopher Smith * 127fb7960fSChristopher Smith * The $cache parameter influences how long files may be kept in caches, the $public parameter 137fb7960fSChristopher Smith * influences if this caching may happen in public proxis or in the browser cache only FS#2734 147fb7960fSChristopher Smith * 157fb7960fSChristopher Smith * This function will abort the current script when a 304 is sent or file sending is handled 167fb7960fSChristopher Smith * through x-sendfile 177fb7960fSChristopher Smith * 187fb7960fSChristopher Smith * @param string $file local file to send 197fb7960fSChristopher Smith * @param string $mime mime type of the file 207fb7960fSChristopher Smith * @param bool $dl set to true to force a browser download 217fb7960fSChristopher Smith * @param int $cache remaining cache time in seconds (-1 for $conf['cache'], 0 for no-cache) 227fb7960fSChristopher Smith * @param bool $public is this a public ressource or a private one? 232fd6745dSGerry Weißbach * @param string $orig original file to send - the file name will be used for the Content-Disposition 246cda96e3SAndreas Gohr * @param array $csp The ContentSecurityPolicy to send 256cda96e3SAndreas Gohr * @author Andreas Gohr <andi@splitbrain.org> 266cda96e3SAndreas Gohr * @author Ben Coburn <btcoburn@silicodon.net> 276cda96e3SAndreas Gohr * @author Gerry Weissbach <dokuwiki@gammaproduction.de> 286cda96e3SAndreas Gohr * 297fb7960fSChristopher Smith */ 306cda96e3SAndreas Gohrfunction sendFile($file, $mime, $dl, $cache, $public = false, $orig = null, $csp=[]) { 317fb7960fSChristopher Smith global $conf; 327fb7960fSChristopher Smith // send mime headers 337fb7960fSChristopher Smith header("Content-Type: $mime"); 347fb7960fSChristopher Smith 356cda96e3SAndreas Gohr // send security policy if given 36*24870174SAndreas Gohr if (!empty($csp)) Headers::contentSecurityPolicy($csp); 376cda96e3SAndreas Gohr 387fb7960fSChristopher Smith // calculate cache times 397fb7960fSChristopher Smith if ($cache == -1) { 407fb7960fSChristopher Smith $maxage = max($conf['cachetime'], 3600); // cachetime or one hour 417fb7960fSChristopher Smith $expires = time() + $maxage; 427fb7960fSChristopher Smith } elseif ($cache > 0) { 437fb7960fSChristopher Smith $maxage = $cache; // given time 447fb7960fSChristopher Smith $expires = time() + $maxage; 457fb7960fSChristopher Smith } else { // $cache == 0 467fb7960fSChristopher Smith $maxage = 0; 477fb7960fSChristopher Smith $expires = 0; // 1970-01-01 487fb7960fSChristopher Smith } 497fb7960fSChristopher Smith 507fb7960fSChristopher Smith // smart http caching headers 517fb7960fSChristopher Smith if($maxage) { 527fb7960fSChristopher Smith if($public) { 537fb7960fSChristopher Smith // cache publically 547fb7960fSChristopher Smith header('Expires: '.gmdate("D, d M Y H:i:s", $expires).' GMT'); 557fb7960fSChristopher Smith header('Cache-Control: public, proxy-revalidate, no-transform, max-age='.$maxage); 567fb7960fSChristopher Smith } else { 577fb7960fSChristopher Smith // cache in browser 587fb7960fSChristopher Smith header('Expires: '.gmdate("D, d M Y H:i:s", $expires).' GMT'); 597fb7960fSChristopher Smith header('Cache-Control: private, no-transform, max-age='.$maxage); 607fb7960fSChristopher Smith } 617fb7960fSChristopher Smith } else { 627fb7960fSChristopher Smith // no cache at all 637fb7960fSChristopher Smith header('Expires: Thu, 01 Jan 1970 00:00:00 GMT'); 647fb7960fSChristopher Smith header('Cache-Control: no-cache, no-transform'); 657fb7960fSChristopher Smith } 667fb7960fSChristopher Smith 677fb7960fSChristopher Smith //send important headers first, script stops here if '304 Not Modified' response 687fb7960fSChristopher Smith $fmtime = @filemtime($file); 697fb7960fSChristopher Smith http_conditionalRequest($fmtime); 707fb7960fSChristopher Smith 712fd6745dSGerry Weißbach // Use the current $file if is $orig is not set. 722fd6745dSGerry Weißbach if ( $orig == null ) { 732fd6745dSGerry Weißbach $orig = $file; 742fd6745dSGerry Weißbach } 752fd6745dSGerry Weißbach 767fb7960fSChristopher Smith //download or display? 777fb7960fSChristopher Smith if ($dl) { 786ce3e5f8SAndreas Gohr header('Content-Disposition: attachment;' . rfc2231_encode( 79*24870174SAndreas Gohr 'filename', PhpString::basename($orig)) . ';' 806ce3e5f8SAndreas Gohr ); 817fb7960fSChristopher Smith } else { 826ce3e5f8SAndreas Gohr header('Content-Disposition: inline;' . rfc2231_encode( 83*24870174SAndreas Gohr 'filename', PhpString::basename($orig)) . ';' 846ce3e5f8SAndreas Gohr ); 857fb7960fSChristopher Smith } 867fb7960fSChristopher Smith 877fb7960fSChristopher Smith //use x-sendfile header to pass the delivery to compatible webservers 8840e0b444SDominik Eckelmann http_sendfile($file); 897fb7960fSChristopher Smith 907fb7960fSChristopher Smith // send file contents 917fb7960fSChristopher Smith $fp = @fopen($file, "rb"); 927fb7960fSChristopher Smith if($fp) { 937fb7960fSChristopher Smith http_rangeRequest($fp, filesize($file), $mime); 947fb7960fSChristopher Smith } else { 957fb7960fSChristopher Smith http_status(500); 967fb7960fSChristopher Smith print "Could not read $file - bad permissions?"; 977fb7960fSChristopher Smith } 987fb7960fSChristopher Smith} 997fb7960fSChristopher Smith 1007fb7960fSChristopher Smith/** 10104585e6cSGerry Weißbach * Try an rfc2231 compatible encoding. This ensures correct 10204585e6cSGerry Weißbach * interpretation of filenames outside of the ASCII set. 10304585e6cSGerry Weißbach * This seems to be needed for file names with e.g. umlauts that 10404585e6cSGerry Weißbach * would otherwise decode wrongly in IE. 10504585e6cSGerry Weißbach * 10604585e6cSGerry Weißbach * There is no additional checking, just the encoding and setting the key=value for usage in headers 10704585e6cSGerry Weißbach * 10804585e6cSGerry Weißbach * @author Gerry Weissbach <gerry.w@gammaproduction.de> 10904585e6cSGerry Weißbach * @param string $name name of the field to be set in the header() call 11004585e6cSGerry Weißbach * @param string $value value of the field to be set in the header() call 11104585e6cSGerry Weißbach * @param string $charset used charset for the encoding of value 11204585e6cSGerry Weißbach * @param string $lang language used. 11304585e6cSGerry Weißbach * @return string in the format " name=value" for values WITHOUT special characters 11404585e6cSGerry Weißbach * @return string in the format " name*=charset'lang'value" for values WITH special characters 11504585e6cSGerry Weißbach */ 11604585e6cSGerry Weißbachfunction rfc2231_encode($name, $value, $charset='utf-8', $lang='en') { 11764159a61SAndreas Gohr $internal = preg_replace_callback( 11864159a61SAndreas Gohr '/[\x00-\x20*\'%()<>@,;:\\\\"\/[\]?=\x80-\xFF]/', 119*24870174SAndreas Gohr static fn($match) => rawurlencode($match[0]), 12064159a61SAndreas Gohr $value 12164159a61SAndreas Gohr ); 12204585e6cSGerry Weißbach if ( $value != $internal ) { 12304585e6cSGerry Weißbach return ' '.$name.'*='.$charset."'".$lang."'".$internal; 12404585e6cSGerry Weißbach } else { 12504585e6cSGerry Weißbach return ' '.$name.'="'.$value.'"'; 12604585e6cSGerry Weißbach } 12704585e6cSGerry Weißbach} 12804585e6cSGerry Weißbach 12904585e6cSGerry Weißbach/** 1307fb7960fSChristopher Smith * Check for media for preconditions and return correct status code 1317fb7960fSChristopher Smith * 1327fb7960fSChristopher Smith * READ: MEDIA, MIME, EXT, CACHE 1337fb7960fSChristopher Smith * WRITE: MEDIA, FILE, array( STATUS, STATUSMESSAGE ) 1347fb7960fSChristopher Smith * 1357fb7960fSChristopher Smith * @author Gerry Weissbach <gerry.w@gammaproduction.de> 13642ea7f44SGerrit Uitslag * 137f481fb8cSKlap-in * @param string $media reference to the media id 138f481fb8cSKlap-in * @param string $file reference to the file variable 139f481fb8cSKlap-in * @param string $rev 140f481fb8cSKlap-in * @param int $width 141f481fb8cSKlap-in * @param int $height 14242ea7f44SGerrit Uitslag * @return array as array(STATUS, STATUSMESSAGE) 1437fb7960fSChristopher Smith */ 1447fb7960fSChristopher Smithfunction checkFileStatus(&$media, &$file, $rev = '', $width=0, $height=0) { 1457fb7960fSChristopher Smith global $MIME, $EXT, $CACHE, $INPUT; 1467fb7960fSChristopher Smith 1477fb7960fSChristopher Smith //media to local file 1483e7e6067SKlap-in if(media_isexternal($media)) { 149cc036f74SKlap-in //check token for external image and additional for resized and cached images 150cc036f74SKlap-in if(media_get_token($media, $width, $height) !== $INPUT->str('tok')) { 151*24870174SAndreas Gohr return [412, 'Precondition Failed']; 1527fb7960fSChristopher Smith } 1537fb7960fSChristopher Smith //handle external images 1547fb7960fSChristopher Smith if(strncmp($MIME, 'image/', 6) == 0) $file = media_get_from_URL($media, $EXT, $CACHE); 1557fb7960fSChristopher Smith if(!$file) { 1567fb7960fSChristopher Smith //download failed - redirect to original URL 157*24870174SAndreas Gohr return [302, $media]; 1587fb7960fSChristopher Smith } 1597fb7960fSChristopher Smith } else { 1607fb7960fSChristopher Smith $media = cleanID($media); 1617fb7960fSChristopher Smith if(empty($media)) { 162*24870174SAndreas Gohr return [400, 'Bad request']; 1637fb7960fSChristopher Smith } 1647fb7960fSChristopher Smith // check token for resized images 1657fb7960fSChristopher Smith if (($width || $height) && media_get_token($media, $width, $height) !== $INPUT->str('tok')) { 166*24870174SAndreas Gohr return [412, 'Precondition Failed']; 1677fb7960fSChristopher Smith } 1687fb7960fSChristopher Smith 1697fb7960fSChristopher Smith //check permissions (namespace only) 1707fb7960fSChristopher Smith if(auth_quickaclcheck(getNS($media).':X') < AUTH_READ) { 171*24870174SAndreas Gohr return [403, 'Forbidden']; 1727fb7960fSChristopher Smith } 1737fb7960fSChristopher Smith $file = mediaFN($media, $rev); 1747fb7960fSChristopher Smith } 1757fb7960fSChristopher Smith 1767fb7960fSChristopher Smith //check file existance 17779e79377SAndreas Gohr if(!file_exists($file)) { 178*24870174SAndreas Gohr return [404, 'Not Found']; 1797fb7960fSChristopher Smith } 1807fb7960fSChristopher Smith 181*24870174SAndreas Gohr return [200, null]; 1827fb7960fSChristopher Smith} 1837fb7960fSChristopher Smith 1847fb7960fSChristopher Smith/** 1857fb7960fSChristopher Smith * Returns the wanted cachetime in seconds 1867fb7960fSChristopher Smith * 1877fb7960fSChristopher Smith * Resolves named constants 1887fb7960fSChristopher Smith * 1897fb7960fSChristopher Smith * @author Andreas Gohr <andi@splitbrain.org> 19042ea7f44SGerrit Uitslag * 19142ea7f44SGerrit Uitslag * @param string $cache 19242ea7f44SGerrit Uitslag * @return int cachetime in seconds 1937fb7960fSChristopher Smith */ 1947fb7960fSChristopher Smithfunction calc_cache($cache) { 1957fb7960fSChristopher Smith global $conf; 1967fb7960fSChristopher Smith 1977fb7960fSChristopher Smith if(strtolower($cache) == 'nocache') return 0; //never cache 1987fb7960fSChristopher Smith if(strtolower($cache) == 'recache') return $conf['cachetime']; //use standard cache 1997fb7960fSChristopher Smith return -1; //cache endless 2007fb7960fSChristopher Smith} 201