* * author : Pierrick LE GALL * * * * $Id: upload.php 556 2004-10-07 21:41:09Z z0rglub $ * * ***************************************************************************/ /*************************************************************************** * * * This program is free software; you can redistribute it and/or modify * * it under the terms of the GNU General Public License as published by * * the Free Software Foundation; * * * ***************************************************************************/ //------------------------------------------------------------------- functions // The validate_upload function checks if the image of the given path is valid. // A picture is valid when : // - width, height and filesize are not higher than the maximum // filesize authorized by the administrator // - the type of the picture is among jpg, gif and png // The function returns an array containing : // - $result['type'] contains the type of the image ('jpg', 'gif' or 'png') // - $result['error'] contains an array with the different errors // found with the picture function validate_upload( $temp_name, $my_max_file_size, $image_max_width, $image_max_height ) { global $conf, $lang; $result = array(); $result['error'] = array(); //echo $_FILES['picture']['name']."
".$temp_name; $extension = get_extension( $_FILES['picture']['name'] ); if ( !in_array( $extension, $conf['picture_ext'] ) ) { array_push( $result['error'], $lang['upload_advise_filetype'] ); return $result; } if ( !isset( $_FILES['picture'] ) ) { // do we even have a file? array_push( $result['error'], "You did not upload anything!" ); } else if ( $_FILES['picture']['size'] > $my_max_file_size * 1024 ) { array_push( $result['error'], $lang['upload_advise_filesize'].$my_max_file_size.' KB' ); } else { // check if we are allowed to upload this file_type // upload de la photo sous un nom temporaire if ( !move_uploaded_file( $_FILES['picture']['tmp_name'], $temp_name ) ) { array_push( $result['error'], $lang['upload_cannot_upload'] ); } else { $size = getimagesize( $temp_name ); if ( isset( $image_max_width ) and $image_max_width != "" and $size[0] > $image_max_width ) { array_push( $result['error'], $lang['upload_advise_width'].$image_max_width.' px' ); } if ( isset( $image_max_height ) and $image_max_height != "" and $size[1] > $image_max_height ) { array_push( $result['error'], $lang['upload_advise_height'].$image_max_height.' px' ); } // $size[2] == 1 means GIF // $size[2] == 2 means JPG // $size[2] == 3 means PNG switch ( $size[2] ) { case 1 : $result['type'] = 'gif'; break; case 2 : $result['type'] = 'jpg'; break; case 3 : $result['type'] = 'png'; break; default : array_push( $result['error'], $lang['upload_advise_filetype'] ); } } } if ( sizeof( $result['error'] ) > 0 ) { // destruction de l'image avec le nom temporaire @unlink( $temp_name ); } else { @chmod( $temp_name, 0644); } return $result; } //----------------------------------------------------------- personnal include include_once( './include/init.inc.php' ); //-------------------------------------------------- access authorization check check_login_authorization(); check_cat_id( $_GET['cat'] ); if ( isset( $page['cat'] ) and is_numeric( $page['cat'] ) ) { check_restrictions( $page['cat'] ); $result = get_cat_info( $page['cat'] ); $page['cat_dir'] = get_complete_dir( $page['cat'] ); $page['cat_site_id'] = $result['site_id']; $page['cat_name'] = $result['name']; $page['cat_uploadable'] = $result['uploadable']; if ( $page['cat_site_id'] != 1 or !$conf['upload_available'] or !$page['cat_uploadable'] ) { echo '
'.$lang['upload_forbidden'].'
'; echo ''; echo $lang['thumbnails'].'
'; exit(); } } //----------------------------------------------------- template initialization // // Start output of page // $title= $lang['upload_title']; include('include/page_header.php'); $handle = $vtp->Open( './template/'.$user['template'].'/upload.vtp' ); initialize_template(); $tpl = array( 'upload_title', 'upload_username', 'mail_address', 'submit', 'upload_successful', 'search_return_main_page','upload_author', 'upload_name','upload_creation_date','upload_comment', 'mandatory' ); templatize_array( $tpl, 'lang', $handle ); $error = array(); $page['upload_successful'] = false; if ( isset( $_GET['waiting_id'] ) ) { $page['waiting_id'] = $_GET['waiting_id']; } //-------------------------------------------------------------- picture upload // verfying fields if ( isset( $_POST['submit'] ) and !isset( $_GET['waiting_id'] ) ) { $path = $page['cat_dir'].$_FILES['picture']['name']; if ( @is_file( $path ) ) { array_push( $error, $lang['upload_file_exists'] ); } // test de la présence des champs obligatoires if ( $_FILES['picture']['name'] == '' ) { array_push( $error, $lang['upload_filenotfound'] ); } if ( !ereg( "([_a-z0-9-]+(\.[_a-z0-9-]+)*@[a-z0-9-]+(\.[a-z0-9-]+)+)", $_POST['mail_address'] ) ) { array_push( $error, $lang['reg_err_mail_address'] ); } if ( $_POST['username'] == '' ) { array_push( $error, $lang['upload_err_username'] ); } $date_creation = ''; if ( $_POST['date_creation'] != '' ) { list( $day,$month,$year ) = explode( '/', $_POST['date_creation'] ); // int checkdate ( int month, int day, int year) if ( checkdate( $month, $day, $year ) ) { // int mktime ( int hour, int minute, int second, // int month, int day, int year [, int is_dst]) $date_creation = mktime( 0, 0, 0, $month, $day, $year ); } else { array_push( $error, $lang['err_date'] ); } } // creation of the "infos" field : // $xml_infos = 'addSession( $handle, 'upload_not_successful' ); //-------------------------------------------------------------- errors display if ( sizeof( $error ) != 0 ) { $vtp->addSession( $handle, 'errors' ); for ( $i = 0; $i < sizeof( $error ); $i++ ) { $vtp->addSession( $handle, 'li' ); $vtp->setVar( $handle, 'li.li', $error[$i] ); $vtp->closeSession( $handle, 'li' ); } $vtp->closeSession( $handle, 'errors' ); } //----------------------------------------------------------------- form action $url = './upload.php?cat='.$page['cat'].'&expand='.$_GET['expand']; if ( isset( $page['waiting_id'] ) ) { $url.= '&waiting_id='.$page['waiting_id']; } $vtp->setGlobalVar( $handle, 'form_action', add_session_id( $url ) ); //--------------------------------------------------------------------- advises if ( $conf['upload_maxfilesize'] != '' ) { $vtp->addSession( $handle, 'advise' ); $content = $lang['upload_advise_filesize']; $content.= $conf['upload_maxfilesize'].' KB'; $vtp->setVar( $handle, 'advise.content', $content ); $vtp->closeSession( $handle, 'advise' ); } if ( isset( $page['waiting_id'] ) ) { $advise_title=$lang['upload_advise_thumbnail'].$_FILES['picture']['name']; $vtp->setGlobalVar( $handle, 'advise_title', $advise_title ); if ( $conf['upload_maxwidth_thumbnail'] != '' ) { $vtp->addSession( $handle, 'advise' ); $content = $lang['upload_advise_width']; $content.= $conf['upload_maxwidth_thumbnail'].' px'; $vtp->setVar( $handle, 'advise.content', $content ); $vtp->closeSession( $handle, 'advise' ); } if ( $conf['upload_maxheight_thumbnail'] != '' ) { $vtp->addSession( $handle, 'advise' ); $content = $lang['upload_advise_height']; $content.= $conf['upload_maxheight_thumbnail'].' px'; $vtp->setVar( $handle, 'advise.content', $content ); $vtp->closeSession( $handle, 'advise' ); } } else { $advise_title = $lang['upload_advise']; $advise_title.= get_cat_display_name( $page['cat_name'], ' - ', 'font-style:italic;' ); $vtp->setGlobalVar( $handle, 'advise_title', $advise_title ); if ( $conf['upload_maxwidth'] != '' ) { $vtp->addSession( $handle, 'advise' ); $content = $lang['upload_advise_width']; $content.= $conf['upload_maxwidth'].' px'; $vtp->setVar( $handle, 'advise.content', $content ); $vtp->closeSession( $handle, 'advise' ); } if ( $conf['upload_maxheight'] != '' ) { $vtp->addSession( $handle, 'advise' ); $content = $lang['upload_advise_height']; $content.= $conf['upload_maxheight'].' px'; $vtp->setVar( $handle, 'advise.content', $content ); $vtp->closeSession( $handle, 'advise' ); } } $vtp->addSession( $handle, 'advise' ); $content = $lang['upload_advise_filetype']; $vtp->setVar( $handle, 'advise.content', $content ); $vtp->closeSession( $handle, 'advise' ); //----------------------------------------- optionnal username and mail address if ( !isset( $page['waiting_id'] ) ) { $vtp->addSession( $handle, 'fields' ); // username if ( isset( $_POST['username'] ) ) $username = $_POST['username']; else $username = $user['username']; $vtp->setVar( $handle, 'fields.username', $username ); // mail address if ( isset( $_POST['mail_address'] ) )$mail_address=$_POST['mail_address']; else $mail_address=$user['mail_address']; $vtp->setGlobalVar( $handle, 'user_mail_address',$user['mail_address'] ); // name of the picture if (isset($_POST['name'])) $vtp->setVar( $handle, 'fields.name', $_POST['name'] ); // author if (isset($_POST['author'])) $vtp->setVar( $handle, 'fields.author', $_POST['author'] ); // date of creation if (isset($_POST['date_creation'])) $vtp->setVar( $handle, 'fields.date_creation', $_POST['date_creation'] ); // comment if (isset($_POST['comment'])) $vtp->setVar( $handle, 'fields.comment', $_POST['comment'] ); $vtp->closeSession( $handle, 'fields' ); $vtp->addSession( $handle, 'note' ); $vtp->closeSession( $handle, 'note' ); } $vtp->closeSession( $handle, 'upload_not_successful' ); } else { $vtp->addSession( $handle, 'upload_successful' ); $vtp->closeSession( $handle, 'upload_successful' ); } //----------------------------------------------------- return to main page url $url = './category.php?cat='.$page['cat'].'&expand='.$_GET['expand']; $vtp->setGlobalVar( $handle, 'return_url', add_session_id( $url ) ); //----------------------------------------------------------- html code display $output.= $vtp->Display( $handle, 0 ); include('include/page_tail.php'); ?>