grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026. -------------------------------------------------------------------------- */ /** @file * @brief */ include ('../inc/includes.php'); if (!$CFG_GLPI["use_public_faq"]) { Session::checkLoginUser(); } $doc = new Document(); if (isset($_GET['docid'])) { // docid for document if (!$doc->getFromDB($_GET['docid'])) { Html::displayErrorAndDie(__('Unknown file'), true); } if (!file_exists(GLPI_DOC_DIR."/".$doc->fields['filepath'])) { Html::displayErrorAndDie(__('File not found'), true); // Not found } else if ($doc->canViewFile($_GET)) { if ($doc->fields['sha1sum'] && $doc->fields['sha1sum'] != sha1_file(GLPI_DOC_DIR."/".$doc->fields['filepath'])) { Html::displayErrorAndDie(__('File is altered (bad checksum)'), true); // Doc alterated } else { $doc->send(); } } else { Html::displayErrorAndDie(__('Unauthorized access to this file'), true); // No right } } else if (isset($_GET["file"])) { // for other file $splitter = explode("/",$_GET["file"], 2); if (count($splitter) == 2) { $send = false; if (($splitter[0] == "_dumps") && Session::haveRight("backup", CREATE)) { $send = true; } if ($splitter[0] == "_pictures") { $filename = explode(".", $splitter[1]); //check extension if (in_array($filename[1], array('jpg', 'jpeg', 'png', 'bmp', 'gif'))) { $send = true; } } if ($send && file_exists(GLPI_DOC_DIR."/".$_GET["file"])) { Toolbox::sendFile(GLPI_DOC_DIR."/".$_GET["file"], $splitter[1]); } else { Html::displayErrorAndDie(__('Unauthorized access to this file'), true); } } else { Html::displayErrorAndDie(__('Invalid filename'), true); } } ?>