59177427 |
1 | <?php |
895905c0 |
2 | |
35586184 |
3 | /** |
4 | * download.php |
5 | * |
76911253 |
6 | * Copyright (c) 1999-2003 The SquirrelMail Project Team |
35586184 |
7 | * Licensed under the GNU GPL. For full terms see the file COPYING. |
8 | * |
9 | * Handles attachment downloads to the users computer. |
10 | * Also allows displaying of attachments when possible. |
11 | * |
12 | * $Id$ |
13 | */ |
14 | |
86725763 |
15 | /* Path for SquirrelMail required files. */ |
16 | define('SM_PATH','../'); |
17 | |
18 | /* SquirrelMail required files. */ |
08185f2a |
19 | require_once(SM_PATH . 'include/validate.php'); |
86725763 |
20 | require_once(SM_PATH . 'functions/imap.php'); |
21 | require_once(SM_PATH . 'functions/mime.php'); |
6b96544a |
22 | |
65c3ec94 |
23 | header('Pragma: '); |
24 | header('Cache-Control: cache'); |
25 | |
0b97a708 |
26 | /* globals */ |
1e12d1ff |
27 | sqgetGlobalVar('key', $key, SQ_COOKIE); |
28 | sqgetGlobalVar('username', $username, SQ_SESSION); |
29 | sqgetGlobalVar('onetimepad', $onetimepad, SQ_SESSION); |
30 | sqgetGlobalVar('messages', $messages, SQ_SESSION); |
31 | sqgetGlobalVar('mailbox', $mailbox, SQ_GET); |
32 | sqgetGlobalVar('ent_id', $ent_id, SQ_GET); |
33 | sqgetGlobalVar('absolute_dl',$absolute_dl, SQ_GET); |
34 | if ( sqgetGlobalVar('passed_id', $temp, SQ_GET) ) { |
35 | $passed_id = (int) $temp; |
36 | } |
1075eaf1 |
37 | |
0b97a708 |
38 | /* end globals */ |
97d7da3b |
39 | |
1075eaf1 |
40 | global $uid_support; |
97d7da3b |
41 | |
1e606225 |
42 | $imapConnection = sqimap_login($username, $key, $imapServerAddress, $imapPort, 0); |
43 | $mbx_response = sqimap_mailbox_select($imapConnection, $mailbox); |
97d7da3b |
44 | |
1e606225 |
45 | $message = &$messages[$mbx_response['UIDVALIDITY']]["$passed_id"]; |
5a1c48cd |
46 | if (!is_object($message)) { |
47 | $message = sqimap_get_message($imapConnection,$passed_id, $mailbox); |
48 | } |
ff9d4297 |
49 | $subject = $message->rfc822_header->subject; |
6914aa18 |
50 | if ($ent_id) { |
51 | $message = &$message->getEntity($ent_id); |
52 | $header = $message->header; |
53 | |
54 | if ($message->rfc822_header) { |
55 | $subject = $message->rfc822_header->subject; |
6914aa18 |
56 | } else { |
57 | $header = $message->header; |
6914aa18 |
58 | } |
59 | $type0 = $header->type0; |
60 | $type1 = $header->type1; |
61 | $encoding = strtolower($header->encoding); |
ff9d4297 |
62 | } else { |
6914aa18 |
63 | /* raw message */ |
64 | $type0 = 'message'; |
65 | $type1 = 'rfc822'; |
bc5ff7c9 |
66 | $encoding = 'US-ASCII'; |
5d39ca4d |
67 | $header = $message->header; |
ff9d4297 |
68 | } |
97d7da3b |
69 | |
65c3ec94 |
70 | /* |
71 | * lets redefine message as this particular entity that we wish to display. |
72 | * it should hold only the header for this entity. We need to fetch the body |
73 | * yet before we can display anything. |
74 | */ |
65c3ec94 |
75 | |
65c3ec94 |
76 | if (isset($override_type0)) { |
77 | $type0 = $override_type0; |
78 | } |
79 | if (isset($override_type1)) { |
80 | $type1 = $override_type1; |
81 | } |
ff9d4297 |
82 | $filename = ''; |
83 | if (is_object($message->header->disposition)) { |
a91189d6 |
84 | $filename = $header->disposition->getProperty('filename'); |
ff9d4297 |
85 | if (!$filename) { |
708ea172 |
86 | $filename = $header->disposition->getProperty('name'); |
ff9d4297 |
87 | } |
6914aa18 |
88 | if (!$filename) { |
a91189d6 |
89 | $filename = $header->getParameter('name'); |
6914aa18 |
90 | } |
cf22004d |
91 | } else { |
5d39ca4d |
92 | $filename = $header->getParameter('name'); |
65c3ec94 |
93 | } |
bc5ff7c9 |
94 | |
387adcdb |
95 | $filename = decodeHeader($filename, true, false); //Don't want html output |
65c3ec94 |
96 | if (strlen($filename) < 1) { |
97 | if ($type1 == 'plain' && $type0 == 'text') { |
98 | $suffix = 'txt'; |
708ea172 |
99 | $filename = $subject . '.txt'; |
65c3ec94 |
100 | } else if ($type1 == 'richtext' && $type0 == 'text') { |
101 | $suffix = 'rtf'; |
708ea172 |
102 | $filename = $subject . '.rtf'; |
65c3ec94 |
103 | } else if ($type1 == 'postscript' && $type0 == 'application') { |
104 | $suffix = 'ps'; |
708ea172 |
105 | $filename = $subject . '.ps'; |
97d7da3b |
106 | } else if ($type1 == 'rfc822' && $type0 == 'message') { |
107 | $suffix = 'eml'; |
708ea172 |
108 | $filename = $subject . '.msg'; |
65c3ec94 |
109 | } else { |
110 | $suffix = $type1; |
111 | } |
112 | |
631db37e |
113 | if (strlen($filename) < 1) { |
5d39ca4d |
114 | $filename = 'untitled'.strip_tags($ent_id).'.'.$suffix; |
631db37e |
115 | } else { |
ff9d4297 |
116 | $filename = "$filename.$suffix"; |
631db37e |
117 | } |
65c3ec94 |
118 | } |
119 | |
120 | /* |
121 | * Note: |
122 | * The following sections display the attachment in different |
123 | * ways depending on how they choose. The first way will download |
124 | * under any circumstance. This sets the Content-type to be |
125 | * applicatin/octet-stream, which should be interpreted by the |
126 | * browser as "download me". |
127 | * The second method (view) is used for images or other formats |
128 | * that should be able to be handled by the browser. It will |
129 | * most likely display the attachment inline inside the browser. |
130 | * And finally, the third one will be used by default. If it |
131 | * is displayable (text or html), it will load them up in a text |
132 | * viewer (built in to squirrelmail). Otherwise, it sets the |
133 | * content-type as application/octet-stream |
134 | */ |
88d916ee |
135 | if (isset($absolute_dl) && $absolute_dl) { |
5c553e34 |
136 | DumpHeaders($type0, $type1, $filename, 1); |
65c3ec94 |
137 | } else { |
5c553e34 |
138 | DumpHeaders($type0, $type1, $filename, 0); |
65c3ec94 |
139 | } |
38bca81c |
140 | /* be aware that any warning caused by download.php will corrupt the |
141 | * attachment in case of ERROR reporting = E_ALL and the output is the screen */ |
ff9d4297 |
142 | mime_print_body_lines ($imapConnection, $passed_id, $ent_id, $encoding); |
65c3ec94 |
143 | |
65c3ec94 |
144 | /* |
145 | * This function is verified to work with Netscape and the *very latest* |
146 | * version of IE. I don't know if it works with Opera, but it should now. |
147 | */ |
148 | function DumpHeaders($type0, $type1, $filename, $force) { |
1e12d1ff |
149 | global $languages, $squirrelmail_language; |
88d916ee |
150 | $isIE = $isIE6 = 0; |
97d7da3b |
151 | |
1e12d1ff |
152 | sqgetGlobalVar('HTTP_USER_AGENT', $HTTP_USER_AGENT, SQ_SERVER); |
0b97a708 |
153 | |
65c3ec94 |
154 | if (strstr($HTTP_USER_AGENT, 'compatible; MSIE ') !== false && |
155 | strstr($HTTP_USER_AGENT, 'Opera') === false) { |
36294f1a |
156 | $isIE = 1; |
65c3ec94 |
157 | } |
158 | |
97d7da3b |
159 | if (strstr($HTTP_USER_AGENT, 'compatible; MSIE 6') !== false && |
160 | strstr($HTTP_USER_AGENT, 'Opera') === false) { |
161 | $isIE6 = 1; |
162 | } |
163 | |
7dae3923 |
164 | if (isset($languages[$squirrelmail_language]['XTRA_CODE']) && |
165 | function_exists($languages[$squirrelmail_language]['XTRA_CODE'])) { |
6fbd125b |
166 | $filename = |
167 | $languages[$squirrelmail_language]['XTRA_CODE']('downloadfilename', $filename, $HTTP_USER_AGENT); |
83be314a |
168 | } else { |
aff49d6c |
169 | // $filename = ereg_replace('[^-a-zA-Z0-9\.]', '_', $filename); |
387adcdb |
170 | $filename = ereg_replace('[\\/:\*\?"<>\|;]', '_', $filename); |
83be314a |
171 | } |
387adcdb |
172 | // We don't need to care about " since they have been replaced by _ |
65c3ec94 |
173 | // A Pox on Microsoft and it's Office! |
88d916ee |
174 | if (!$force) { |
65c3ec94 |
175 | // Try to show in browser window |
176 | header("Content-Disposition: inline; filename=\"$filename\""); |
177 | header("Content-Type: $type0/$type1; name=\"$filename\""); |
178 | } else { |
179 | // Try to pop up the "save as" box |
180 | // IE makes this hard. It pops up 2 save boxes, or none. |
181 | // http://support.microsoft.com/support/kb/articles/Q238/5/88.ASP |
182 | // But, accordint to Microsoft, it is "RFC compliant but doesn't |
183 | // take into account some deviations that allowed within the |
184 | // specification." Doesn't that mean RFC non-compliant? |
185 | // http://support.microsoft.com/support/kb/articles/Q258/4/52.ASP |
186 | // |
187 | // The best thing you can do for IE is to upgrade to the latest |
188 | // version |
88d916ee |
189 | if ($isIE && !$isIE6) { |
65c3ec94 |
190 | // http://support.microsoft.com/support/kb/articles/Q182/3/15.asp |
191 | // Do not have quotes around filename, but that applied to |
192 | // "attachment"... does it apply to inline too? |
193 | // |
194 | // This combination seems to work mostly. IE 5.5 SP 1 has |
195 | // known issues (see the Microsoft Knowledge Base) |
196 | header("Content-Disposition: inline; filename=$filename"); |
65c3ec94 |
197 | // This works for most types, but doesn't work with Word files |
198 | header("Content-Type: application/download; name=\"$filename\""); |
199 | |
200 | // These are spares, just in case. :-) |
201 | //header("Content-Type: $type0/$type1; name=\"$filename\""); |
202 | //header("Content-Type: application/x-msdownload; name=\"$filename\""); |
203 | //header("Content-Type: application/octet-stream; name=\"$filename\""); |
204 | } else { |
205 | header("Content-Disposition: attachment; filename=\"$filename\""); |
206 | // application/octet-stream forces download for Netscape |
207 | header("Content-Type: application/octet-stream; name=\"$filename\""); |
208 | } |
209 | } |
210 | } |
631db37e |
211 | ?> |