]> git.mxchange.org Git - friendica.git/blobdiff - mod/photo.php
Just some more fixed notice
[friendica.git] / mod / photo.php
index 3cd8250a9e7bd727cfbe5666c6b96e58da09f5fb..653802d30e8bd27ffe4b3f7eec21c371323ab446 100644 (file)
@@ -1,36 +1,22 @@
 <?php
 
-require_once('include/security.php');
-
-function photo_init(&$a) {
-
-       // To-Do:
-       // - checking with realpath
-       // - checking permissions
-       /*
-       $cache = get_config('system','itemcache');
-        if (($cache != '') and is_dir($cache)) {
-               $cachefile = $cache."/".$a->argc."-".$a->argv[1]."-".$a->argv[2]."-".$a->argv[3];
-               if (file_exists($cachefile)) {
-                       $data = file_get_contents($cachefile);
-
-                       if(function_exists('header_remove')) {
-                               header_remove('Pragma');
-                               header_remove('pragma');
-                       }
+/**
+ * @file mod/photo.php
+ */
+use Friendica\App;
+use Friendica\Database\DBM;
+use Friendica\Object\Image;
 
-                       header("Content-type: image/jpeg");
-                       header("Expires: " . gmdate("D, d M Y H:i:s", time() + (3600*24)) . " GMT");
-                       header("Cache-Control: max-age=" . (3600*24));
-                       echo $data;
-                       killme();
-                       // NOTREACHED
-               }
-       }*/
+require_once 'include/security.php';
+
+function photo_init(App $a)
+{
+       global $_SERVER;
 
        $prvcachecontrol = false;
+       $file = "";
 
-       switch($a->argc) {
+       switch ($a->argc) {
                case 4:
                        $person = $a->argv[3];
                        $customres = intval($a->argv[2]);
@@ -42,6 +28,7 @@ function photo_init(&$a) {
                        break;
                case 2:
                        $photo = $a->argv[1];
+                       $file = $photo;
                        break;
                case 1:
                default:
@@ -49,17 +36,28 @@ function photo_init(&$a) {
                        // NOTREACHED
        }
 
-       $default = 'images/person-175.jpg';
-
-       if(isset($type)) {
-
-
-               /**
-                * Profile photos
-                */
+       if (isset($_SERVER['HTTP_IF_MODIFIED_SINCE'])) {
+               header('HTTP/1.1 304 Not Modified');
+               header("Last-Modified: " . gmdate("D, d M Y H:i:s", time()) . " GMT");
+               if (!empty($_SERVER['HTTP_IF_NONE_MATCH'])) {
+                       header('Etag: ' . $_SERVER['HTTP_IF_NONE_MATCH']);
+               }
+               header("Expires: " . gmdate("D, d M Y H:i:s", time() + (31536000)) . " GMT");
+               header("Cache-Control: max-age=31536000");
+               if (function_exists('header_remove')) {
+                       header_remove('Last-Modified');
+                       header_remove('Expires');
+                       header_remove('Cache-Control');
+               }
+               exit;
+       }
 
-               switch($type) {
+       $default = 'images/person-175.jpg';
+       $public = true;
 
+       if (isset($type)) {
+               // Profile photos
+               switch ($type) {
                        case 'profile':
                        case 'custom':
                                $resolution = 4;
@@ -75,85 +73,81 @@ function photo_init(&$a) {
                                break;
                }
 
-               $uid = str_replace('.jpg', '', $person);
+               $uid = str_replace(['.jpg', '.png', '.gif'], ['', '', ''], $person);
+
+               foreach (Image::supportedTypes() AS $m => $e) {
+                       $uid = str_replace('.' . $e, '', $uid);
+               }
 
                $r = q("SELECT * FROM `photo` WHERE `scale` = %d AND `uid` = %d AND `profile` = 1 LIMIT 1",
                        intval($resolution),
                        intval($uid)
                );
-               if(count($r)) {
+               if (DBM::is_result($r)) {
                        $data = $r[0]['data'];
+                       $mimetype = $r[0]['type'];
                }
-               if(! isset($data)) {
+               if (empty($data)) {
                        $data = file_get_contents($default);
+                       $mimetype = 'image/jpeg';
                }
-       }
-       else {
+       } else {
+               // Other photos
+               $resolution = 0;
+               $photo = str_replace(['.jpg', '.png', '.gif'], ['', '', ''], $photo);
 
-               /**
-                * Other photos
-                */
+               foreach (Image::supportedTypes() AS $m => $e) {
+                       $photo = str_replace('.' . $e, '', $photo);
+               }
 
-               $resolution = 0;
-               $photo = str_replace('.jpg','',$photo);
-       
-               if(substr($photo,-2,1) == '-') {
-                       $resolution = intval(substr($photo,-1,1));
-                       $photo = substr($photo,0,-2);
+               if (substr($photo, -2, 1) == '-') {
+                       $resolution = intval(substr($photo, -1, 1));
+                       $photo = substr($photo, 0, -2);
                }
 
-               $r = q("SELECT `uid` FROM `photo` WHERE `resource-id` = '%s' AND `scale` = %d LIMIT 1",
+               // check if the photo exists and get the owner of the photo
+               $r = q("SELECT `uid` FROM `photo` WHERE `resource-id` = '%s' LIMIT 1",
                        dbesc($photo),
                        intval($resolution)
                );
-               if(count($r)) {
-                       
+               if (DBM::is_result($r)) {
                        $sql_extra = permissions_sql($r[0]['uid']);
 
                        // Now we'll see if we can access the photo
-
-                       $r = q("SELECT * FROM `photo` WHERE `resource-id` = '%s' AND `scale` = %d $sql_extra LIMIT 1",
+                       $r = q("SELECT * FROM `photo` WHERE `resource-id` = '%s' AND `scale` <= %d $sql_extra ORDER BY scale DESC LIMIT 1",
                                dbesc($photo),
                                intval($resolution)
                        );
-
-                       if(count($r)) {
+                       if (DBM::is_result($r)) {
+                               $resolution = $r[0]['scale'];
                                $data = $r[0]['data'];
-                       }
-                       else {
-
-                               // Does the picture exist? It may be a remote person with no credentials,
-                               // but who should otherwise be able to view it. Show a default image to let 
-                               // them know permissions was denied. It may be possible to view the image 
-                               // through an authenticated profile visit.
-                               // There won't be many completely unauthorised people seeing this because
-                               // they won't have the photo link, so there's a reasonable chance that the person
-                               // might be able to obtain permission to view it.
-                               $r = q("SELECT * FROM `photo` WHERE `resource-id` = '%s' AND `scale` = %d LIMIT 1",
-                                       dbesc($photo),
-                                       intval($resolution)
-                               );
-                               if(count($r)) {
-                                       $data = file_get_contents('images/nosign.jpg');
-                                       $prvcachecontrol = true;
-                               }
+                               $mimetype = $r[0]['type'];
+                               $public = $r[0]['allow_cid'] == '' && $r[0]['allow_gid'] == '' && $r[0]['deny_cid'] == '' && $r[0]['deny_gid'] == '';
+                       } else {
+                               // The picure exists. We already checked with the first query.
+                               // obviously, this is not an authorized viev!
+                               $data = file_get_contents('images/nosign.jpg');
+                               $mimetype = 'image/jpeg';
+                               $prvcachecontrol = true;
+                               $public = false;
                        }
                }
        }
 
-       if(! isset($data)) {
-               if(isset($resolution)) {
-                       switch($resolution) {
-
+       if (empty($data)) {
+               if (isset($resolution)) {
+                       switch ($resolution) {
                                case 4:
                                        $data = file_get_contents('images/person-175.jpg');
+                                       $mimetype = 'image/jpeg';
                                        break;
                                case 5:
                                        $data = file_get_contents('images/person-80.jpg');
+                                       $mimetype = 'image/jpeg';
                                        break;
                                case 6:
                                        $data = file_get_contents('images/person-48.jpg');
+                                       $mimetype = 'image/jpeg';
                                        break;
                                default:
                                        killme();
@@ -163,42 +157,53 @@ function photo_init(&$a) {
                }
        }
 
-       if(isset($customres) && $customres > 0 && $customres < 500) {
-               require_once('include/Photo.php');
-               $ph = new Photo($data);
-               if($ph->is_valid()) {
-                       $ph->scaleImageSquare($customres);
-                       $data = $ph->imageString();
+       // Resize only if its not a GIF and it is supported by the library
+       if ($mimetype != "image/gif" && in_array($mimetype, Image::supportedTypes())) {
+               $Image = new Image($data, $mimetype);
+               if ($Image->isValid()) {
+                       if (isset($customres) && $customres > 0 && $customres < 500) {
+                               $Image->scaleToSquare($customres);
+                       }
+                       $data = $Image->asString();
+                       $mimetype = $Image->getType();
                }
        }
 
-       // Writing in cachefile
-       if (isset($cachefile) && $cachefile != '')
-               file_put_contents($cachefile, $data);
-
-       if(function_exists('header_remove')) {
+       if (function_exists('header_remove')) {
                header_remove('Pragma');
                header_remove('pragma');
        }
 
-       header("Content-type: image/jpeg");
-
-       if($prvcachecontrol) {
+       header("Content-type: " . $mimetype);
 
+       if ($prvcachecontrol) {
                // it is a private photo that they have no permission to view.
                // tell the browser not to cache it, in case they authenticate
                // and subsequently have permission to see it
-
                header("Cache-Control: no-store, no-cache, must-revalidate");
-
+       } else {
+               header("Last-Modified: " . gmdate("D, d M Y H:i:s", time()) . " GMT");
+               header('Etag: "' . md5($data) . '"');
+               header("Expires: " . gmdate("D, d M Y H:i:s", time() + (31536000)) . " GMT");
+               header("Cache-Control: max-age=31536000");
        }
-       else {
+       echo $data;
 
-               header("Expires: " . gmdate("D, d M Y H:i:s", time() + (3600*24)) . " GMT");
-               header("Cache-Control: max-age=" . (3600*24));
+       // If the photo is public and there is an existing photo directory store the photo there
+       if ($public and $file != '') {
+               // If the photo path isn't there, try to create it
+               $basepath = $a->get_basepath();
+               if (!is_dir($basepath . "/photo")) {
+                       if (is_writable($basepath)) {
+                               mkdir($basepath . "/photo");
+                       }
+               }
 
+               if (is_dir($basepath . "/photo")) {
+                       file_put_contents($basepath . "/photo/" . $file, $data);
+               }
        }
-       echo $data;
+
        killme();
        // NOTREACHED
 }