2012-01-23 05:42:52 +00:00
|
|
|
<?php
|
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
class Oekaki extends Extension
|
|
|
|
{
|
|
|
|
public function onPageRequest(PageRequestEvent $event)
|
|
|
|
{
|
|
|
|
global $user, $page;
|
2012-01-23 05:42:52 +00:00
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
if ($event->page_matches("oekaki")) {
|
2019-07-09 09:10:21 -05:00
|
|
|
if ($user->can(Permissions::CREATE_IMAGE)) {
|
2019-05-28 17:59:38 +01:00
|
|
|
if ($event->get_arg(0) == "create") {
|
|
|
|
$this->theme->display_page();
|
|
|
|
$this->theme->display_block();
|
|
|
|
}
|
|
|
|
if ($event->get_arg(0) == "claim") {
|
|
|
|
// FIXME: move .chi to data/oekaki/$ha/$hash mirroring images and thumbs
|
|
|
|
// FIXME: .chi viewer?
|
|
|
|
// FIXME: clean out old unclaimed images?
|
|
|
|
$pattern = data_path('oekaki_unclaimed/' . $_SERVER['REMOTE_ADDR'] . ".*.png");
|
|
|
|
foreach (glob($pattern) as $tmpname) {
|
|
|
|
assert(file_exists($tmpname));
|
2012-06-26 19:47:40 +01:00
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
$pathinfo = pathinfo($tmpname);
|
|
|
|
if (!array_key_exists('extension', $pathinfo)) {
|
|
|
|
throw new UploadException("File has no extension");
|
|
|
|
}
|
|
|
|
log_info("oekaki", "Processing file [{$pathinfo['filename']}]");
|
|
|
|
$metadata = [];
|
|
|
|
$metadata['filename'] = 'oekaki.png';
|
|
|
|
$metadata['extension'] = $pathinfo['extension'];
|
|
|
|
$metadata['tags'] = Tag::explode('oekaki tagme');
|
|
|
|
$metadata['source'] = null;
|
|
|
|
$duev = new DataUploadEvent($tmpname, $metadata);
|
|
|
|
send_event($duev);
|
|
|
|
if ($duev->image_id == -1) {
|
|
|
|
throw new UploadException("File type not recognised");
|
|
|
|
} else {
|
|
|
|
unlink($tmpname);
|
2019-06-18 20:58:28 -05:00
|
|
|
$page->set_mode(PageMode::REDIRECT);
|
2019-05-28 17:59:38 +01:00
|
|
|
$page->set_redirect(make_link("post/view/".$duev->image_id));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if ($event->get_arg(0) == "upload") {
|
|
|
|
// FIXME: this allows anyone to upload anything to /data ...
|
|
|
|
// hardcoding the ext to .png should stop the obvious exploit,
|
|
|
|
// but more checking may be wise
|
|
|
|
if (isset($_FILES["picture"])) {
|
|
|
|
header('Content-type: text/plain');
|
2012-01-23 05:42:52 +00:00
|
|
|
|
2019-10-02 11:23:57 +01:00
|
|
|
//$file = $_FILES['picture']['name'];
|
2019-05-28 17:59:38 +01:00
|
|
|
//$ext = (strpos($file, '.') === FALSE) ? '' : substr($file, strrpos($file, '.'));
|
|
|
|
$uploadname = $_SERVER['REMOTE_ADDR'] . "." . time();
|
|
|
|
$uploadfile = data_path('oekaki_unclaimed/'.$uploadname);
|
2012-01-23 05:42:52 +00:00
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
log_info("oekaki", "Uploading file [$uploadname]");
|
2012-01-23 05:42:52 +00:00
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
$success = true;
|
|
|
|
if (isset($_FILES["chibifile"])) {
|
|
|
|
$success = $success && move_uploaded_file($_FILES['chibifile']['tmp_name'], $uploadfile . ".chi");
|
|
|
|
}
|
2012-01-23 05:42:52 +00:00
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
// hardcode the ext, so nobody can upload "foo.php"
|
|
|
|
$success = $success && move_uploaded_file($_FILES['picture']['tmp_name'], $uploadfile . ".png"); # $ext);
|
|
|
|
if ($success) {
|
|
|
|
echo "CHIBIOK\n";
|
|
|
|
} else {
|
|
|
|
echo "CHIBIERROR\n";
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
echo "CHIBIERROR No Data\n";
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2012-01-23 05:42:52 +00:00
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
// FIXME: "edit this image" button on existing images?
|
|
|
|
public function onPostListBuilding(PostListBuildingEvent $event)
|
|
|
|
{
|
|
|
|
global $user;
|
2019-07-09 09:10:21 -05:00
|
|
|
if ($user->can(Permissions::CREATE_IMAGE)) {
|
2019-05-28 17:59:38 +01:00
|
|
|
$this->theme->display_block();
|
|
|
|
}
|
|
|
|
}
|
2012-01-23 05:42:52 +00:00
|
|
|
}
|