XoopsModules25x /
tdmdownloads
This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
via PHP's auto-loading mechanism.
| 1 | <?php |
||||
| 2 | |||||
| 3 | declare(strict_types=1); |
||||
| 4 | |||||
| 5 | namespace XoopsModules\Tdmdownloads; |
||||
| 6 | |||||
| 7 | /** |
||||
| 8 | * TDMDownload |
||||
| 9 | * |
||||
| 10 | * You may not change or alter any portion of this comment or credits |
||||
| 11 | * of supporting developers from this source code or any supporting source code |
||||
| 12 | * which is considered copyrighted (c) material of the original comment or credit authors. |
||||
| 13 | * This program is distributed in the hope that it will be useful, |
||||
| 14 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||||
| 15 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
||||
| 16 | * |
||||
| 17 | * @copyright Gregory Mage (Aka Mage) |
||||
| 18 | * @license GNU GPL 2 (https://www.gnu.org/licenses/old-licenses/gpl-2.0.html) |
||||
| 19 | * @author Gregory Mage (Aka Mage) |
||||
| 20 | */ |
||||
| 21 | |||||
| 22 | use XoopsModules\Tdmdownloads; |
||||
| 23 | |||||
| 24 | /** |
||||
| 25 | * Class Modified |
||||
| 26 | * @package XoopsModules\Tdmdownloads |
||||
| 27 | */ |
||||
| 28 | class Modified extends \XoopsObject |
||||
| 29 | { |
||||
| 30 | // constructor |
||||
| 31 | public function __construct() |
||||
| 32 | { |
||||
| 33 | $this->initVar('requestid', \XOBJ_DTYPE_INT, null, false, 11); |
||||
| 34 | $this->initVar('lid', \XOBJ_DTYPE_INT, null, false, 11); |
||||
| 35 | $this->initVar('cid', \XOBJ_DTYPE_INT, null, false, 5); |
||||
| 36 | $this->initVar('title', \XOBJ_DTYPE_TXTBOX, null, false); |
||||
| 37 | $this->initVar('url', \XOBJ_DTYPE_TXTBOX, null, false); |
||||
| 38 | $this->initVar('homepage', \XOBJ_DTYPE_TXTBOX, null, false); |
||||
| 39 | $this->initVar('version', \XOBJ_DTYPE_TXTBOX, null, false); |
||||
| 40 | $this->initVar('size', \XOBJ_DTYPE_TXTBOX, null, false); |
||||
| 41 | $this->initVar('platform', \XOBJ_DTYPE_TXTBOX, null, false); |
||||
| 42 | $this->initVar('logourl', \XOBJ_DTYPE_TXTBOX, null, false); |
||||
| 43 | $this->initVar('description', \XOBJ_DTYPE_TXTAREA, null, false); |
||||
| 44 | // Pour autoriser le html |
||||
| 45 | $this->initVar('dohtml', \XOBJ_DTYPE_INT, 1, false); |
||||
| 46 | $this->initVar('modifysubmitter', \XOBJ_DTYPE_INT, null, false, 11); |
||||
| 47 | } |
||||
| 48 | |||||
| 49 | /** |
||||
| 50 | * @param null $db |
||||
|
0 ignored issues
–
show
Documentation
Bug
introduced
by
Loading history...
|
|||||
| 51 | * @return int|string |
||||
| 52 | */ |
||||
| 53 | public function getNewEnreg($db = null) |
||||
| 54 | { |
||||
| 55 | $newEnreg = 0; |
||||
| 56 | /** @var \XoopsMySQLDatabase $db */ |
||||
| 57 | if (null !== $db) { |
||||
| 58 | $newEnreg = $db->getInsertId(); |
||||
| 59 | } |
||||
| 60 | return $newEnreg; |
||||
| 61 | } |
||||
| 62 | |||||
| 63 | /** |
||||
| 64 | * @param $lid |
||||
| 65 | * @param $erreur |
||||
| 66 | * @param array $donnee |
||||
| 67 | * @param bool $action |
||||
| 68 | * @return \XoopsThemeForm |
||||
| 69 | */ |
||||
| 70 | public function getForm($lid, $erreur, $donnee = [], $action = false) |
||||
| 71 | { |
||||
| 72 | global $xoopsDB, $xoopsModule, $xoopsUser; |
||||
| 73 | $helper = Helper::getInstance(); |
||||
| 74 | $moduleDirName = \basename(\dirname(__DIR__)); |
||||
| 75 | if (!$action) { |
||||
| 76 | $action = $_SERVER['REQUEST_URI']; |
||||
| 77 | } |
||||
| 78 | $groups = \is_object($xoopsUser) ? $xoopsUser->getGroups() : XOOPS_GROUP_ANONYMOUS; |
||||
| 79 | /** @var \XoopsGroupPermHandler $grouppermHandler */ |
||||
| 80 | $grouppermHandler = \xoops_getHandler('groupperm'); |
||||
| 81 | $perm_upload = $grouppermHandler->checkRight('tdmdownloads_ac', 32, $groups, $xoopsModule->getVar('mid')); |
||||
| 82 | //appel des class |
||||
| 83 | /** @var \XoopsModules\Tdmdownloads\DownloadsHandler $downloadsHandler */ |
||||
| 84 | $downloadsHandler = Helper::getInstance()->getHandler('Downloads'); |
||||
| 85 | // $categoryHandler = Helper::getInstance()->getHandler('Category'); |
||||
| 86 | $viewDownloads = $downloadsHandler->get($lid); |
||||
| 87 | require_once XOOPS_ROOT_PATH . '/class/xoopsformloader.php'; |
||||
| 88 | // affectation des variables |
||||
| 89 | if (true === $erreur) { |
||||
| 90 | $d_title = $donnee['title']; |
||||
| 91 | $d_cid = $donnee['cid']; |
||||
| 92 | $d_homepage = $donnee['homepage']; |
||||
| 93 | $d_version = $donnee['version']; |
||||
| 94 | $d_platform = $donnee['platform']; |
||||
| 95 | $d_description = $donnee['description']; |
||||
| 96 | } else { |
||||
| 97 | $d_title = $viewDownloads->getVar('title'); |
||||
| 98 | $d_cid = $viewDownloads->getVar('cid'); |
||||
| 99 | $d_homepage = $viewDownloads->getVar('homepage'); |
||||
| 100 | $d_version = $viewDownloads->getVar('version'); |
||||
| 101 | $d_platform = $viewDownloads->getVar('platform'); |
||||
| 102 | $d_description = $viewDownloads->getVar('description', 'e'); |
||||
| 103 | } |
||||
| 104 | //nom du formulaire |
||||
| 105 | $title = \sprintf(_AM_TDMDOWNLOADS_FORMEDIT); |
||||
| 106 | //création du formulaire |
||||
| 107 | $form = new \XoopsThemeForm($title, 'form', $action, 'post', true); |
||||
| 108 | $form->setExtra('enctype="multipart/form-data"'); |
||||
| 109 | //titre |
||||
| 110 | $form->addElement(new \XoopsFormText(_AM_TDMDOWNLOADS_FORMTITLE, 'title', 50, 255, $d_title), true); |
||||
| 111 | // fichier |
||||
| 112 | $fichier = new \XoopsFormElementTray(_AM_TDMDOWNLOADS_FORMFILE, '<br><br>'); |
||||
| 113 | $url = $viewDownloads->getVar('url'); |
||||
| 114 | $formurl = new \XoopsFormText(_AM_TDMDOWNLOADS_FORMURL, 'url', 75, 255, $url); |
||||
|
0 ignored issues
–
show
It seems like
$url can also be of type array and array; however, parameter $value of XoopsFormText::__construct() does only seem to accept string, maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
Loading history...
|
|||||
| 115 | $fichier->addElement($formurl, false); |
||||
| 116 | if ($perm_upload) { |
||||
| 117 | $fichier->addElement(new \XoopsFormFile(_AM_TDMDOWNLOADS_FORMUPLOAD, 'attachedfile', $helper->getConfig('maxuploadsize')), false); |
||||
| 118 | } |
||||
| 119 | $form->addElement($fichier); |
||||
| 120 | //catégorie |
||||
| 121 | /** @var \XoopsModules\Tdmdownloads\CategoryHandler $categoryHandler */ |
||||
| 122 | $categoryHandler = Helper::getInstance()->getHandler('Category'); |
||||
| 123 | $utility = new \XoopsModules\Tdmdownloads\Utility(); |
||||
| 124 | $categories = $utility->getItemIds('tdmdownloads_submit', $moduleDirName); |
||||
| 125 | $criteria = new \CriteriaCompo(); |
||||
| 126 | $criteria->setSort('cat_weight ASC, cat_title'); |
||||
| 127 | $criteria->setOrder('ASC'); |
||||
| 128 | if ($xoopsUser) { |
||||
| 129 | if (!$xoopsUser->isAdmin($xoopsModule->mid())) { |
||||
| 130 | $criteria->add(new \Criteria('cat_cid', '(' . \implode(',', $categories) . ')', 'IN')); |
||||
| 131 | } |
||||
| 132 | } else { |
||||
| 133 | $criteria->add(new \Criteria('cat_cid', '(' . \implode(',', $categories) . ')', 'IN')); |
||||
| 134 | } |
||||
| 135 | $downloadscatArray = $categoryHandler->getAll($criteria); |
||||
| 136 | if (empty($downloadscatArray)) { |
||||
| 137 | \redirect_header('index.php', 2, \_NOPERM); |
||||
| 138 | } |
||||
| 139 | $mytree = new \XoopsModules\Tdmdownloads\Tree($downloadscatArray, 'cat_cid', 'cat_pid'); |
||||
| 140 | $form->addElement($mytree->makeSelectElement('cid', 'cat_title', '--', $d_cid, true, 0, '', _AM_TDMDOWNLOADS_FORMINCAT), true); |
||||
| 141 | //affichage des champs |
||||
| 142 | $fieldHandler = Helper::getInstance()->getHandler('Field'); |
||||
| 143 | $criteria = new \CriteriaCompo(); |
||||
| 144 | $criteria->setSort('weight ASC, title'); |
||||
| 145 | $criteria->setOrder('ASC'); |
||||
| 146 | $downloads_field = $fieldHandler->getAll($criteria); |
||||
| 147 | foreach (\array_keys($downloads_field) as $i) { |
||||
| 148 | /** @var \XoopsModules\Tdmdownloads\Field[] $downloads_field */ |
||||
| 149 | if (1 == $downloads_field[$i]->getVar('status_def')) { |
||||
| 150 | if (1 == $downloads_field[$i]->getVar('fid')) { |
||||
| 151 | //page d'accueil |
||||
| 152 | if (1 == $downloads_field[$i]->getVar('status')) { |
||||
| 153 | $form->addElement(new \XoopsFormText(_AM_TDMDOWNLOADS_FORMHOMEPAGE, 'homepage', 50, 255, $d_homepage)); |
||||
| 154 | } else { |
||||
| 155 | $form->addElement(new \XoopsFormHidden('homepage', '')); |
||||
| 156 | } |
||||
| 157 | } |
||||
| 158 | if (2 == $downloads_field[$i]->getVar('fid')) { |
||||
| 159 | //version |
||||
| 160 | if (1 == $downloads_field[$i]->getVar('status')) { |
||||
| 161 | $form->addElement(new \XoopsFormText(_AM_TDMDOWNLOADS_FORMVERSION, 'version', 10, 255, $d_version)); |
||||
| 162 | } else { |
||||
| 163 | $form->addElement(new \XoopsFormHidden('version', '')); |
||||
| 164 | } |
||||
| 165 | } |
||||
| 166 | if (3 == $downloads_field[$i]->getVar('fid')) { |
||||
| 167 | //taille du fichier |
||||
| 168 | if (1 == $downloads_field[$i]->getVar('status')) { |
||||
| 169 | $size_value_arr = \explode(' ', $viewDownloads->getVar('size')); |
||||
| 170 | $aff_size = new \XoopsFormElementTray(_AM_TDMDOWNLOADS_FORMSIZE_WHEN_SUBMIT, ''); |
||||
| 171 | $aff_size->addElement(new \XoopsFormText('', 'sizeValue', 13, 13, $size_value_arr[0])); |
||||
| 172 | if (!\array_key_exists(1, $size_value_arr)) { |
||||
| 173 | $size_value_arr[1] = 'K'; |
||||
| 174 | } |
||||
| 175 | $type = new \XoopsFormSelect('', 'sizeType', $size_value_arr[1]); |
||||
| 176 | $typeArray = [ |
||||
| 177 | 'B' => _AM_TDMDOWNLOADS_BYTES, |
||||
| 178 | 'K' => _AM_TDMDOWNLOADS_KBYTES, |
||||
| 179 | 'M' => _AM_TDMDOWNLOADS_MBYTES, |
||||
| 180 | 'G' => _AM_TDMDOWNLOADS_GBYTES, |
||||
| 181 | 'T' => _AM_TDMDOWNLOADS_TBYTES, |
||||
| 182 | ]; |
||||
| 183 | $type->addOptionArray($typeArray); |
||||
| 184 | $aff_size->addElement($type); |
||||
| 185 | $form->addElement($aff_size); |
||||
| 186 | } else { |
||||
| 187 | $form->addElement(new \XoopsFormHidden('size', '')); |
||||
| 188 | $form->addElement(new \XoopsFormHidden('type_size', '')); |
||||
| 189 | } |
||||
| 190 | } |
||||
| 191 | if (4 == $downloads_field[$i]->getVar('fid')) { |
||||
| 192 | //plateforme |
||||
| 193 | if (1 == $downloads_field[$i]->getVar('status')) { |
||||
| 194 | $platformselect = new \XoopsFormSelect(_AM_TDMDOWNLOADS_FORMPLATFORM, 'platform', \explode('|', $d_platform), 5, true); |
||||
| 195 | $platformArray = \explode('|', $helper->getConfig('platform')); |
||||
|
0 ignored issues
–
show
It seems like
$helper->getConfig('platform') can also be of type null; however, parameter $string of explode() does only seem to accept string, maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
Loading history...
|
|||||
| 196 | foreach ($platformArray as $platform) { |
||||
| 197 | $platformselect->addOption((string)$platform, $platform); |
||||
| 198 | } |
||||
| 199 | $form->addElement($platformselect, false); |
||||
| 200 | //$form->addElement(new \XoopsFormText(_AM_TDMDOWNLOADS_FORMPLATFORM, 'platform', 50, 255, $d_platform)); |
||||
| 201 | } else { |
||||
| 202 | $form->addElement(new \XoopsFormHidden('platform', '')); |
||||
| 203 | } |
||||
| 204 | } |
||||
| 205 | } else { |
||||
| 206 | $contenu = ''; |
||||
| 207 | $fieldName = 'champ' . $downloads_field[$i]->getVar('fid'); |
||||
| 208 | $fielddataHandler = Helper::getInstance()->getHandler('Fielddata'); |
||||
| 209 | $criteria = new \CriteriaCompo(); |
||||
| 210 | $criteria->add(new \Criteria('lid', $viewDownloads->getVar('lid'))); |
||||
|
0 ignored issues
–
show
It seems like
$viewDownloads->getVar('lid') can also be of type array and array; however, parameter $value of Criteria::__construct() does only seem to accept string, maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
Loading history...
|
|||||
| 211 | $criteria->add(new \Criteria('fid', $downloads_field[$i]->getVar('fid'))); |
||||
| 212 | $downloadsfielddata = $fielddataHandler->getAll($criteria); |
||||
| 213 | foreach (\array_keys($downloadsfielddata) as $j) { |
||||
| 214 | /** @var \XoopsModules\Tdmdownloads\Fielddata[] $downloadsfielddata */ |
||||
| 215 | if (true === $erreur) { |
||||
| 216 | $contenu = $donnee[$fieldName]; |
||||
| 217 | } else { |
||||
| 218 | $contenu = $downloadsfielddata[$j]->getVar('data'); |
||||
| 219 | } |
||||
| 220 | } |
||||
| 221 | if (1 == $downloads_field[$i]->getVar('status')) { |
||||
| 222 | $form->addElement(new \XoopsFormText($downloads_field[$i]->getVar('title'), $fieldName, 50, 255, $contenu)); |
||||
|
0 ignored issues
–
show
It seems like
$downloads_field[$i]->getVar('title') can also be of type array and array; however, parameter $caption of XoopsFormText::__construct() does only seem to accept string, maybe add an additional type check?
(
Ignorable by Annotation
)
If this is a false-positive, you can also ignore this issue in your code via the
Loading history...
|
|||||
| 223 | } else { |
||||
| 224 | $form->addElement(new \XoopsFormHidden($fieldName, '')); |
||||
| 225 | } |
||||
| 226 | } |
||||
| 227 | } |
||||
| 228 | //description |
||||
| 229 | $editorConfigs = []; |
||||
| 230 | $editorConfigs['name'] = 'description'; |
||||
| 231 | $editorConfigs['value'] = $d_description; |
||||
| 232 | $editorConfigs['rows'] = 20; |
||||
| 233 | $editorConfigs['cols'] = 60; |
||||
| 234 | $editorConfigs['width'] = '100%'; |
||||
| 235 | $editorConfigs['height'] = '400px'; |
||||
| 236 | $editorConfigs['editor'] = $helper->getConfig('editor'); |
||||
| 237 | $form->addElement(new \XoopsFormEditor(_AM_TDMDOWNLOADS_FORMTEXTDOWNLOADS, 'description', $editorConfigs), true); |
||||
| 238 | //image |
||||
| 239 | if ($helper->getConfig('useshots')) { |
||||
| 240 | $uploaddir = XOOPS_ROOT_PATH . '/uploads/' . $moduleDirName . '/images/shots/' . $viewDownloads->getVar('logourl'); |
||||
| 241 | $categoryImage = $viewDownloads->getVar('logourl') ?: 'blank.gif'; |
||||
| 242 | $uploadirectory = '/uploads/' . $moduleDirName . '/images/shots'; |
||||
| 243 | if (!\is_file($uploaddir)) { |
||||
| 244 | $categoryImage = 'blank.gif'; |
||||
| 245 | } |
||||
| 246 | $imgtray = new \XoopsFormElementTray(_AM_TDMDOWNLOADS_FORMIMG, '<br>'); |
||||
| 247 | $imgpath = \sprintf(_AM_TDMDOWNLOADS_FORMPATH, $uploadirectory); |
||||
| 248 | $imageselect = new \XoopsFormSelect($imgpath, 'logo_img', $categoryImage); |
||||
| 249 | $topics_array = \XoopsLists::getImgListAsArray(XOOPS_ROOT_PATH . $uploadirectory); |
||||
| 250 | foreach ($topics_array as $image) { |
||||
| 251 | $imageselect->addOption($image, $image); |
||||
| 252 | } |
||||
| 253 | $imageselect->setExtra("onchange='showImgSelected(\"image3\", \"logo_img\", \"" . $uploadirectory . '", "", "' . XOOPS_URL . "\")'"); |
||||
| 254 | $imgtray->addElement($imageselect, false); |
||||
| 255 | $imgtray->addElement(new \XoopsFormLabel('', "<br><img src='" . XOOPS_URL . '/' . $uploadirectory . '/' . $categoryImage . "' name='image3' id='image3' alt=''>")); |
||||
| 256 | $fileseltray = new \XoopsFormElementTray('', '<br>'); |
||||
| 257 | if ($perm_upload) { |
||||
| 258 | $fileseltray->addElement(new \XoopsFormFile(_AM_TDMDOWNLOADS_FORMUPLOAD, 'attachedimage', $helper->getConfig('maxuploadsize')), false); |
||||
| 259 | } |
||||
| 260 | $imgtray->addElement($fileseltray); |
||||
| 261 | $form->addElement($imgtray); |
||||
| 262 | } |
||||
| 263 | $form->addElement(new \XoopsFormCaptcha(), true); |
||||
| 264 | $form->addElement(new \XoopsFormHidden('lid', $lid)); |
||||
| 265 | //pour enregistrer le formulaire |
||||
| 266 | $form->addElement(new \XoopsFormHidden('op', 'save')); |
||||
| 267 | //bouton d'envoi du formulaire |
||||
| 268 | $form->addElement(new \XoopsFormButtonTray('', \_SUBMIT, 'submit', 'submit', false)); |
||||
| 269 | return $form; |
||||
| 270 | } |
||||
| 271 | } |
||||
| 272 |