17fb7960fSChristopher Smith<?php 2d4f83172SAndreas Gohr 324870174SAndreas Gohruse dokuwiki\HTTP\Headers; 424870174SAndreas Gohruse dokuwiki\Utf8\PhpString; 5d4f83172SAndreas Gohr 67fb7960fSChristopher Smith/** 77fb7960fSChristopher Smith * Functions used by lib/exe/fetch.php 87fb7960fSChristopher Smith * (not included by other parts of dokuwiki) 97fb7960fSChristopher Smith */ 107fb7960fSChristopher Smith 117fb7960fSChristopher Smith/** 127fb7960fSChristopher Smith * Set headers and send the file to the client 137fb7960fSChristopher Smith * 147fb7960fSChristopher Smith * The $cache parameter influences how long files may be kept in caches, the $public parameter 157fb7960fSChristopher Smith * influences if this caching may happen in public proxis or in the browser cache only FS#2734 167fb7960fSChristopher Smith * 177fb7960fSChristopher Smith * This function will abort the current script when a 304 is sent or file sending is handled 187fb7960fSChristopher Smith * through x-sendfile 197fb7960fSChristopher Smith * 207fb7960fSChristopher Smith * @param string $file local file to send 217fb7960fSChristopher Smith * @param string $mime mime type of the file 227fb7960fSChristopher Smith * @param bool $dl set to true to force a browser download 237fb7960fSChristopher Smith * @param int $cache remaining cache time in seconds (-1 for $conf['cache'], 0 for no-cache) 247fb7960fSChristopher Smith * @param bool $public is this a public ressource or a private one? 252fd6745dSGerry Weißbach * @param string $orig original file to send - the file name will be used for the Content-Disposition 266cda96e3SAndreas Gohr * @param array $csp The ContentSecurityPolicy to send 276cda96e3SAndreas Gohr * @author Andreas Gohr <andi@splitbrain.org> 286cda96e3SAndreas Gohr * @author Ben Coburn <btcoburn@silicodon.net> 296cda96e3SAndreas Gohr * @author Gerry Weissbach <dokuwiki@gammaproduction.de> 306cda96e3SAndreas Gohr * 317fb7960fSChristopher Smith */ 32d868eb89SAndreas Gohrfunction sendFile($file, $mime, $dl, $cache, $public = false, $orig = null, $csp = []) 33d868eb89SAndreas Gohr{ 347fb7960fSChristopher Smith global $conf; 357fb7960fSChristopher Smith // send mime headers 367fb7960fSChristopher Smith header("Content-Type: $mime"); 377fb7960fSChristopher Smith 386cda96e3SAndreas Gohr // send security policy if given 3924870174SAndreas Gohr if (!empty($csp)) Headers::contentSecurityPolicy($csp); 406cda96e3SAndreas Gohr 417fb7960fSChristopher Smith // calculate cache times 427fb7960fSChristopher Smith if ($cache == -1) { 437fb7960fSChristopher Smith $maxage = max($conf['cachetime'], 3600); // cachetime or one hour 447fb7960fSChristopher Smith $expires = time() + $maxage; 457fb7960fSChristopher Smith } elseif ($cache > 0) { 467fb7960fSChristopher Smith $maxage = $cache; // given time 477fb7960fSChristopher Smith $expires = time() + $maxage; 487fb7960fSChristopher Smith } else { // $cache == 0 497fb7960fSChristopher Smith $maxage = 0; 507fb7960fSChristopher Smith $expires = 0; // 1970-01-01 517fb7960fSChristopher Smith } 527fb7960fSChristopher Smith 537fb7960fSChristopher Smith // smart http caching headers 547fb7960fSChristopher Smith if ($maxage) { 557fb7960fSChristopher Smith if ($public) { 567fb7960fSChristopher Smith // cache publically 577fb7960fSChristopher Smith header('Expires: ' . gmdate("D, d M Y H:i:s", $expires) . ' GMT'); 587fb7960fSChristopher Smith header('Cache-Control: public, proxy-revalidate, no-transform, max-age=' . $maxage); 597fb7960fSChristopher Smith } else { 607fb7960fSChristopher Smith // cache in browser 617fb7960fSChristopher Smith header('Expires: ' . gmdate("D, d M Y H:i:s", $expires) . ' GMT'); 627fb7960fSChristopher Smith header('Cache-Control: private, no-transform, max-age=' . $maxage); 637fb7960fSChristopher Smith } 647fb7960fSChristopher Smith } else { 657fb7960fSChristopher Smith // no cache at all 667fb7960fSChristopher Smith header('Expires: Thu, 01 Jan 1970 00:00:00 GMT'); 677fb7960fSChristopher Smith header('Cache-Control: no-cache, no-transform'); 687fb7960fSChristopher Smith } 697fb7960fSChristopher Smith 707fb7960fSChristopher Smith //send important headers first, script stops here if '304 Not Modified' response 717fb7960fSChristopher Smith $fmtime = @filemtime($file); 727fb7960fSChristopher Smith http_conditionalRequest($fmtime); 737fb7960fSChristopher Smith 742fd6745dSGerry Weißbach // Use the current $file if is $orig is not set. 752fd6745dSGerry Weißbach if ($orig == null) { 762fd6745dSGerry Weißbach $orig = $file; 772fd6745dSGerry Weißbach } 782fd6745dSGerry Weißbach 797fb7960fSChristopher Smith //download or display? 807fb7960fSChristopher Smith if ($dl) { 816ce3e5f8SAndreas Gohr header('Content-Disposition: attachment;' . rfc2231_encode( 82dccd6b2bSAndreas Gohr 'filename', 83dccd6b2bSAndreas Gohr PhpString::basename($orig) 84dccd6b2bSAndreas Gohr ) . ';'); 857fb7960fSChristopher Smith } else { 866ce3e5f8SAndreas Gohr header('Content-Disposition: inline;' . rfc2231_encode( 87dccd6b2bSAndreas Gohr 'filename', 88dccd6b2bSAndreas Gohr PhpString::basename($orig) 89dccd6b2bSAndreas Gohr ) . ';'); 907fb7960fSChristopher Smith } 917fb7960fSChristopher Smith 927fb7960fSChristopher Smith //use x-sendfile header to pass the delivery to compatible webservers 9340e0b444SDominik Eckelmann http_sendfile($file); 947fb7960fSChristopher Smith 957fb7960fSChristopher Smith // send file contents 967fb7960fSChristopher Smith $fp = @fopen($file, "rb"); 977fb7960fSChristopher Smith if ($fp) { 987fb7960fSChristopher Smith http_rangeRequest($fp, filesize($file), $mime); 997fb7960fSChristopher Smith } else { 1007fb7960fSChristopher Smith http_status(500); 10126dfc232SAndreas Gohr echo "Could not read $file - bad permissions?"; 1027fb7960fSChristopher Smith } 1037fb7960fSChristopher Smith} 1047fb7960fSChristopher Smith 1057fb7960fSChristopher Smith/** 10604585e6cSGerry Weißbach * Try an rfc2231 compatible encoding. This ensures correct 10704585e6cSGerry Weißbach * interpretation of filenames outside of the ASCII set. 10804585e6cSGerry Weißbach * This seems to be needed for file names with e.g. umlauts that 10904585e6cSGerry Weißbach * would otherwise decode wrongly in IE. 11004585e6cSGerry Weißbach * 11104585e6cSGerry Weißbach * There is no additional checking, just the encoding and setting the key=value for usage in headers 11204585e6cSGerry Weißbach * 11304585e6cSGerry Weißbach * @author Gerry Weissbach <gerry.w@gammaproduction.de> 11404585e6cSGerry Weißbach * @param string $name name of the field to be set in the header() call 11504585e6cSGerry Weißbach * @param string $value value of the field to be set in the header() call 11604585e6cSGerry Weißbach * @param string $charset used charset for the encoding of value 11704585e6cSGerry Weißbach * @param string $lang language used. 11804585e6cSGerry Weißbach * @return string in the format " name=value" for values WITHOUT special characters 11904585e6cSGerry Weißbach * @return string in the format " name*=charset'lang'value" for values WITH special characters 12004585e6cSGerry Weißbach */ 121d868eb89SAndreas Gohrfunction rfc2231_encode($name, $value, $charset = 'utf-8', $lang = 'en') 122d868eb89SAndreas Gohr{ 12364159a61SAndreas Gohr $internal = preg_replace_callback( 12464159a61SAndreas Gohr '/[\x00-\x20*\'%()<>@,;:\\\\"\/[\]?=\x80-\xFF]/', 12524870174SAndreas Gohr static fn($match) => rawurlencode($match[0]), 12664159a61SAndreas Gohr $value 12764159a61SAndreas Gohr ); 12804585e6cSGerry Weißbach if ($value != $internal) { 12904585e6cSGerry Weißbach return ' ' . $name . '*=' . $charset . "'" . $lang . "'" . $internal; 13004585e6cSGerry Weißbach } else { 13104585e6cSGerry Weißbach return ' ' . $name . '="' . $value . '"'; 13204585e6cSGerry Weißbach } 13304585e6cSGerry Weißbach} 13404585e6cSGerry Weißbach 13504585e6cSGerry Weißbach/** 1367fb7960fSChristopher Smith * Check for media for preconditions and return correct status code 1377fb7960fSChristopher Smith * 1387fb7960fSChristopher Smith * READ: MEDIA, MIME, EXT, CACHE 1397fb7960fSChristopher Smith * WRITE: MEDIA, FILE, array( STATUS, STATUSMESSAGE ) 1407fb7960fSChristopher Smith * 1417fb7960fSChristopher Smith * @author Gerry Weissbach <gerry.w@gammaproduction.de> 14242ea7f44SGerrit Uitslag * 143f481fb8cSKlap-in * @param string $media reference to the media id 144f481fb8cSKlap-in * @param string $file reference to the file variable 145f481fb8cSKlap-in * @param string $rev 146f481fb8cSKlap-in * @param int $width 147f481fb8cSKlap-in * @param int $height 14842ea7f44SGerrit Uitslag * @return array as array(STATUS, STATUSMESSAGE) 1497fb7960fSChristopher Smith */ 150d868eb89SAndreas Gohrfunction checkFileStatus(&$media, &$file, $rev = '', $width = 0, $height = 0) 151d868eb89SAndreas Gohr{ 1527fb7960fSChristopher Smith global $MIME, $EXT, $CACHE, $INPUT; 1537fb7960fSChristopher Smith 1547fb7960fSChristopher Smith //media to local file 1553e7e6067SKlap-in if (media_isexternal($media)) { 156cc036f74SKlap-in //check token for external image and additional for resized and cached images 157cc036f74SKlap-in if (media_get_token($media, $width, $height) !== $INPUT->str('tok')) { 15824870174SAndreas Gohr return [412, 'Precondition Failed']; 1597fb7960fSChristopher Smith } 1607fb7960fSChristopher Smith //handle external images 161*6c16a3a9Sfiwswe if (str_starts_with($MIME, 'image/')) $file = media_get_from_URL($media, $EXT, $CACHE); 1627fb7960fSChristopher Smith if (!$file) { 1637fb7960fSChristopher Smith //download failed - redirect to original URL 16424870174SAndreas Gohr return [302, $media]; 1657fb7960fSChristopher Smith } 1667fb7960fSChristopher Smith } else { 1677fb7960fSChristopher Smith $media = cleanID($media); 1687fb7960fSChristopher Smith if (empty($media)) { 16924870174SAndreas Gohr return [400, 'Bad request']; 1707fb7960fSChristopher Smith } 1717fb7960fSChristopher Smith // check token for resized images 1727fb7960fSChristopher Smith if (($width || $height) && media_get_token($media, $width, $height) !== $INPUT->str('tok')) { 17324870174SAndreas Gohr return [412, 'Precondition Failed']; 1747fb7960fSChristopher Smith } 1757fb7960fSChristopher Smith 1767fb7960fSChristopher Smith //check permissions (namespace only) 1777fb7960fSChristopher Smith if (auth_quickaclcheck(getNS($media) . ':X') < AUTH_READ) { 17824870174SAndreas Gohr return [403, 'Forbidden']; 1797fb7960fSChristopher Smith } 1807fb7960fSChristopher Smith $file = mediaFN($media, $rev); 1817fb7960fSChristopher Smith } 1827fb7960fSChristopher Smith 1837fb7960fSChristopher Smith //check file existance 18479e79377SAndreas Gohr if (!file_exists($file)) { 18524870174SAndreas Gohr return [404, 'Not Found']; 1867fb7960fSChristopher Smith } 1877fb7960fSChristopher Smith 18824870174SAndreas Gohr return [200, null]; 1897fb7960fSChristopher Smith} 1907fb7960fSChristopher Smith 1917fb7960fSChristopher Smith/** 1927fb7960fSChristopher Smith * Returns the wanted cachetime in seconds 1937fb7960fSChristopher Smith * 1947fb7960fSChristopher Smith * Resolves named constants 1957fb7960fSChristopher Smith * 1967fb7960fSChristopher Smith * @author Andreas Gohr <andi@splitbrain.org> 19742ea7f44SGerrit Uitslag * 19842ea7f44SGerrit Uitslag * @param string $cache 19942ea7f44SGerrit Uitslag * @return int cachetime in seconds 2007fb7960fSChristopher Smith */ 201d868eb89SAndreas Gohrfunction calc_cache($cache) 202d868eb89SAndreas Gohr{ 2037fb7960fSChristopher Smith global $conf; 2047fb7960fSChristopher Smith 2057fb7960fSChristopher Smith if (strtolower($cache) == 'nocache') return 0; //never cache 2067fb7960fSChristopher Smith if (strtolower($cache) == 'recache') return $conf['cachetime']; //use standard cache 2077fb7960fSChristopher Smith return -1; //cache endless 2087fb7960fSChristopher Smith} 209