board3 /
Board3-Portal
This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
| 1 | <?php |
||
| 2 | /** |
||
| 3 | * |
||
| 4 | * @package Board3 Portal v2.1 |
||
| 5 | * @copyright (c) 2013 Board3 Group ( www.board3.de ) |
||
| 6 | * @license http://opensource.org/licenses/gpl-2.0.php GNU General Public License v2 |
||
| 7 | * |
||
| 8 | */ |
||
| 9 | |||
| 10 | namespace board3\portal\modules; |
||
| 11 | |||
| 12 | /** |
||
| 13 | * @package Modulname |
||
| 14 | */ |
||
| 15 | class attachments extends module_base |
||
| 16 | { |
||
| 17 | /** |
||
| 18 | * Allowed columns: Just sum up your options (Exp: left + right = 10) |
||
| 19 | * top 1 |
||
| 20 | * left 2 |
||
| 21 | * center 4 |
||
| 22 | * right 8 |
||
| 23 | * bottom 16 |
||
| 24 | */ |
||
| 25 | public $columns = 31; |
||
| 26 | |||
| 27 | /** |
||
| 28 | * Default modulename |
||
| 29 | */ |
||
| 30 | public $name = 'PORTAL_ATTACHMENTS'; |
||
| 31 | |||
| 32 | /** |
||
| 33 | * Default module-image: |
||
| 34 | * file must be in "{T_THEME_PATH}/images/portal/" |
||
| 35 | */ |
||
| 36 | public $image_src = 'portal_attach.png'; |
||
| 37 | |||
| 38 | /** |
||
| 39 | * module-language file |
||
| 40 | * file must be in "language/{$user->lang}/mods/portal/" |
||
| 41 | */ |
||
| 42 | public $language = 'portal_attachments_module'; |
||
| 43 | |||
| 44 | /** @var \phpbb\auth\auth */ |
||
| 45 | protected $auth; |
||
| 46 | |||
| 47 | /** @var \phpbb\config\config */ |
||
| 48 | protected $config; |
||
| 49 | |||
| 50 | /** @var \board3\portal\includes\modules_helper */ |
||
| 51 | protected $helper; |
||
| 52 | |||
| 53 | /** @var \phpbb\request\request */ |
||
| 54 | protected $request; |
||
| 55 | |||
| 56 | /** @var \phpbb\template\template */ |
||
| 57 | protected $template; |
||
| 58 | |||
| 59 | /** @var \phpbb\db\driver\driver_interface */ |
||
| 60 | protected $db; |
||
| 61 | |||
| 62 | /** @var string PHP file extension */ |
||
| 63 | protected $php_ext; |
||
| 64 | |||
| 65 | /** @var string phpBB root path */ |
||
| 66 | protected $phpbb_root_path; |
||
| 67 | |||
| 68 | /** @var \phpbb\user */ |
||
| 69 | protected $user; |
||
| 70 | |||
| 71 | /** |
||
| 72 | * Construct an attachments object |
||
| 73 | * |
||
| 74 | * @param \phpbb\auth\auth $auth phpBB auth service |
||
| 75 | * @param \phpbb\config\config $config phpBB config |
||
| 76 | * @param \board3\portal\includes\modules_helper $helper Modules helper |
||
| 77 | * @param \phpbb\template\template $template phpBB template |
||
| 78 | * @param \phpbb\db\driver\driver_interface $db Database driver |
||
| 79 | * @param \phpbb\request\request $request phpBB request |
||
| 80 | * @param string $phpEx php file extension |
||
| 81 | * @param string $phpbb_root_path phpBB root path |
||
| 82 | * @param \phpbb\user $user phpBB user object |
||
| 83 | */ |
||
| 84 | View Code Duplication | public function __construct($auth, $config, $helper, $template, $db, $request, $phpEx, $phpbb_root_path, $user) |
|
| 85 | { |
||
| 86 | $this->auth = $auth; |
||
| 87 | $this->config = $config; |
||
| 88 | $this->helper = $helper; |
||
| 89 | $this->template = $template; |
||
| 90 | $this->db = $db; |
||
| 91 | $this->request = $request; |
||
| 92 | $this->php_ext = $phpEx; |
||
| 93 | $this->phpbb_root_path = $phpbb_root_path; |
||
| 94 | $this->user = $user; |
||
| 95 | } |
||
| 96 | |||
| 97 | /** |
||
| 98 | * {@inheritdoc} |
||
| 99 | */ |
||
| 100 | public function get_template_center($module_id) |
||
| 101 | { |
||
| 102 | return $this->parse_template($module_id, 'center'); |
||
| 103 | } |
||
| 104 | |||
| 105 | /** |
||
| 106 | * {@inheritdoc} |
||
| 107 | */ |
||
| 108 | public function get_template_side($module_id) |
||
| 109 | { |
||
| 110 | return $this->parse_template($module_id, 'side'); |
||
| 111 | } |
||
| 112 | |||
| 113 | /** |
||
| 114 | * {@inheritdoc} |
||
| 115 | */ |
||
| 116 | public function get_template_acp($module_id) |
||
| 117 | { |
||
| 118 | return array( |
||
| 119 | 'title' => 'ACP_PORTAL_ATTACHMENTS_NUMBER_SETTINGS', |
||
| 120 | 'vars' => array( |
||
| 121 | 'legend1' => 'ACP_PORTAL_ATTACHMENTS_NUMBER_SETTINGS', |
||
| 122 | 'board3_attachments_number_' . $module_id => array('lang' => 'PORTAL_ATTACHMENTS_NUMBER' , 'validate' => 'int', 'type' => 'text:3:3', 'explain' => true), |
||
| 123 | 'board3_attach_max_length_' . $module_id => array('lang' => 'PORTAL_ATTACHMENTS_MAX_LENGTH' , 'validate' => 'int', 'type' => 'text:3:3', 'explain' => true), |
||
| 124 | 'board3_attachments_forum_ids_' . $module_id => array('lang' => 'PORTAL_ATTACHMENTS_FORUM_IDS', 'validate' => 'string', 'type' => 'custom', 'explain' => true, 'method' => array('board3.portal.modules_helper', 'generate_forum_select'), 'submit' => array('board3.portal.modules_helper', 'store_selected_forums')), |
||
| 125 | 'board3_attachments_forum_exclude_' . $module_id => array('lang' => 'PORTAL_ATTACHMENTS_FORUM_EXCLUDE', 'validate' => 'bool', 'type' => 'radio:yes_no', 'explain' => true), |
||
| 126 | 'board3_attachments_filetype_' . $module_id => array('lang' => 'PORTAL_ATTACHMENTS_FILETYPE', 'validate' => 'string', 'type' => 'custom', 'explain' => true, 'method' => 'select_filetype', 'submit' => 'store_filetypes'), |
||
| 127 | 'board3_attachments_exclude_' . $module_id => array('lang' => 'PORTAL_ATTACHMENTS_EXCLUDE', 'validate' => 'bool', 'type' => 'radio:yes_no', 'explain' => true), |
||
| 128 | ), |
||
| 129 | ); |
||
| 130 | } |
||
| 131 | |||
| 132 | /** |
||
| 133 | * {@inheritdoc} |
||
| 134 | */ |
||
| 135 | public function install($module_id) |
||
| 136 | { |
||
| 137 | $this->config->set('board3_attachments_number_' . $module_id, 8); |
||
| 138 | $this->config->set('board3_attach_max_length_' . $module_id, 15); |
||
| 139 | $this->config->set('board3_attachments_forum_ids_' . $module_id, ''); |
||
| 140 | $this->config->set('board3_attachments_forum_exclude_' . $module_id, 0); |
||
| 141 | $this->config->set('board3_attachments_filetype_' . $module_id, ''); |
||
| 142 | $this->config->set('board3_attachments_exclude_' . $module_id, 0); |
||
| 143 | return true; |
||
| 144 | } |
||
| 145 | |||
| 146 | /** |
||
| 147 | * {@inheritdoc} |
||
| 148 | */ |
||
| 149 | View Code Duplication | public function uninstall($module_id, $db) |
|
| 150 | { |
||
| 151 | $del_config = array( |
||
| 152 | 'board3_attachments_number_' . $module_id, |
||
| 153 | 'board3_attach_max_length_' . $module_id, |
||
| 154 | 'board3_attachments_forum_ids_' . $module_id, |
||
| 155 | 'board3_attachments_forum_exclude_' . $module_id, |
||
| 156 | 'board3_attachments_filetype_' . $module_id, |
||
| 157 | 'board3_attachments_exclude_' . $module_id, |
||
| 158 | ); |
||
| 159 | $sql = 'DELETE FROM ' . CONFIG_TABLE . ' |
||
| 160 | WHERE ' . $db->sql_in_set('config_name', $del_config); |
||
| 161 | return $db->sql_query($sql); |
||
| 162 | } |
||
| 163 | |||
| 164 | /** |
||
| 165 | * Create select box for attachment filetype |
||
| 166 | * |
||
| 167 | * @param mixed $value Value of input |
||
| 168 | * @param string $key Key name |
||
| 169 | * @param int $module_id Module ID |
||
| 170 | * |
||
| 171 | * @return string Forum select box HTML |
||
| 172 | */ |
||
| 173 | public function select_filetype($value, $key, $module_id) |
||
|
0 ignored issues
–
show
|
|||
| 174 | { |
||
| 175 | $extensions = array(); |
||
| 176 | |||
| 177 | // Get extensions |
||
| 178 | $sql = 'SELECT * |
||
| 179 | FROM ' . EXTENSIONS_TABLE . ' |
||
| 180 | ORDER BY extension ASC'; |
||
| 181 | $result = $this->db->sql_query($sql); |
||
| 182 | |||
| 183 | while ($row = $this->db->sql_fetchrow($result)) |
||
| 184 | { |
||
| 185 | $extensions[] = array( |
||
| 186 | 'value' => $row['extension'], |
||
| 187 | 'title' => $row['extension'], |
||
| 188 | ); |
||
| 189 | } |
||
| 190 | $this->db->sql_freeresult($result); |
||
| 191 | |||
| 192 | $selected = $this->get_selected_filetypes($module_id); |
||
| 193 | |||
| 194 | return $this->helper->generate_select_box($key, $extensions, $selected, true); |
||
| 195 | } |
||
| 196 | |||
| 197 | /** |
||
| 198 | * Store selected filetypes |
||
| 199 | * |
||
| 200 | * @param string $key Key name |
||
| 201 | * @param int $module_id Module ID |
||
| 202 | * |
||
| 203 | * @return null |
||
| 204 | */ |
||
| 205 | View Code Duplication | public function store_filetypes($key, $module_id) |
|
| 206 | { |
||
| 207 | // Get selected extensions |
||
| 208 | $values = $this->request->variable($key, array(0 => '')); |
||
| 209 | |||
| 210 | $filetypes = implode(',', $values); |
||
| 211 | |||
| 212 | $this->config->set('board3_attachments_filetype_' . $module_id, $filetypes); |
||
| 213 | |||
| 214 | } |
||
| 215 | |||
| 216 | /** |
||
| 217 | * Parse template variables for module |
||
| 218 | * |
||
| 219 | * @param int $module_id Module ID |
||
| 220 | * @param string $type Module type (center or side) |
||
| 221 | * |
||
| 222 | * @return string Template file name or false if nothing should |
||
| 223 | * be displayed |
||
| 224 | */ |
||
| 225 | protected function parse_template($module_id, $type) |
||
| 226 | { |
||
| 227 | $attach_forums = false; |
||
| 228 | $where = ''; |
||
| 229 | |||
| 230 | // Get filetypes and put them into an array |
||
| 231 | $filetypes = $this->get_selected_filetypes($module_id); |
||
| 232 | |||
| 233 | if ($this->config['board3_attachments_forum_ids_' . $module_id] !== '') |
||
| 234 | { |
||
| 235 | $attach_forums_config = (strpos($this->config['board3_attachments_forum_ids_' . $module_id], ',') !== false) ? explode(',', $this->config['board3_attachments_forum_ids_' . $module_id]) : array($this->config['board3_attachments_forum_ids_' . $module_id]); |
||
| 236 | $forum_list = array_unique(array_keys($this->auth->acl_getf('f_read', true))); |
||
| 237 | |||
| 238 | View Code Duplication | if ($this->config['board3_attachments_forum_exclude_' . $module_id]) |
|
| 239 | { |
||
| 240 | $forum_list = array_unique(array_diff($forum_list, $attach_forums_config)); |
||
| 241 | } |
||
| 242 | else |
||
| 243 | { |
||
| 244 | $forum_list = array_unique(array_intersect($attach_forums_config, $forum_list)); |
||
| 245 | } |
||
| 246 | } |
||
| 247 | else |
||
| 248 | { |
||
| 249 | $forum_list = array_unique(array_keys($this->auth->acl_getf('f_read', true))); |
||
| 250 | } |
||
| 251 | |||
| 252 | View Code Duplication | if (sizeof($forum_list)) |
|
| 253 | { |
||
| 254 | $attach_forums = true; |
||
| 255 | $where = 'AND ' . $this->db->sql_in_set('t.forum_id', $forum_list); |
||
| 256 | } |
||
| 257 | |||
| 258 | if (sizeof($filetypes)) |
||
| 259 | { |
||
| 260 | if ($this->config['board3_attachments_exclude_' . $module_id]) |
||
| 261 | { |
||
| 262 | $where .= ' AND ' . $this->db->sql_in_set('a.extension', $filetypes, true); |
||
| 263 | } |
||
| 264 | else |
||
| 265 | { |
||
| 266 | $where .= ' AND ' . $this->db->sql_in_set('a.extension', $filetypes); |
||
| 267 | } |
||
| 268 | } |
||
| 269 | |||
| 270 | if ($attach_forums === true) |
||
| 271 | { |
||
| 272 | // Just grab all attachment info from database |
||
| 273 | $sql = 'SELECT |
||
| 274 | a.*, |
||
| 275 | t.forum_id |
||
| 276 | FROM |
||
| 277 | ' . ATTACHMENTS_TABLE . ' a, |
||
| 278 | ' . TOPICS_TABLE . ' t |
||
| 279 | WHERE |
||
| 280 | a.topic_id <> 0 |
||
| 281 | AND a.topic_id = t.topic_id |
||
| 282 | ' . $where . ' |
||
| 283 | ORDER BY |
||
| 284 | filetime ' . ((!$this->config['display_order']) ? 'DESC' : 'ASC') . ', post_msg_id ASC'; |
||
| 285 | $result = $this->db->sql_query_limit($sql, $this->config['board3_attachments_number_' . $module_id], 0, 600); |
||
| 286 | |||
| 287 | while ($row = $this->db->sql_fetchrow($result)) |
||
| 288 | { |
||
| 289 | $size_lang = ($row['filesize'] >= 1048576) ? $this->user->lang['MIB'] : (($row['filesize'] >= 1024) ? $this->user->lang['KIB'] : $this->user->lang['BYTES']); |
||
| 290 | $row['filesize'] = ($row['filesize'] >= 1048576) ? round((round($row['filesize'] / 1048576 * 100) / 100), 2) : (($row['filesize'] >= 1024) ? round((round($row['filesize'] / 1024 * 100) / 100), 2) : $row['filesize']); |
||
| 291 | |||
| 292 | $raw_filename = utf8_substr($row['real_filename'], 0, strrpos($row['real_filename'], '.')); |
||
| 293 | $replace = character_limit($raw_filename, $this->config['board3_attach_max_length_' . $module_id]); |
||
| 294 | |||
| 295 | $this->template->assign_block_vars('attach_' . $type, array( |
||
| 296 | 'FILESIZE' => $row['filesize'] . ' ' . $size_lang, |
||
| 297 | 'FILETIME' => $this->user->format_date($row['filetime']), |
||
| 298 | 'DOWNLOAD_COUNT' => (int) $row['download_count'], // grab downloads count |
||
| 299 | 'FILENAME' => $replace, |
||
| 300 | 'REAL_FILENAME' => $row['real_filename'], |
||
| 301 | 'PHYSICAL_FILENAME' => basename($row['physical_filename']), |
||
| 302 | 'ATTACH_ID' => $row['attach_id'], |
||
| 303 | 'POST_IDS' => (!empty($post_ids[$row['attach_id']])) ? $post_ids[$row['attach_id']] : '', |
||
| 304 | 'POST_MSG_ID' => $row['post_msg_id'], // grab post ID to redirect to post |
||
| 305 | 'U_FILE' => append_sid($this->phpbb_root_path . 'download/file.' . $this->php_ext, 'id=' . $row['attach_id']), |
||
| 306 | 'U_TOPIC' => append_sid($this->phpbb_root_path . 'viewtopic.' . $this->php_ext, 'p='.$row['post_msg_id'].'#p'.$row['post_msg_id']), |
||
| 307 | )); |
||
| 308 | } |
||
| 309 | $this->db->sql_freeresult($result); |
||
| 310 | |||
| 311 | $this->template->assign_var('S_DISPLAY_ATTACHMENTS', true); |
||
| 312 | } |
||
| 313 | else |
||
| 314 | { |
||
| 315 | $this->template->assign_var('S_DISPLAY_ATTACHMENTS', false); |
||
| 316 | } |
||
| 317 | |||
| 318 | return 'attachments_' . $type . '.html'; |
||
| 319 | } |
||
| 320 | |||
| 321 | /** |
||
| 322 | * Get the filetypes that were selected in the ACP |
||
| 323 | * |
||
| 324 | * @param int $module_id Module ID |
||
| 325 | * |
||
| 326 | * @return array An array with the selected filetypes |
||
| 327 | */ |
||
| 328 | protected function get_selected_filetypes($module_id) |
||
| 329 | { |
||
| 330 | $selected = array(); |
||
| 331 | if (isset($this->config['board3_attachments_filetype_' . $module_id]) && strlen($this->config['board3_attachments_filetype_' . $module_id]) > 0) |
||
| 332 | { |
||
| 333 | $selected = explode(',', $this->config['board3_attachments_filetype_' . $module_id]); |
||
| 334 | } |
||
| 335 | |||
| 336 | return $selected; |
||
| 337 | } |
||
| 338 | } |
||
| 339 |
This check looks from parameters that have been defined for a function or method, but which are not used in the method body.