Blame view

sources/apps/files/ajax/upload.php 5.87 KB
03e52840d   Kload   Init
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
  <?php
  
  // Firefox and Konqueror tries to download application/json for me.  --Arthur
  OCP\JSON::setContentTypeHeader('text/plain');
  
  // If a directory token is sent along check if public upload is permitted.
  // If not, check the login.
  // If no token is sent along, rely on login only
  
  $allowedPermissions = OCP\PERMISSION_ALL;
  
  $l = OC_L10N::get('files');
  if (empty($_POST['dirToken'])) {
  	// The standard case, files are uploaded through logged in users :)
  	OCP\JSON::checkLoggedIn();
  	$dir = isset($_POST['dir']) ? $_POST['dir'] : "";
  	if (!$dir || empty($dir) || $dir === false) {
  		OCP\JSON::error(array('data' => array_merge(array('message' => $l->t('Unable to set upload directory.')))));
  		die();
  	}
  } else {
  	// return only read permissions for public upload
  	$allowedPermissions = OCP\PERMISSION_READ;
  
  	$linkItem = OCP\Share::getShareByToken($_POST['dirToken']);
  	if ($linkItem === false) {
  		OCP\JSON::error(array('data' => array_merge(array('message' => $l->t('Invalid Token')))));
  		die();
  	}
  
  	if (!($linkItem['permissions'] & OCP\PERMISSION_CREATE)) {
  		OCP\JSON::checkLoggedIn();
  	} else {
  		// resolve reshares
  		$rootLinkItem = OCP\Share::resolveReShare($linkItem);
  
  		// Setup FS with owner
31b7f2792   Kload   Upgrade to ownclo...
38
  		OC_Util::tearDownFS();
03e52840d   Kload   Init
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
  		OC_Util::setupFS($rootLinkItem['uid_owner']);
  
  		// The token defines the target directory (security reasons)
  		$path = \OC\Files\Filesystem::getPath($linkItem['file_source']);
  		$dir = sprintf(
  			"/%s/%s",
  			$path,
  			isset($_POST['subdir']) ? $_POST['subdir'] : ''
  		);
  
  		if (!$dir || empty($dir) || $dir === false) {
  			OCP\JSON::error(array('data' => array_merge(array('message' => $l->t('Unable to set upload directory.')))));
  			die();
  		}
  	}
  }
  
  
  OCP\JSON::callCheck();
  
  
  // get array with current storage stats (e.g. max file size)
31b7f2792   Kload   Upgrade to ownclo...
61
  $storageStats = \OCA\Files\Helper::buildFileStorageStatistics($dir);
03e52840d   Kload   Init
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
  
  if (!isset($_FILES['files'])) {
  	OCP\JSON::error(array('data' => array_merge(array('message' => $l->t('No file was uploaded. Unknown error')), $storageStats)));
  	exit();
  }
  
  foreach ($_FILES['files']['error'] as $error) {
  	if ($error != 0) {
  		$errors = array(
  			UPLOAD_ERR_OK => $l->t('There is no error, the file uploaded with success'),
  			UPLOAD_ERR_INI_SIZE => $l->t('The uploaded file exceeds the upload_max_filesize directive in php.ini: ')
  			. ini_get('upload_max_filesize'),
  			UPLOAD_ERR_FORM_SIZE => $l->t('The uploaded file exceeds the MAX_FILE_SIZE directive that was specified in the HTML form'),
  			UPLOAD_ERR_PARTIAL => $l->t('The uploaded file was only partially uploaded'),
  			UPLOAD_ERR_NO_FILE => $l->t('No file was uploaded'),
  			UPLOAD_ERR_NO_TMP_DIR => $l->t('Missing a temporary folder'),
  			UPLOAD_ERR_CANT_WRITE => $l->t('Failed to write to disk'),
  		);
  		OCP\JSON::error(array('data' => array_merge(array('message' => $errors[$error]), $storageStats)));
  		exit();
  	}
  }
  $files = $_FILES['files'];
31b7f2792   Kload   Upgrade to ownclo...
85
  $error = false;
03e52840d   Kload   Init
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
  
  $maxUploadFileSize = $storageStats['uploadMaxFilesize'];
  $maxHumanFileSize = OCP\Util::humanFileSize($maxUploadFileSize);
  
  $totalSize = 0;
  foreach ($files['size'] as $size) {
  	$totalSize += $size;
  }
  if ($maxUploadFileSize >= 0 and $totalSize > $maxUploadFileSize) {
  	OCP\JSON::error(array('data' => array('message' => $l->t('Not enough storage available'),
  		'uploadMaxFilesize' => $maxUploadFileSize,
  		'maxHumanFilesize' => $maxHumanFileSize)));
  	exit();
  }
  
  $result = array();
  if (strpos($dir, '..') === false) {
  	$fileCount = count($files['name']);
  	for ($i = 0; $i < $fileCount; $i++) {
03e52840d   Kload   Init
105
  		// $path needs to be normalized - this failed within drag'n'drop upload to a sub-folder
31b7f2792   Kload   Upgrade to ownclo...
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
  		if (isset($_POST['resolution']) && $_POST['resolution']==='autorename') {
  			// append a number in brackets like 'filename (2).ext'
  			$target = OCP\Files::buildNotExistingFileName(stripslashes($dir), $files['name'][$i]);
  		} else {
  			$target = \OC\Files\Filesystem::normalizePath(stripslashes($dir).'/'.$files['name'][$i]);
  		}
  		
  		if ( ! \OC\Files\Filesystem::file_exists($target)
  			|| (isset($_POST['resolution']) && $_POST['resolution']==='replace')
  		) {
  			// upload and overwrite file
  			try
  			{
  				if (is_uploaded_file($files['tmp_name'][$i]) and \OC\Files\Filesystem::fromTmpFile($files['tmp_name'][$i], $target)) {
  
  					// updated max file size after upload
  					$storageStats = \OCA\Files\Helper::buildFileStorageStatistics($dir);
  
  					$meta = \OC\Files\Filesystem::getFileInfo($target);
  					if ($meta === false) {
  						$error = $l->t('Upload failed. Could not get file info.');
  					} else {
  						$result[] = array('status' => 'success',
  							'mime' => $meta['mimetype'],
  							'mtime' => $meta['mtime'],
  							'size' => $meta['size'],
  							'id' => $meta['fileid'],
  							'name' => basename($target),
  							'etag' => $meta['etag'],
  							'originalname' => $files['tmp_name'][$i],
  							'uploadMaxFilesize' => $maxUploadFileSize,
  							'maxHumanFilesize' => $maxHumanFileSize,
  							'permissions' => $meta['permissions'] & $allowedPermissions
  						);
  					}
  
  				} else {
  					$error = $l->t('Upload failed. Could not find uploaded file');
  				}
  			} catch(Exception $ex) {
  				$error = $ex->getMessage();
  			}
  			
  		} else {
  			// file already exists
03e52840d   Kload   Init
151
  			$meta = \OC\Files\Filesystem::getFileInfo($target);
03e52840d   Kload   Init
152
  			if ($meta === false) {
31b7f2792   Kload   Upgrade to ownclo...
153
  				$error = $l->t('Upload failed. Could not get file info.');
03e52840d   Kload   Init
154
  			} else {
31b7f2792   Kload   Upgrade to ownclo...
155
  				$result[] = array('status' => 'existserror',
03e52840d   Kload   Init
156
  					'mime' => $meta['mimetype'],
31b7f2792   Kload   Upgrade to ownclo...
157
  					'mtime' => $meta['mtime'],
03e52840d   Kload   Init
158
159
160
  					'size' => $meta['size'],
  					'id' => $meta['fileid'],
  					'name' => basename($target),
31b7f2792   Kload   Upgrade to ownclo...
161
162
  					'etag' => $meta['etag'],
  					'originalname' => $files['tmp_name'][$i],
03e52840d   Kload   Init
163
164
165
166
167
168
169
  					'uploadMaxFilesize' => $maxUploadFileSize,
  					'maxHumanFilesize' => $maxHumanFileSize,
  					'permissions' => $meta['permissions'] & $allowedPermissions
  				);
  			}
  		}
  	}
03e52840d   Kload   Init
170
171
172
  } else {
  	$error = $l->t('Invalid directory.');
  }
31b7f2792   Kload   Upgrade to ownclo...
173
174
175
176
177
178
  if ($error === false) {
  	OCP\JSON::encodedPrint($result);
  	exit();
  } else {
  	OCP\JSON::error(array(array('data' => array_merge(array('message' => $error), $storageStats))));
  }