X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=src%2Fdownload.php;h=a021558afc5262d60edefc0a7ef4f0be149a71c4;hp=e630d95b0928c615d4991c6bcd237afb884c9d1c;hb=ea5f4b8eaf805c4cc4e9533e87d057300a7fe666;hpb=7dae3923bce31e86ee1ab74fbc6020c4e2270514 diff --git a/src/download.php b/src/download.php index e630d95b..a021558a 100644 --- a/src/download.php +++ b/src/download.php @@ -3,7 +3,7 @@ /** * download.php * - * Copyright (c) 1999-2002 The SquirrelMail Project Team + * Copyright (c) 1999-2003 The SquirrelMail Project Team * Licensed under the GNU GPL. For full terms see the file COPYING. * * Handles attachment downloads to the users computer. @@ -12,73 +12,61 @@ * $Id$ */ -require_once('../src/validate.php'); -require_once('../functions/imap.php'); -require_once('../functions/mime.php'); +/* Path for SquirrelMail required files. */ +define('SM_PATH','../'); + +/* SquirrelMail required files. */ +require_once(SM_PATH . 'include/validate.php'); +require_once(SM_PATH . 'functions/imap.php'); +require_once(SM_PATH . 'functions/mime.php'); header('Pragma: '); header('Cache-Control: cache'); -function get_extract_to_target_list($imapConnection) { - $boxes = sqimap_mailbox_list($imapConnection); - for ($i = 0; $i < count($boxes); $i++) { - if (!in_array('noselect', $boxes[$i]['flags'])) { - $box = $boxes[$i]['unformatted']; - $box2 = str_replace(' ', ' ', $boxes[$i]['unformatted-disp']); - if ( $box2 == 'INBOX' ) { - $box2 = _("INBOX"); - } - echo "\n"; - } - } -} -$mailbox = decodeHeader($mailbox); +/* globals */ +sqgetGlobalVar('key', $key, SQ_COOKIE); +sqgetGlobalVar('username', $username, SQ_SESSION); +sqgetGlobalVar('onetimepad', $onetimepad, SQ_SESSION); +sqgetGlobalVar('messages', $messages, SQ_SESSION); +sqgetGlobalVar('mailbox', $mailbox, SQ_GET); +sqgetGlobalVar('ent_id', $ent_id, SQ_GET); +sqgetGlobalVar('absolute_dl',$absolute_dl, SQ_GET); +if ( sqgetGlobalVar('passed_id', $temp, SQ_GET) ) { + $passed_id = (int) $temp; +} -global $messages, $uid_support; +/* end globals */ + +global $uid_support; $imapConnection = sqimap_login($username, $key, $imapServerAddress, $imapPort, 0); $mbx_response = sqimap_mailbox_select($imapConnection, $mailbox); -if (!isset($passed_ent_id)) { - $passed_ent_id = ''; -} $message = &$messages[$mbx_response['UIDVALIDITY']]["$passed_id"]; +if (!is_object($message)) { + $message = sqimap_get_message($imapConnection,$passed_id, $mailbox); +} $subject = $message->rfc822_header->subject; -$message = &$message->getEntity($ent_id); -$header = $message->header; -if ($message->rfc822_header) { - $subject = $message->rfc822_header->subject; - $charset = $header->content_type->properties['charset']; +if ($ent_id) { + $message = &$message->getEntity($ent_id); + $header = $message->header; + + if ($message->rfc822_header) { + $subject = $message->rfc822_header->subject; + } else { + $header = $message->header; + } + $type0 = $header->type0; + $type1 = $header->type1; + $encoding = strtolower($header->encoding); } else { - $header = $message->header; - $charset = $header->getParameter('charset'); + /* raw message */ + $type0 = 'message'; + $type1 = 'rfc822'; + $encoding = 'US-ASCII'; + $header = $message->header; } -$type0 = $header->type0; -$type1 = $header->type1; -$encoding = strtolower($header->encoding); -/* -$extracted = false; -if (isset($extract_message) && $extract_message) { - $cmd = "FETCH $passed_id BODY[$passed_ent_id]"; - $read = sqimap_run_command ($imapConnection, $cmd, true, $response, $message, $uid_support); - $cnt = count($read); - $body = ''; - $length = 0; - for ($i=1;$i<$cnt;$i++) { - $length = $length + strlen($read[$i]); - $body .= $read[$i]; - } - if (isset($targetMailbox) && $length>0) { - sqimap_append ($imapConnection, $targetMailbox, $length); - fputs($imapConnection,$body); - sqimap_append_done ($imapConnection); - $extracted = true; - } -} - - -*/ /* * lets redefine message as this particular entity that we wish to display. * it should hold only the header for this entity. We need to fetch the body @@ -93,30 +81,37 @@ if (isset($override_type1)) { } $filename = ''; if (is_object($message->header->disposition)) { - $filename = decodeHeader($header->disposition->getProperty('filename')); + $filename = $header->disposition->getProperty('filename'); if (!$filename) { - $filename = decodeHeader($header->disposition->getProperty('name')); + $filename = $header->disposition->getProperty('name'); } + if (!$filename) { + $filename = $header->getParameter('name'); + } +} else { + $filename = $header->getParameter('name'); } + +$filename = decodeHeader($filename, true, false); //Don't want html output if (strlen($filename) < 1) { if ($type1 == 'plain' && $type0 == 'text') { $suffix = 'txt'; - $filename = $subject . '.txt'; + $filename = $subject . '.txt'; } else if ($type1 == 'richtext' && $type0 == 'text') { $suffix = 'rtf'; - $filename = $subject . '.rtf'; + $filename = $subject . '.rtf'; } else if ($type1 == 'postscript' && $type0 == 'application') { $suffix = 'ps'; - $filename = $subject . '.ps'; + $filename = $subject . '.ps'; } else if ($type1 == 'rfc822' && $type0 == 'message') { $suffix = 'eml'; - $filename = $subject . '.msg'; + $filename = $subject . '.msg'; } else { $suffix = $type1; } if (strlen($filename) < 1) { - $filename = "untitled$ent_id.$suffix"; + $filename = 'untitled'.strip_tags($ent_id).'.'.$suffix; } else { $filename = "$filename.$suffix"; } @@ -137,7 +132,7 @@ if (strlen($filename) < 1) { * viewer (built in to squirrelmail). Otherwise, it sets the * content-type as application/octet-stream */ -if (isset($absolute_dl) && $absolute_dl == 'true') { +if (isset($absolute_dl) && $absolute_dl) { DumpHeaders($type0, $type1, $filename, 1); } else { DumpHeaders($type0, $type1, $filename, 0); @@ -151,8 +146,10 @@ mime_print_body_lines ($imapConnection, $passed_id, $ent_id, $encoding); * version of IE. I don't know if it works with Opera, but it should now. */ function DumpHeaders($type0, $type1, $filename, $force) { - global $HTTP_USER_AGENT, $languages, $squirrelmail_language; - $isIE = 0; + global $languages, $squirrelmail_language; + $isIE = $isIE6 = 0; + + sqgetGlobalVar('HTTP_USER_AGENT', $HTTP_USER_AGENT, SQ_SERVER); if (strstr($HTTP_USER_AGENT, 'compatible; MSIE ') !== false && strstr($HTTP_USER_AGENT, 'Opera') === false) { @@ -169,11 +166,12 @@ function DumpHeaders($type0, $type1, $filename, $force) { $filename = $languages[$squirrelmail_language]['XTRA_CODE']('downloadfilename', $filename, $HTTP_USER_AGENT); } else { - $filename = ereg_replace('[^-a-zA-Z0-9\.]', '_', $filename); +// $filename = ereg_replace('[^-a-zA-Z0-9\.]', '_', $filename); + $filename = ereg_replace('[\\/:\*\?"<>\|;]', '_', $filename); } - + // We don't need to care about " since they have been replaced by _ // A Pox on Microsoft and it's Office! - if (! $force) { + if (!$force) { // Try to show in browser window header("Content-Disposition: inline; filename=\"$filename\""); header("Content-Type: $type0/$type1; name=\"$filename\""); @@ -188,7 +186,7 @@ function DumpHeaders($type0, $type1, $filename, $force) { // // The best thing you can do for IE is to upgrade to the latest // version - if ($isIE && !isset($isIE6)) { + if ($isIE && !$isIE6) { // http://support.microsoft.com/support/kb/articles/Q182/3/15.asp // Do not have quotes around filename, but that applied to // "attachment"... does it apply to inline too? @@ -196,7 +194,6 @@ function DumpHeaders($type0, $type1, $filename, $force) { // This combination seems to work mostly. IE 5.5 SP 1 has // known issues (see the Microsoft Knowledge Base) header("Content-Disposition: inline; filename=$filename"); - // This works for most types, but doesn't work with Word files header("Content-Type: application/download; name=\"$filename\"");