4 Copyright 2003,2004,2007 $ThePhpWikiProgrammingTeam
5 Copyright 2008-2009 Marc-Etienne Vargenau, Alcatel-Lucent
7 This file is part of PhpWiki.
9 PhpWiki is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 2 of the License, or
12 (at your option) any later version.
14 PhpWiki is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with PhpWiki; if not, write to the Free Software
21 Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
26 * UpLoad: Allow Administrator to upload files to a special directory,
27 * which should preferably be added to the InterWikiMap
28 * Usage: <?plugin UpLoad ?>
29 * Author: NathanGass <gass@iogram.ch>
30 * Changes: ReiniUrban <rurban@x-ray.at>,
31 * qubit <rtryon@dartmouth.edu>
32 * Marc-Etienne Vargenau, Alcatel-Lucent
33 * Note: See also Jochen Kalmbach's plugin/UserFileManagement.php
36 class WikiPlugin_UpLoad
39 var $disallowed_extensions;
40 // TODO: use PagePerms instead
41 var $only_authenticated = true; // allow only authenticated users may upload.
47 function getDescription () {
48 return _("Upload files to the local InterWiki Upload:<filename>");
51 function getVersion() {
52 return preg_replace("/[Revision: $]/", '',
56 function getDefaultArguments() {
57 return array('logfile' => 'phpwiki-upload.log',
58 // add a link of the fresh file automatically to the
59 // end of the page (or current page)
61 'page' => '[pagename]',
63 'mode' => 'actionpage', // or edit
67 function run($dbi, $argstr, &$request, $basepage) {
68 $this->allowed_extensions = explode("\n",
105 $this->disallowed_extensions = explode("\n",
143 //removed "\{[[:xdigit:]]{8}(?:-[[:xdigit:]]{4}){3}-[[:xdigit:]]{12}\}"
145 $args = $this->getArgs($argstr, $request);
148 $file_dir = getUploadFilePath();
150 $form = HTML::form(array('action' => $request->getPostURL(),
151 'enctype' => 'multipart/form-data',
152 'method' => 'post'));
153 $contents = HTML::div(array('class' => 'wikiaction'));
154 $contents->pushContent(HTML::input(array('type' => 'hidden',
155 'name' => 'MAX_FILE_SIZE',
156 'value'=> MAX_UPLOAD_SIZE)));
157 $contents->pushContent(HTML::input(array('name' => 'userfile',
160 if ($mode == 'edit') {
161 $contents->pushContent(HTML::input(array('name' => 'action',
164 $contents->pushContent(HTML::raw(" "));
165 $contents->pushContent(HTML::input(array('value' => _("Upload"),
166 'name' => 'edit[upload]',
167 'type' => 'submit')));
169 $contents->pushContent(HTML::raw(" "));
170 $contents->pushContent(HTML::input(array('value' => _("Upload"),
171 'type' => 'submit')));
173 $form->pushContent($contents);
176 if ($request->isPost() and $this->only_authenticated) {
177 // Make sure that the user is logged in.
178 $user = $request->getUser();
179 if (!$user->isAuthenticated()) {
181 if (isa($WikiTheme, 'WikiTheme_gforge')) {
182 $message->pushContent(HTML::div(array('class' => 'error'),
183 HTML::p(_("You cannot upload files.")),
185 HTML::li(_("Check you are logged in.")),
186 HTML::li(_("Check you are in the right project.")),
187 HTML::li(_("Check you are a member of the current project."))
191 $message->pushContent(HTML::div(array('class' => 'error'),
192 HTML::p(_("ACCESS DENIED: You must log in to upload files."))));
195 $result->pushContent($form);
196 $result->pushContent($message);
201 $userfile = $request->getUploadedFile('userfile');
203 $userfile_name = $userfile->getName();
204 $userfile_name = trim(basename($userfile_name));
205 if (UPLOAD_USERDIR) {
206 $file_dir .= $request->_user->_userid;
207 if (!file_exists($file_dir))
208 mkdir($file_dir, 0775);
210 $u_userfile = $request->_user->_userid . "/" . $userfile_name;
212 $u_userfile = $userfile_name;
214 $u_userfile = preg_replace("/ /", "%20", $u_userfile);
215 $userfile_tmpname = $userfile->getTmpName();
216 $err_header = HTML::div(array('class' => 'error'),
217 HTML::p(fmt("ERROR uploading '%s'", $userfile_name)));
218 if (preg_match("/(\." . join("|\.", $this->disallowed_extensions) . ")(\.|\$)/i",
221 $message->pushContent($err_header);
222 $message->pushContent(HTML::p(fmt("Files with extension %s are not allowed.",
223 join(", ", $this->disallowed_extensions))));
225 elseif (! DISABLE_UPLOAD_ONLY_ALLOWED_EXTENSIONS and
226 ! preg_match("/(\." . join("|\.", $this->allowed_extensions) . ")\$/i",
229 $message->pushContent($err_header);
230 $message->pushContent(HTML::p(fmt("Only files with the extension %s are allowed.",
231 join(", ", $this->allowed_extensions))));
233 elseif (preg_match("/[^._a-zA-Z0-9- ]/", strip_accents($userfile_name)))
235 $message->pushContent($err_header);
236 $message->pushContent(HTML::p(_("Invalid filename. File names may only contain alphanumeric characters and dot, underscore, space or dash.")));
238 elseif (file_exists($file_dir . $userfile_name)) {
239 $message->pushContent($err_header);
240 $message->pushContent(HTML::p(fmt("There is already a file with name %s uploaded.",
243 elseif ($userfile->getSize() > (MAX_UPLOAD_SIZE)) {
244 $message->pushContent($err_header);
245 $message->pushContent(HTML::p(_("Sorry but this file is too big.")));
247 elseif (move_uploaded_file($userfile_tmpname, $file_dir . $userfile_name) or
248 (IsWindows() and rename($userfile_tmpname, $file_dir . $userfile_name))
251 $interwiki = new PageType_interwikimap();
252 $link = $interwiki->link("Upload:$u_userfile");
253 $message->pushContent(HTML::div(array('class' => 'feedback'),
254 HTML::p(_("File successfully uploaded.")),
257 // the upload was a success and we need to mark this event in the "upload log"
259 $upload_log = $file_dir . basename($logfile);
260 $this->log($userfile, $upload_log, $message);
263 require_once("lib/loadsave.php");
264 $pagehandle = $dbi->getPage($page);
265 if ($pagehandle->exists()) {// don't replace default contents
266 $current = $pagehandle->getCurrentRevision();
267 $version = $current->getVersion();
268 $text = $current->getPackedContent();
269 $newtext = $text . "\n* Upload:$u_userfile"; // don't inline images
270 $meta = $current->_data;
271 $meta['summary'] = sprintf(_("uploaded %s"),$u_userfile);
272 $pagehandle->save($newtext, $version + 1, $meta);
276 $message->pushContent($err_header);
277 $message->pushContent(HTML::br(),_("Uploading failed."),HTML::br());
281 $message->pushContent(HTML::br(),_("No file selected. Please select one."),HTML::br());
284 //$result = HTML::div( array( 'class' => 'wikiaction' ) );
286 $result->pushContent($form);
287 $result->pushContent($message);
291 function log ($userfile, $upload_log, &$message) {
293 $user = $GLOBALS['request']->_user;
294 if (file_exists($upload_log) and (!is_writable($upload_log))) {
295 trigger_error(_("The upload logfile exists but is not writable."), E_USER_WARNING);
297 elseif (!$log_handle = fopen ($upload_log, "a")) {
298 trigger_error(_("Can't open the upload logfile."), E_USER_WARNING);
300 else { // file size in KB; precision of 0.1
301 $file_size = round(($userfile->getSize())/1024, 1);
302 if ($file_size <= 0) {
303 $file_size = "< 0.1";
305 $userfile_name = $userfile->getName();
308 . "<tr><td><a href=\"$userfile_name\">$userfile_name</a></td>"
309 . "<td align=\"right\">$file_size kB</td>"
310 . "<td> " . $WikiTheme->formatDate(time()) . "</td>"
311 . "<td> <em>" . $user->getId() . "</em></td></tr>");
319 // (c-file-style: "gnu")
324 // c-hanging-comment-ender-p: nil
325 // indent-tabs-mode: nil