3 +--------------------------------------------------------------------+
4 | CiviCRM version 4.4 |
5 +--------------------------------------------------------------------+
6 | Copyright CiviCRM LLC (c) 2004-2014 |
7 +--------------------------------------------------------------------+
8 | This file is a part of CiviCRM. |
10 | CiviCRM is free software; you can copy, modify, and distribute it |
11 | under the terms of the GNU Affero General Public License |
12 | Version 3, 19 November 2007 and the CiviCRM Licensing Exception. |
14 | CiviCRM is distributed in the hope that it will be useful, but |
15 | WITHOUT ANY WARRANTY; without even the implied warranty of |
16 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
17 | See the GNU Affero General Public License for more details. |
19 | You should have received a copy of the GNU Affero General Public |
20 | License and the CiviCRM Licensing Exception along |
21 | with this program; if not, contact CiviCRM LLC |
22 | at info[AT]civicrm[DOT]org. If you have questions about the |
23 | GNU Affero General Public License or the licensing of CiviCRM, |
24 | see the CiviCRM license FAQ at http://civicrm.org/licensing |
25 +--------------------------------------------------------------------+
31 * @copyright CiviCRM LLC (c) 2004-2014
35 class CRM_Contact_Page_ImageFile
extends CRM_Core_Page
{
38 * @var int Time to live (seconds).
40 * 12 hours: 12 * 60 * 60 = 43200
45 if (!preg_match('/^[^\/]+\.(jpg|jpeg|png|gif)$/i', $_GET['photo'])) {
46 CRM_Core_Error
::fatal('Malformed photo name');
49 // FIXME Optimize performance of image_url query
50 $sql = "SELECT id FROM civicrm_contact WHERE image_url like %1;";
52 1 => array("%" . $_GET['photo'], 'String')
54 $dao = CRM_Core_DAO
::executeQuery($sql, $params);
55 while ($dao->fetch()) {
59 $config = CRM_Core_Config
::singleton();
61 $config->customFileUploadDir
. $_GET['photo'],
62 'image/' . pathinfo($_GET['photo'], PATHINFO_EXTENSION
),
65 CRM_Utils_System
::civiExit();
68 CRM_Core_Error
::fatal('Photo does not exist');
75 * @param string $mimeType
77 * Time to live (seconds).
79 protected function download($file, $mimeType, $ttl) {
80 if (!file_exists($file)) {
81 header("HTTP/1.0 404 Not Found");
83 } elseif (!is_readable($file)) {
84 header('HTTP/1.0 403 Forbidden');
87 header('Expires: ' . gmdate('D, d M Y H:i:s \G\M\T', CRM_Utils_Time
::getTimeRaw() +
$ttl));
88 header("Content-Type: $mimeType");
89 header("Content-Disposition: inline; filename=\"" . basename($file) . "\"");
90 header("Cache-Control: max-age=$ttl, public");
91 header('Pragma: public');