2010-08-02 12:36:55 +02:00
|
|
|
<?php
|
|
|
|
// Pandora FMS - http://pandorafms.com
|
|
|
|
// ==================================================
|
|
|
|
// Copyright (c) 2005-2010 Artica Soluciones Tecnologicas
|
|
|
|
// Please see http://pandorafms.org for full contribution list
|
|
|
|
// This program is free software; you can redistribute it and/or
|
|
|
|
// modify it under the terms of the GNU Lesser General Public License
|
|
|
|
// as published by the Free Software Foundation; version 2
|
|
|
|
// This program is distributed in the hope that it will be useful,
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU General Public License for more details.
|
2018-11-21 13:08:58 +01:00
|
|
|
// Don't start a session before this import.
|
|
|
|
// The session is configured and started inside the config process.
|
2019-01-30 16:18:44 +01:00
|
|
|
require_once 'config.php';
|
|
|
|
require_once 'functions.php';
|
|
|
|
require_once 'functions_filemanager.php';
|
2018-11-21 13:08:58 +01:00
|
|
|
|
2010-08-02 12:36:55 +02:00
|
|
|
global $config;
|
|
|
|
|
2019-01-30 16:18:44 +01:00
|
|
|
check_login();
|
2015-07-22 13:30:45 +02:00
|
|
|
|
2012-12-17 14:44:28 +01:00
|
|
|
$auth_method = db_get_value('value', 'tconfig', 'token', 'auth');
|
|
|
|
|
2019-01-30 16:18:44 +01:00
|
|
|
if ($auth_method != 'ad' && $auth_method != 'ldap') {
|
|
|
|
include_once 'auth/'.$auth_method.'.php';
|
2018-11-19 16:33:27 +01:00
|
|
|
}
|
2010-08-02 12:36:55 +02:00
|
|
|
|
|
|
|
|
2019-01-30 16:18:44 +01:00
|
|
|
$styleError = 'background:url("../images/err.png") no-repeat scroll 0 0 transparent; padding:4px 1px 6px 30px; color:#CC0000;';
|
2010-08-02 12:36:55 +02:00
|
|
|
|
2020-01-07 17:31:14 +01:00
|
|
|
$file_raw = get_parameter('file', null);
|
2012-12-17 14:44:28 +01:00
|
|
|
|
2020-01-07 17:31:14 +01:00
|
|
|
$file = base64_decode(urldecode($file_raw));
|
2012-12-17 14:44:28 +01:00
|
|
|
|
2010-08-02 12:36:55 +02:00
|
|
|
$hash = get_parameter('hash', null);
|
|
|
|
|
2020-01-07 17:31:14 +01:00
|
|
|
if ($file === '' || $hash === '' || $hash !== md5($file_raw.$config['dbpass']) || !isset($_SERVER['HTTP_REFERER'])) {
|
2019-01-30 16:18:44 +01:00
|
|
|
echo "<h3 style='".$styleError."'>".__('Security error. Please contact the administrator.').'</h3>';
|
2020-01-07 17:31:14 +01:00
|
|
|
} else {
|
|
|
|
$downloadable_file = '';
|
|
|
|
$parse_all_queries = explode('&', parse_url($_SERVER['HTTP_REFERER'], PHP_URL_QUERY));
|
|
|
|
$parse_sec2_query = explode('=', $parse_all_queries[1]);
|
2020-05-12 08:43:16 +02:00
|
|
|
// If is metaconsole, the file manager has a route distinct than node.
|
|
|
|
$main_file_manager = (is_metaconsole() === true) ? 'advanced/metasetup' : 'godmode/setup/file_manager';
|
2020-01-07 17:31:14 +01:00
|
|
|
if ($parse_sec2_query[0] === 'sec2') {
|
|
|
|
switch ($parse_sec2_query[1]) {
|
2020-05-12 08:43:16 +02:00
|
|
|
case $main_file_manager:
|
2020-01-07 17:31:14 +01:00
|
|
|
$downloadable_file = $_SERVER['DOCUMENT_ROOT'].'/pandora_console/'.$file;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case 'extensions/files_repo':
|
|
|
|
$downloadable_file = $_SERVER['DOCUMENT_ROOT'].'/pandora_console/attachment/files_repo/'.$file;
|
|
|
|
break;
|
|
|
|
|
2020-03-05 14:52:04 +01:00
|
|
|
case 'enterprise/godmode/agentes/collections':
|
|
|
|
$downloadable_file = $_SERVER['DOCUMENT_ROOT'].'/pandora_console/attachment/collection/'.$file;
|
|
|
|
break;
|
|
|
|
|
2020-05-12 11:56:53 +02:00
|
|
|
case 'advanced/collections':
|
|
|
|
if (is_metaconsole() === true) {
|
|
|
|
$downloadable_file = '/'.$file;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
|
2020-01-07 17:31:14 +01:00
|
|
|
default:
|
|
|
|
$downloadable_file = '';
|
|
|
|
// Do nothing
|
|
|
|
break;
|
|
|
|
}
|
2019-01-30 16:18:44 +01:00
|
|
|
}
|
|
|
|
|
2020-01-07 17:31:14 +01:00
|
|
|
if ($downloadable_file === '' || !file_exists($downloadable_file)) {
|
2019-01-30 16:18:44 +01:00
|
|
|
echo "<h3 style='".$styleError."'>".__('File is missing in disk storage. Please contact the administrator.').'</h3>';
|
|
|
|
} else {
|
|
|
|
header('Content-type: aplication/octet-stream;');
|
2020-01-07 17:31:14 +01:00
|
|
|
header('Content-type: '.mime_content_type($downloadable_file).';');
|
|
|
|
header('Content-Length: '.filesize($downloadable_file));
|
|
|
|
header('Content-Disposition: attachment; filename="'.basename($downloadable_file).'"');
|
|
|
|
readfile($downloadable_file);
|
2019-01-30 16:18:44 +01:00
|
|
|
}
|
2010-08-02 12:36:55 +02:00
|
|
|
}
|