UploadController.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332
  1. <?php
  2. namespace App\Controllers;
  3. use App\Exceptions\UnauthorizedException;
  4. use Intervention\Image\ImageManagerStatic as Image;
  5. use League\Flysystem\FileExistsException;
  6. use League\Flysystem\FileNotFoundException;
  7. use League\Flysystem\Filesystem;
  8. use Slim\Exception\NotFoundException;
  9. use Slim\Http\Request;
  10. use Slim\Http\Response;
  11. use Slim\Http\Stream;
  12. class UploadController extends Controller
  13. {
  14. /**
  15. * @param Request $request
  16. * @param Response $response
  17. * @return Response
  18. * @throws FileExistsException
  19. */
  20. public function upload(Request $request, Response $response): Response
  21. {
  22. $json = ['message' => null];
  23. if ($request->getParam('token') === null) {
  24. $json['message'] = 'Token not specified.';
  25. return $response->withJson($json, 400);
  26. }
  27. $user = $this->database->query('SELECT * FROM `users` WHERE `token` = ? LIMIT 1', $request->getParam('token'))->fetch();
  28. if (!$user) {
  29. $json['message'] = 'Token specified not found.';
  30. return $response->withJson($json, 404);
  31. }
  32. if (!$user->active) {
  33. $json['message'] = 'Account disabled.';
  34. return $response->withJson($json, 401);
  35. }
  36. do {
  37. $code = uniqid();
  38. } while ($this->database->query('SELECT COUNT(*) AS `count` FROM `uploads` WHERE `code` = ?', $code)->fetch()->count > 0);
  39. /** @var \Psr\Http\Message\UploadedFileInterface $file */
  40. $file = $request->getUploadedFiles()['upload'];
  41. $fileInfo = pathinfo($file->getClientFilename());
  42. $storagePath = "$user->user_code/$code.$fileInfo[extension]";
  43. storage()->writeStream($storagePath, $file->getStream()->detach());
  44. $this->database->query('INSERT INTO `uploads`(`user_id`, `code`, `filename`, `storage_path`) VALUES (?, ?, ?, ?)', [
  45. $user->id,
  46. $code,
  47. $file->getClientFilename(),
  48. $storagePath,
  49. ]);
  50. $json['message'] = 'OK.';
  51. $json['url'] = urlFor("/$user->user_code/$code.$fileInfo[extension]");
  52. $this->logger->info("User $user->username uploaded new media.", [$this->database->raw()->lastInsertId()]);
  53. return $response->withJson($json, 201);
  54. }
  55. /**
  56. * @param Request $request
  57. * @param Response $response
  58. * @param $args
  59. * @return Response
  60. * @throws FileNotFoundException
  61. * @throws NotFoundException
  62. */
  63. public function show(Request $request, Response $response, $args): Response
  64. {
  65. $media = $this->getMedia($args['userCode'], $args['mediaCode']);
  66. if (!$media || (!$media->published && $this->session->get('user_id') !== $media->user_id && !$this->session->get('admin', false))) {
  67. throw new NotFoundException($request, $response);
  68. }
  69. if (isBot($request->getHeaderLine('User-Agent'))) {
  70. return $this->streamMedia($request, $response, storage(), $media);
  71. } else {
  72. $filesystem = storage();
  73. try {
  74. $media->mimetype = $filesystem->getMimetype($media->storage_path);
  75. $media->size = humanFileSize($filesystem->getSize($media->storage_path));
  76. $type = explode('/', $media->mimetype)[0];
  77. if ($type === 'text') {
  78. $media->text = $filesystem->read($media->storage_path);
  79. } else if (in_array($type, ['image', 'video'])) {
  80. $url = urlFor("/$args[userCode]/$args[mediaCode]/raw");
  81. $header = "<{$url}>; rel=preload; as={$type}";
  82. if ($this->session->get('logged', false)) {
  83. $header .= '; nopush';
  84. }
  85. $response = $response->withHeader('Link', $header);
  86. }
  87. } catch (FileNotFoundException $e) {
  88. throw new NotFoundException($request, $response);
  89. }
  90. return $this->view->render($response, 'upload/public.twig', [
  91. 'delete_token' => isset($args['token']) ? $args['token'] : null,
  92. 'media' => $media,
  93. 'extension' => pathinfo($media->filename, PATHINFO_EXTENSION),
  94. ]);
  95. }
  96. }
  97. /**
  98. * @param Request $request
  99. * @param Response $response
  100. * @param $args
  101. * @return Response
  102. * @throws NotFoundException
  103. * @throws UnauthorizedException
  104. */
  105. public function deleteByToken(Request $request, Response $response, $args): Response
  106. {
  107. $media = $this->getMedia($args['userCode'], $args['mediaCode']);
  108. if (!$media) {
  109. throw new NotFoundException($request, $response);
  110. }
  111. $user = $this->database->query('SELECT `id`, `active` FROM `users` WHERE `token` = ? LIMIT 1', $args['token'])->fetch();
  112. if (!$user) {
  113. $this->session->alert(lang('token_not_found'), 'danger');
  114. return $response->withRedirect($request->getHeaderLine('HTTP_REFERER'));
  115. }
  116. if (!$user->active) {
  117. $this->session->alert(lang('account_disabled'), 'danger');
  118. return $response->withRedirect($request->getHeaderLine('HTTP_REFERER'));
  119. }
  120. if ($this->session->get('admin', false) || $user->id === $media->user_id) {
  121. try {
  122. storage()->delete($media->storage_path);
  123. } catch (FileNotFoundException $e) {
  124. throw new NotFoundException($request, $response);
  125. } finally {
  126. $this->database->query('DELETE FROM `uploads` WHERE `id` = ?', $media->mediaId);
  127. $this->logger->info('User ' . $user->username . ' deleted a media via token.', [$media->mediaId]);
  128. }
  129. } else {
  130. throw new UnauthorizedException();
  131. }
  132. return redirect($response, 'home');
  133. }
  134. /**
  135. * @param Request $request
  136. * @param Response $response
  137. * @param $args
  138. * @return Response
  139. * @throws NotFoundException
  140. * @throws FileNotFoundException
  141. */
  142. public function getRawById(Request $request, Response $response, $args): Response
  143. {
  144. $media = $this->database->query('SELECT * FROM `uploads` WHERE `id` = ? LIMIT 1', $args['id'])->fetch();
  145. if (!$media) {
  146. throw new NotFoundException($request, $response);
  147. }
  148. return $this->streamMedia($request, $response, storage(), $media);
  149. }
  150. /**
  151. * @param Request $request
  152. * @param Response $response
  153. * @param $args
  154. * @return Response
  155. * @throws NotFoundException
  156. * @throws FileNotFoundException
  157. */
  158. public function showRaw(Request $request, Response $response, $args): Response
  159. {
  160. $media = $this->getMedia($args['userCode'], $args['mediaCode']);
  161. if (!$media || !$media->published && $this->session->get('user_id') !== $media->user_id && !$this->session->get('admin', false)) {
  162. throw new NotFoundException($request, $response);
  163. }
  164. return $this->streamMedia($request, $response, storage(), $media);
  165. }
  166. /**
  167. * @param Request $request
  168. * @param Response $response
  169. * @param $args
  170. * @return Response
  171. * @throws NotFoundException
  172. * @throws FileNotFoundException
  173. */
  174. public function download(Request $request, Response $response, $args): Response
  175. {
  176. $media = $this->getMedia($args['userCode'], $args['mediaCode']);
  177. if (!$media || !$media->published && $this->session->get('user_id') !== $media->user_id && !$this->session->get('admin', false)) {
  178. throw new NotFoundException($request, $response);
  179. }
  180. return $this->streamMedia($request, $response, storage(), $media, 'attachment');
  181. }
  182. /**
  183. * @param Request $request
  184. * @param Response $response
  185. * @param $args
  186. * @return Response
  187. * @throws NotFoundException
  188. */
  189. public function togglePublish(Request $request, Response $response, $args): Response
  190. {
  191. if ($this->session->get('admin')) {
  192. $media = $this->database->query('SELECT * FROM `uploads` WHERE `id` = ? LIMIT 1', $args['id'])->fetch();
  193. } else {
  194. $media = $this->database->query('SELECT * FROM `uploads` WHERE `id` = ? AND `user_id` = ? LIMIT 1', [$args['id'], $this->session->get('user_id')])->fetch();
  195. }
  196. if (!$media) {
  197. throw new NotFoundException($request, $response);
  198. }
  199. $this->database->query('UPDATE `uploads` SET `published`=? WHERE `id`=?', [$media->published ? 0 : 1, $media->id]);
  200. return $response->withStatus(200);
  201. }
  202. /**
  203. * @param Request $request
  204. * @param Response $response
  205. * @param $args
  206. * @return Response
  207. * @throws NotFoundException
  208. * @throws UnauthorizedException
  209. */
  210. public function delete(Request $request, Response $response, $args): Response
  211. {
  212. $media = $this->database->query('SELECT * FROM `uploads` WHERE `id` = ? LIMIT 1', $args['id'])->fetch();
  213. if (!$media) {
  214. throw new NotFoundException($request, $response);
  215. }
  216. if ($this->session->get('admin', false) || $media->user_id === $this->session->get('user_id')) {
  217. try {
  218. storage()->delete($media->storage_path);
  219. } catch (FileNotFoundException $e) {
  220. throw new NotFoundException($request, $response);
  221. } finally {
  222. $this->database->query('DELETE FROM `uploads` WHERE `id` = ?', $args['id']);
  223. $this->logger->info('User ' . $this->session->get('username') . ' deleted a media.', [$args['id']]);
  224. $this->session->set('used_space', humanFileSize($this->getUsedSpaceByUser($this->session->get('user_id'))));
  225. }
  226. } else {
  227. throw new UnauthorizedException();
  228. }
  229. return $response->withStatus(200);
  230. }
  231. /**
  232. * @param $userCode
  233. * @param $mediaCode
  234. * @return mixed
  235. */
  236. protected function getMedia($userCode, $mediaCode)
  237. {
  238. $mediaCode = pathinfo($mediaCode)['filename'];
  239. $media = $this->database->query('SELECT `uploads`.*, `users`.*, `users`.`id` AS `userId`, `uploads`.`id` AS `mediaId` FROM `uploads` INNER JOIN `users` ON `uploads`.`user_id` = `users`.`id` WHERE `user_code` = ? AND `uploads`.`code` = ? LIMIT 1', [
  240. $userCode,
  241. $mediaCode,
  242. ])->fetch();
  243. return $media;
  244. }
  245. /**
  246. * @param Request $request
  247. * @param Response $response
  248. * @param Filesystem $storage
  249. * @param $media
  250. * @param string $disposition
  251. * @return Response
  252. * @throws FileNotFoundException
  253. */
  254. protected function streamMedia(Request $request, Response $response, Filesystem $storage, $media, string $disposition = 'inline'): Response
  255. {
  256. $mime = $storage->getMimetype($media->storage_path);
  257. if ($request->getParam('width') !== null && explode('/', $mime)[0] === 'image') {
  258. $image = Image::make($storage->readStream($media->storage_path))
  259. ->resizeCanvas(
  260. $request->getParam('width'),
  261. $request->getParam('height'),
  262. 'center')
  263. ->encode('png');
  264. return $response
  265. ->withHeader('Content-Type', 'image/png')
  266. ->withHeader('Content-Disposition', $disposition . ';filename="scaled-' . pathinfo($media->filename)['filename'] . '.png"')
  267. ->write($image);
  268. } else {
  269. return $response
  270. ->withHeader('Content-Type', $mime)
  271. ->withHeader('Content-Disposition', $disposition . '; filename="' . $media->filename . '"')
  272. ->withHeader('Content-Length', $storage->getSize($media->storage_path))
  273. ->withBody(new Stream($storage->readStream($media->storage_path)));
  274. }
  275. }
  276. }