PluginProbe
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder / 2.17.6
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder v2.17.6
V-3.3.0 3.2.2 3.2.1 3.2.0 3.1.4 3.1.3 3.1.2 3.1.1 3.1.0 V3.0.3 V3.0.2 -3.0.1 V_3.0.0 1.1.1 1.1.8 1.2 1.3 1.4 1.4.18 1.5.2 1.9 2.0 2.10.0 2.10.1 2.10.2 All 137 releases
← All changes | includes/Core/Util/FileDownloadProvider.php +131 -141 1.22.17.6 View file →
@@ -1,161 +1,151 @@
1 1 <?php
2 +
2 3 namespace BitCode\BitForm\Core\Util;
3 4
4 5 final class FileDownloadProvider
5 6 {
6 - public function register()
7 - {
8 - add_action('template_redirect', array($this,'authCheckandFrceDownloadHelper'));
9 - add_shortcode('bitforms-frontend-file', array($this,'handleFileDownload'));
7 + public function register()
8 + {
9 + add_action('template_redirect', [$this, 'authCheckandFrceDownloadHelper']);
10 + add_shortcode('bitforms-frontend-file', [$this, 'handleFileDownload']);
11 + }
12 +
13 + public function handleFileDownload()
14 + {
15 + if (!isset($_GET['formID']) || !isset($_GET['entryID']) || !isset($_GET['fileID'])) {
16 + global $wp_query;
17 + $wp_query->set_404();
18 + status_header(404);
19 + get_template_part(404);
20 + exit();
10 21 }
22 + $formID = intval(sanitize_text_field($_GET['formID']));
23 + $entryID = intval(sanitize_text_field($_GET['entryID']));
24 + $fileID = sanitize_file_name($_GET['fileID']);
25 + $filePath = FileHandler::getEntriesFileUploadDir($formID, $entryID) . DIRECTORY_SEPARATOR . $fileID;
11 26
12 - public function handleFileDownload()
13 - {
14 - if (!isset($_GET['formID']) || !isset($_GET['entryID']) || !isset($_GET['fileID'])) {
15 - global $wp_query;
16 - $wp_query->set_404();
17 - status_header(404);
18 - get_template_part(404);
19 - exit();
20 - }
21 - $formID = intval(sanitize_text_field($_GET['formID']));
22 - $entryID = intval(sanitize_text_field($_GET['entryID']));
23 - $fileID = sanitize_file_name($_GET['fileID']);
24 - $filePath = BITFORMS_UPLOAD_DIR.DIRECTORY_SEPARATOR.$formID.DIRECTORY_SEPARATOR.$entryID.DIRECTORY_SEPARATOR.$fileID;
25 - if (is_readable($filePath)) {
26 - $this->fileDownloadORView($file, true);
27 - }
27 + if (is_readable($filePath)) {
28 + $this->fileDownloadORView($filePath, true);
28 29 }
30 + }
29 31
30 - public static function getBaseDownloadURL()
31 - {
32 - $routes = get_option('bitforms_routes');
33 - if (isset($routes['file'])) {
34 - $file_page = get_page($routes['file']);
35 - if (empty($file_page)) {
36 - $file_route_id = wp_insert_post(
37 - array(
38 - 'post_name' => 'bitforms-file',
39 - 'comment_status' => 'closed',
40 - 'ping_status' => 'closed',
41 - 'post_content' => '<!-- wp:shortcode -->[bitforms-frontend-file /]<!-- /wp:shortcode -->',
42 - 'post_status' => 'publish',
43 - 'post_type' => 'bitforms'
44 - )
45 - );
46 - $routes['file'] = $file_route_id;
47 - update_option('bitforms_routes', $routes);
48 - $file_page_slug = get_post_permalink($file_route_id);
49 - } else {
50 - $file_page_slug = get_post_permalink($file_page->ID);
51 - }
32 + public static function getBaseDownloadURL()
33 + {
34 + $routes = get_option('bitforms_routes');
35 + if (isset($routes['file'])) {
36 + $file_page = get_post($routes['file']);
37 + if (empty($file_page)) {
38 + $file_route_id = wp_insert_post(
39 + [
40 + 'post_name' => 'bitforms-file',
41 + 'comment_status' => 'closed',
42 + 'ping_status' => 'closed',
43 + 'post_content' => '<!-- wp:shortcode -->[bitforms-frontend-file /]<!-- /wp:shortcode -->',
44 + 'post_status' => 'publish',
45 + 'post_type' => 'bitforms'
46 + ]
47 + );
48 + $routes['file'] = $file_route_id;
49 + update_option('bitforms_routes', $routes);
50 + $file_page_slug = get_post_permalink($file_route_id);
51 + } else {
52 + $file_page_slug = get_post_permalink($file_page->ID);
53 + }
54 + } else {
55 + $file_route_id = wp_insert_post(
56 + [
57 + 'post_name' => 'bitforms-file',
58 + 'comment_status' => 'closed',
59 + 'ping_status' => 'closed',
60 + 'post_content' => '<!-- wp:shortcode -->[bitforms-frontend-file /]<!-- /wp:shortcode -->',
61 + 'post_status' => 'publish',
62 + 'post_type' => 'bitforms'
63 + ]
64 + );
65 + $route_value = [];
66 + $route_value['file'] = $file_route_id;
67 + update_option('bitforms_routes', $route_value);
68 + $file_page_slug = get_post_permalink($file_route_id);
69 + }
70 +
71 + return $file_page_slug;
72 + }
73 +
74 + public function authCheckandFrceDownloadHelper()
75 + {
76 + if (!is_singular('bitforms')) {
77 + return;
78 + }
79 + global $post;
80 + if (!empty($post->post_content)) {
81 + $shortCodeRegex = get_shortcode_regex();
82 + preg_match_all('/' . $shortCodeRegex . '/', $post->post_content, $regexMatchGroups);
83 + if (!empty($regexMatchGroups[2]) && in_array('bitforms-frontend-file', $regexMatchGroups[2]) && is_user_logged_in()) {
84 + $file = $this->isRequestedFileExists();
85 + if ($file) {
86 + $this->fileDownloadORView($file, isset($_GET['download']));
52 87 } else {
53 - $file_route_id = wp_insert_post(
54 - array(
55 - 'post_name' => 'bitforms-file',
56 - 'comment_status' => 'closed',
57 - 'ping_status' => 'closed',
58 - 'post_content' => '<!-- wp:shortcode -->[bitforms-frontend-file /]<!-- /wp:shortcode -->',
59 - 'post_status' => 'publish',
60 - 'post_type' => 'bitforms'
61 - )
62 - );
63 - $route_value = array();
64 - $route_value['file'] = $file_route_id;
65 - update_option('bitforms_routes', $route_value);
66 - $file_page_slug = get_post_permalink($file_route_id);
88 + $this->show404();
67 89 }
90 + } else {
91 + auth_redirect();
92 + }
93 + }
94 + }
68 95
69 - return $file_page_slug;
70 - }
96 + private function show404()
97 + {
98 + global $wp_query;
99 + $wp_query->set_404();
100 + status_header(404);
101 + get_template_part(404);
102 + exit();
103 + }
71 104
72 - public function authCheckandFrceDownloadHelper()
73 - {
74 - if (!is_singular('bitforms')) {
75 - return;
76 - }
77 - global $post;
78 - if (!empty($post->post_content)) {
79 - $shortCodeRegex = get_shortcode_regex();
80 - preg_match_all('/'.$shortCodeRegex.'/', $post->post_content, $regexMatchGroups);
81 - if (!empty($regexMatchGroups[2]) && in_array('bitforms-frontend-file', $regexMatchGroups[2]) && is_user_logged_in()) {
82 - $file = $this->isRequestedFileExists();
83 - if ($file) {
84 - $this->fileDownloadORView($file, isset($_GET['download']));
85 - } else {
86 - $this->show404();
87 - }
88 - } else {
89 - auth_redirect();
90 - }
91 - }
105 + private function isRequestedFileExists()
106 + {
107 + if (!isset($_GET['formID']) || !isset($_GET['entryID']) || !isset($_GET['fileID'])) {
108 + return false;
92 109 }
93 -
94 - private function show404()
95 - {
96 - global $wp_query;
97 - $wp_query->set_404();
98 - status_header(404);
99 - get_template_part(404);
100 - exit();
110 + $formID = intval(sanitize_text_field($_GET['formID']));
111 + $entryID = intval(sanitize_text_field($_GET['entryID']));
112 + $fileID = sanitize_file_name($_GET['fileID']);
113 + $filePath = FileHandler::getEntriesFileUploadDir($formID, $entryID) . DIRECTORY_SEPARATOR . $fileID;
114 + if (is_readable($filePath)) {
115 + return $filePath;
101 116 }
102 - private function isRequestedFileExists()
103 - {
104 - if (!isset($_GET['formID']) || !isset($_GET['entryID']) || !isset($_GET['fileID'])) {
105 - return false;
106 - }
107 - $formID = intval(sanitize_text_field($_GET['formID']));
108 - $entryID = intval(sanitize_text_field($_GET['entryID']));
109 - $fileID = sanitize_file_name($_GET['fileID']);
110 - $filePath = BITFORMS_UPLOAD_DIR.DIRECTORY_SEPARATOR.$formID.DIRECTORY_SEPARATOR.$entryID.DIRECTORY_SEPARATOR.$fileID;
111 - if (is_readable($filePath)) {
112 - return $filePath;
113 - }
114 117
115 - return false;
116 - }
118 + return false;
119 + }
117 120
118 - private function fileDownloadORView($filePath, $forceDownload = false)
119 - {
120 - if ($forceDownload) {
121 - header("Content-Type: application/force-download");
122 - header("Content-Type: application/octet-stream");
123 - header("Content-Type: application/download");
124 - header('Content-Disposition: attachment; filename="'.basename($filePath).'"');
125 - } else {
126 - $ext = pathinfo($filePath, PATHINFO_EXTENSION);
127 - if ($ext=='pdf') {
128 - $content_types='application/pdf';
129 - } elseif ($ext=='doc') {
130 - $content_types='application/msword';
131 - } elseif ($ext=='docx') {
132 - $content_types='application/vnd.openxmlformats-officedocument.wordprocessingml.document';
133 - } elseif ($ext=='xls') {
134 - $content_types='application/vnd.ms-excel';
135 - } elseif ($ext=='xlsx') {
136 - $content_types='application/vnd.openxmlformats-officedocument.spreadsheetml.sheet';
137 - } elseif ($ext=='txt' || $ext=='php' || $ext=='html' || $ext=='xhtml' || $ext=='json') {
138 - $content_types='text/plain';
139 - } elseif ($ext=='jpg' || $ext=='jpeg' || $ext=='png' || $ext=='gif' || $ext=='tiff' || $ext=='svg' || $ext=='icon' || $ext=='ico') {
140 - $content_types="image/$ext";
141 - } elseif ($ext=='mpeg' || $ext=='mp3' || $ext=='wav') {
142 - $content_types="audio/$ext";
143 - } elseif ($ext=='mp4' || $ext=='webm' || $ext=='ogg') {
144 - $content_types="video/$ext";
145 - } else {
146 - $content_types='application/download';
147 - }
148 - header('Content-Disposition:filename="'.basename($filePath).'"');
149 - header("Content-Type: $content_types");
121 + private function fileDownloadORView($filePath, $forceDownload = false)
122 + {
123 + if ($forceDownload) {
124 + header('Content-Type: application/force-download');
125 + header('Content-Type: application/octet-stream');
126 + header('Content-Type: application/download');
127 + header('Content-Disposition: attachment; filename="' . basename($filePath) . '"');
128 + } else {
129 + $fileInfo = wp_check_filetype($filePath);
130 + $content_types = 'text/plain';
131 + if ($fileInfo['type'] && $fileInfo['ext']) {
132 + $content_types = $fileInfo['type'];
133 + $ext = $fileInfo['ext'];
134 + if (in_array($ext[1], ['txt', 'php', 'html', 'xhtml', 'json'])) {
135 + $content_types = 'text/plain';
150 136 }
151 - header('Content-Description: File Transfer');
152 - header('Expires: 0');
153 - header('Cache-Control: must-revalidate, post-check=0, pre-check=0');
154 - header('Pragma: public');
155 - header('Content-Length: ' . filesize($filePath));
156 - header("Content-Transfer-Encoding: binary ");
157 - flush();
158 - readfile($filePath);
159 - die();
137 + }
138 + header('Content-Disposition:filename="' . basename($filePath) . '"');
139 + header("Content-Type: $content_types");
160 140 }
141 + header('Content-Description: File Transfer');
142 + header('Expires: 0');
143 + header('Cache-Control: must-revalidate, post-check=0, pre-check=0');
144 + header('Pragma: public');
145 + header('Content-Length: ' . filesize($filePath));
146 + header('Content-Transfer-Encoding: binary ');
147 + flush();
148 + readfile($filePath);
149 + die();
150 + }
161 151 }