949function dol_move($srcfile, $destfile, $newmask = 0, $overwriteifexists = 1, $testvirus = 0, $indexdatabase = 1, $moreinfo = array())
951 global $user, $db, $conf;
954 dol_syslog(
"files.lib.php::dol_move srcfile=".$srcfile.
" destfile=".$destfile.
" newmask=".$newmask.
" overwritifexists=".$overwriteifexists);
959 dol_syslog(
"files.lib.php::dol_move srcfile does not exists. we ignore the move request.");
963 if ($overwriteifexists || !$destexists) {
968 $testvirusarray = array();
971 if (count($testvirusarray)) {
972 dol_syslog(
"files.lib.php::dol_move canceled because a virus was found into source file. we ignore the move request.", LOG_WARNING);
977 global $dolibarr_main_restrict_os_commands;
978 if (!empty($dolibarr_main_restrict_os_commands)) {
979 $arrayofallowedcommand = explode(
',', $dolibarr_main_restrict_os_commands);
980 $arrayofallowedcommand = array_map(
'trim', $arrayofallowedcommand);
981 if (in_array(basename($destfile), $arrayofallowedcommand)) {
984 dol_syslog(
"files.lib.php::dol_move canceled because target filename ".basename($destfile).
" is using a reserved command name. we ignore the move request.", LOG_WARNING);
989 $result = @rename($newpathofsrcfile, $newpathofdestfile);
992 dol_syslog(
"files.lib.php::dol_move Failed. We try to delete target first and move after.", LOG_WARNING);
995 $result = @rename($newpathofsrcfile, $newpathofdestfile);
997 dol_syslog(
"files.lib.php::dol_move Failed.", LOG_WARNING);
1002 if ($result && $indexdatabase) {
1004 $rel_filetorenamebefore = preg_replace(
'/^'.preg_quote(DOL_DATA_ROOT,
'/').
'/',
'', $srcfile);
1005 $rel_filetorenameafter = preg_replace(
'/^'.preg_quote(DOL_DATA_ROOT,
'/').
'/',
'', $destfile);
1006 if (!preg_match(
'/([\\/]temp[\\/]|[\\/]thumbs|\.meta$)/', $rel_filetorenameafter)) {
1007 $rel_filetorenamebefore = preg_replace(
'/^[\\/]/',
'', $rel_filetorenamebefore);
1008 $rel_filetorenameafter = preg_replace(
'/^[\\/]/',
'', $rel_filetorenameafter);
1011 dol_syslog(
"Try to rename also entries in database for full relative path before = ".$rel_filetorenamebefore.
" after = ".$rel_filetorenameafter, LOG_DEBUG);
1012 include_once DOL_DOCUMENT_ROOT.
'/ecm/class/ecmfiles.class.php';
1014 $ecmfiletarget =
new EcmFiles($db);
1015 $resultecmtarget = $ecmfiletarget->fetch(0,
'', $rel_filetorenameafter);
1016 if ($resultecmtarget > 0) {
1017 $ecmfiletarget->delete($user);
1021 $resultecm = $ecmfile->fetch(0,
'', $rel_filetorenamebefore);
1022 if ($resultecm > 0) {
1023 $filename = basename($rel_filetorenameafter);
1024 $rel_dir = dirname($rel_filetorenameafter);
1025 $rel_dir = preg_replace(
'/[\\/]$/',
'', $rel_dir);
1026 $rel_dir = preg_replace(
'/^[\\/]/',
'', $rel_dir);
1028 $ecmfile->filepath = $rel_dir;
1029 $ecmfile->filename = $filename;
1031 $resultecm = $ecmfile->update($user);
1032 } elseif ($resultecm == 0) {
1033 $filename = basename($rel_filetorenameafter);
1034 $rel_dir = dirname($rel_filetorenameafter);
1035 $rel_dir = preg_replace(
'/[\\/]$/',
'', $rel_dir);
1036 $rel_dir = preg_replace(
'/^[\\/]/',
'', $rel_dir);
1038 $ecmfile->filepath = $rel_dir;
1039 $ecmfile->filename = $filename;
1041 $ecmfile->fullpath_orig = basename($srcfile);
1042 $ecmfile->gen_or_uploaded =
'uploaded';
1043 if (!empty($moreinfo) && !empty($moreinfo[
'description'])) {
1044 $ecmfile->description = $moreinfo[
'description'];
1046 $ecmfile->description =
'';
1048 if (!empty($moreinfo) && !empty($moreinfo[
'keywords'])) {
1049 $ecmfile->keywords = $moreinfo[
'keywords'];
1051 $ecmfile->keywords =
'';
1053 if (!empty($moreinfo) && !empty($moreinfo[
'note_private'])) {
1054 $ecmfile->note_private = $moreinfo[
'note_private'];
1056 if (!empty($moreinfo) && !empty($moreinfo[
'note_public'])) {
1057 $ecmfile->note_public = $moreinfo[
'note_public'];
1059 if (!empty($moreinfo) && !empty($moreinfo[
'src_object_type'])) {
1060 $ecmfile->src_object_type = $moreinfo[
'src_object_type'];
1062 if (!empty($moreinfo) && !empty($moreinfo[
'src_object_id'])) {
1063 $ecmfile->src_object_id = $moreinfo[
'src_object_id'];
1066 $resultecm = $ecmfile->create($user);
1067 if ($resultecm < 0) {
1070 } elseif ($resultecm < 0) {
1074 if ($resultecm > 0) {
1082 if (empty($newmask)) {
1089 dolChmod($newpathofdestfile, $newmask);
2575 global $conf, $db, $user, $hookmanager;
2576 global $dolibarr_main_data_root, $dolibarr_main_document_root_alt;
2579 if (!is_object($fuser)) {
2583 if (empty($modulepart)) {
2584 return 'ErrorBadParameter';
2586 if (empty($entity)) {
2587 if (!isModEnabled(
'multicompany')) {
2594 if ($modulepart ==
'users') {
2595 $modulepart =
'user';
2597 if ($modulepart ==
'tva') {
2598 $modulepart =
'tax-vat';
2601 if ($modulepart ==
'expedition' && strpos($original_file,
'receipt/') === 0) {
2602 $modulepart =
'delivery';
2606 dol_syslog(
'dol_check_secure_access_document modulepart='.$modulepart.
' original_file='.$original_file.
' entity='.$entity);
2610 $sqlprotectagainstexternals =
'';
2614 if (empty($refname)) {
2615 $refname = basename(dirname($original_file).
"/");
2616 if ($refname ==
'thumbs' || $refname ==
'temp') {
2618 $refname = basename(dirname(dirname($original_file)).
"/");
2625 $download =
'download';
2626 if ($mode ==
'write') {
2629 $download =
'upload';
2633 if ($modulepart ==
'medias' && !empty($dolibarr_main_data_root)) {
2634 if (empty($entity) || empty($conf->medias->multidir_output[$entity])) {
2635 return array(
'accessallowed'=>0,
'error'=>
'Value entity must be provided');
2638 $original_file = $conf->medias->multidir_output[$entity].
'/'.$original_file;
2639 } elseif ($modulepart ==
'logs' && !empty($dolibarr_main_data_root)) {
2641 $accessallowed = ($user->admin && basename($original_file) == $original_file && preg_match(
'/^dolibarr.*\.(log|json)$/', basename($original_file)));
2642 $original_file = $dolibarr_main_data_root.
'/'.$original_file;
2643 } elseif ($modulepart ==
'doctemplates' && !empty($dolibarr_main_data_root)) {
2645 $accessallowed = $user->admin;
2646 $original_file = $dolibarr_main_data_root.
'/doctemplates/'.$original_file;
2647 } elseif ($modulepart ==
'doctemplateswebsite' && !empty($dolibarr_main_data_root)) {
2649 $accessallowed = ($fuser->rights->website->write && preg_match(
'/\.jpg$/i', basename($original_file)));
2650 $original_file = $dolibarr_main_data_root.
'/doctemplates/websites/'.$original_file;
2651 } elseif ($modulepart ==
'packages' && !empty($dolibarr_main_data_root)) {
2654 $tmp = explode(
',', $dolibarr_main_document_root_alt);
2657 $accessallowed = ($user->admin && preg_match(
'/^module_.*\.zip$/', basename($original_file)));
2658 $original_file = $dirins.
'/'.$original_file;
2659 } elseif ($modulepart ==
'mycompany' && !empty($conf->mycompany->dir_output)) {
2662 $original_file = $conf->mycompany->dir_output.
'/'.$original_file;
2663 } elseif ($modulepart ==
'userphoto' && !empty($conf->user->dir_output)) {
2666 if (preg_match(
'/^\d+\/photos\//', $original_file)) {
2669 $original_file = $conf->user->dir_output.
'/'.$original_file;
2670 } elseif ($modulepart ==
'userphotopublic' && !empty($conf->user->dir_output)) {
2675 if (preg_match(
'/^(\d+)\/photos\//', $original_file, $reg)) {
2677 $tmpobject =
new User($db);
2678 $tmpobject->fetch($reg[1],
'',
'', 1);
2680 $securekey =
GETPOST(
'securekey',
'alpha', 1);
2682 global $dolibarr_main_cookie_cryptkey, $dolibarr_main_instance_unique_id;
2683 $valuetouse = $dolibarr_main_instance_unique_id ? $dolibarr_main_instance_unique_id : $dolibarr_main_cookie_cryptkey;
2684 $encodedsecurekey =
dol_hash($valuetouse.
'uservirtualcard'.$tmpobject->id.
'-'.$tmpobject->login,
'md5');
2685 if ($encodedsecurekey == $securekey) {
2694 $original_file = $conf->user->dir_output.
'/'.$original_file;
2695 } elseif (($modulepart ==
'companylogo') && !empty($conf->mycompany->dir_output)) {
2698 $original_file = $conf->mycompany->dir_output.
'/logos/'.$original_file;
2699 } elseif ($modulepart ==
'memberphoto' && !empty($conf->adherent->dir_output)) {
2702 if (preg_match(
'/^\d+\/photos\//', $original_file)) {
2705 $original_file = $conf->adherent->dir_output.
'/'.$original_file;
2706 } elseif ($modulepart ==
'apercufacture' && !empty($conf->facture->multidir_output[$entity])) {
2708 if ($fuser->hasRight(
'facture', $lire)) {
2711 $original_file = $conf->facture->multidir_output[$entity].
'/'.$original_file;
2712 } elseif ($modulepart ==
'apercupropal' && !empty($conf->propal->multidir_output[$entity])) {
2714 if ($fuser->hasRight(
'propal', $lire)) {
2717 $original_file = $conf->propal->multidir_output[$entity].
'/'.$original_file;
2718 } elseif ($modulepart ==
'apercucommande' && !empty($conf->commande->multidir_output[$entity])) {
2720 if ($fuser->hasRight(
'commande', $lire)) {
2723 $original_file = $conf->commande->multidir_output[$entity].
'/'.$original_file;
2724 } elseif (($modulepart ==
'apercufichinter' || $modulepart ==
'apercuficheinter') && !empty($conf->ficheinter->dir_output)) {
2726 if ($fuser->hasRight(
'ficheinter', $lire)) {
2729 $original_file = $conf->ficheinter->dir_output.
'/'.$original_file;
2730 } elseif (($modulepart ==
'apercucontract') && !empty($conf->contrat->multidir_output[$entity])) {
2732 if ($fuser->hasRight(
'contrat', $lire)) {
2735 $original_file = $conf->contrat->multidir_output[$entity].
'/'.$original_file;
2736 } elseif (($modulepart ==
'apercusupplier_proposal' || $modulepart ==
'apercusupplier_proposal') && !empty($conf->supplier_proposal->dir_output)) {
2738 if ($fuser->hasRight(
'supplier_proposal', $lire)) {
2741 $original_file = $conf->supplier_proposal->dir_output.
'/'.$original_file;
2742 } elseif (($modulepart ==
'apercusupplier_order' || $modulepart ==
'apercusupplier_order') && !empty($conf->fournisseur->commande->dir_output)) {
2744 if ($fuser->hasRight(
'fournisseur',
'commande', $lire)) {
2747 $original_file = $conf->fournisseur->commande->dir_output.
'/'.$original_file;
2748 } elseif (($modulepart ==
'apercusupplier_invoice' || $modulepart ==
'apercusupplier_invoice') && !empty($conf->fournisseur->facture->dir_output)) {
2750 if ($fuser->hasRight(
'fournisseur', $lire)) {
2753 $original_file = $conf->fournisseur->facture->dir_output.
'/'.$original_file;
2754 } elseif (($modulepart ==
'holiday') && !empty($conf->holiday->dir_output)) {
2755 if ($fuser->hasRight(
'holiday', $read) || $fuser->hasRight(
'holiday',
'readall') || preg_match(
'/^specimen/i', $original_file)) {
2758 if ($refname && !$fuser->hasRight(
'holiday',
'readall') && !preg_match(
'/^specimen/i', $original_file)) {
2759 include_once DOL_DOCUMENT_ROOT.
'/holiday/class/holiday.class.php';
2760 $tmpholiday =
new Holiday($db);
2761 $tmpholiday->fetch(
'', $refname);
2762 $accessallowed =
checkUserAccessToObject($user, array(
'holiday'), $tmpholiday,
'holiday',
'',
'',
'rowid',
'');
2765 $original_file = $conf->holiday->dir_output.
'/'.$original_file;
2766 } elseif (($modulepart ==
'expensereport') && !empty($conf->expensereport->dir_output)) {
2767 if ($fuser->hasRight(
'expensereport', $lire) || $fuser->hasRight(
'expensereport',
'readall') || preg_match(
'/^specimen/i', $original_file)) {
2770 if ($refname && !$fuser->hasRight(
'expensereport',
'readall') && !preg_match(
'/^specimen/i', $original_file)) {
2771 include_once DOL_DOCUMENT_ROOT.
'/expensereport/class/expensereport.class.php';
2773 $tmpexpensereport->fetch(
'', $refname);
2774 $accessallowed =
checkUserAccessToObject($user, array(
'expensereport'), $tmpexpensereport,
'expensereport',
'',
'',
'rowid',
'');
2777 $original_file = $conf->expensereport->dir_output.
'/'.$original_file;
2778 } elseif (($modulepart ==
'apercuexpensereport') && !empty($conf->expensereport->dir_output)) {
2780 if ($fuser->hasRight(
'expensereport', $lire)) {
2783 $original_file = $conf->expensereport->dir_output.
'/'.$original_file;
2784 } elseif ($modulepart ==
'propalstats' && !empty($conf->propal->multidir_temp[$entity])) {
2786 if ($fuser->hasRight(
'propal', $lire)) {
2789 $original_file = $conf->propal->multidir_temp[$entity].
'/'.$original_file;
2790 } elseif ($modulepart ==
'orderstats' && !empty($conf->commande->dir_temp)) {
2792 if ($fuser->hasRight(
'commande', $lire)) {
2795 $original_file = $conf->commande->dir_temp.
'/'.$original_file;
2796 } elseif ($modulepart ==
'orderstatssupplier' && !empty($conf->fournisseur->dir_output)) {
2797 if ($fuser->hasRight(
'fournisseur',
'commande', $lire)) {
2800 $original_file = $conf->fournisseur->commande->dir_temp.
'/'.$original_file;
2801 } elseif ($modulepart ==
'billstats' && !empty($conf->facture->dir_temp)) {
2803 if ($fuser->hasRight(
'facture', $lire)) {
2806 $original_file = $conf->facture->dir_temp.
'/'.$original_file;
2807 } elseif ($modulepart ==
'billstatssupplier' && !empty($conf->fournisseur->dir_output)) {
2808 if ($fuser->hasRight(
'fournisseur',
'facture', $lire)) {
2811 $original_file = $conf->fournisseur->facture->dir_temp.
'/'.$original_file;
2812 } elseif ($modulepart ==
'expeditionstats' && !empty($conf->expedition->dir_temp)) {
2814 if ($fuser->hasRight(
'expedition', $lire)) {
2817 $original_file = $conf->expedition->dir_temp.
'/'.$original_file;
2818 } elseif ($modulepart ==
'tripsexpensesstats' && !empty($conf->deplacement->dir_temp)) {
2820 if ($fuser->hasRight(
'deplacement', $lire)) {
2823 $original_file = $conf->deplacement->dir_temp.
'/'.$original_file;
2824 } elseif ($modulepart ==
'memberstats' && !empty($conf->adherent->dir_temp)) {
2826 if ($fuser->hasRight(
'adherent', $lire)) {
2829 $original_file = $conf->adherent->dir_temp.
'/'.$original_file;
2830 } elseif (preg_match(
'/^productstats_/i', $modulepart) && !empty($conf->product->dir_temp)) {
2832 if ($fuser->hasRight(
'produit', $lire) || $fuser->hasRight(
'service', $lire)) {
2835 $original_file = (!empty($conf->product->multidir_temp[$entity]) ? $conf->product->multidir_temp[$entity] : $conf->service->multidir_temp[$entity]).
'/'.$original_file;
2836 } elseif (in_array($modulepart, array(
'tax',
'tax-vat',
'tva')) && !empty($conf->tax->dir_output)) {
2838 if ($fuser->hasRight(
'tax',
'charges', $lire)) {
2841 $modulepartsuffix = str_replace(
'tax-',
'', $modulepart);
2842 $original_file = $conf->tax->dir_output.
'/'.($modulepartsuffix !=
'tax' ? $modulepartsuffix.
'/' :
'').$original_file;
2843 } elseif ($modulepart ==
'actions' && !empty($conf->agenda->dir_output)) {
2845 if ($fuser->hasRight(
'agenda',
'myactions', $read)) {
2848 if ($refname && !preg_match(
'/^specimen/i', $original_file)) {
2849 include_once DOL_DOCUMENT_ROOT.
'/comm/action/class/actioncomm.class.php';
2851 $tmpobject->fetch((
int) $refname);
2852 $accessallowed =
checkUserAccessToObject($user, array(
'agenda'), $tmpobject->id,
'actioncomm&societe',
'myactions|allactions',
'fk_soc',
'id',
'');
2853 if ($user->socid && $tmpobject->socid) {
2858 $original_file = $conf->agenda->dir_output.
'/'.$original_file;
2859 } elseif ($modulepart ==
'category' && !empty($conf->categorie->multidir_output[$entity])) {
2861 if (empty($entity) || empty($conf->categorie->multidir_output[$entity])) {
2862 return array(
'accessallowed'=>0,
'error'=>
'Value entity must be provided');
2864 if ($fuser->hasRight(
"categorie", $lire) || $fuser->hasRight(
"takepos",
"run")) {
2867 $original_file = $conf->categorie->multidir_output[$entity].
'/'.$original_file;
2868 } elseif ($modulepart ==
'prelevement' && !empty($conf->prelevement->dir_output)) {
2870 if ($fuser->hasRight(
'prelevement',
'bons', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2873 $original_file = $conf->prelevement->dir_output.
'/'.$original_file;
2874 } elseif ($modulepart ==
'graph_stock' && !empty($conf->stock->dir_temp)) {
2877 $original_file = $conf->stock->dir_temp.
'/'.$original_file;
2878 } elseif ($modulepart ==
'graph_fourn' && !empty($conf->fournisseur->dir_temp)) {
2881 $original_file = $conf->fournisseur->dir_temp.
'/'.$original_file;
2882 } elseif ($modulepart ==
'graph_product' && !empty($conf->product->dir_temp)) {
2885 $original_file = $conf->product->multidir_temp[$entity].
'/'.$original_file;
2886 } elseif ($modulepart ==
'barcode') {
2891 $original_file =
'';
2892 } elseif ($modulepart ==
'iconmailing' && !empty($conf->mailing->dir_temp)) {
2895 $original_file = $conf->mailing->dir_temp.
'/'.$original_file;
2896 } elseif ($modulepart ==
'scanner_user_temp' && !empty($conf->scanner->dir_temp)) {
2899 $original_file = $conf->scanner->dir_temp.
'/'.$fuser->id.
'/'.$original_file;
2900 } elseif ($modulepart ==
'fckeditor' && !empty($conf->fckeditor->dir_output)) {
2903 $original_file = $conf->fckeditor->dir_output.
'/'.$original_file;
2904 } elseif ($modulepart ==
'user' && !empty($conf->user->dir_output)) {
2906 $canreaduser = (!empty($fuser->admin) || $fuser->rights->user->user->{$lire});
2907 if ($fuser->id == (
int) $refname) {
2910 if ($canreaduser || preg_match(
'/^specimen/i', $original_file)) {
2913 $original_file = $conf->user->dir_output.
'/'.$original_file;
2914 } elseif (($modulepart ==
'company' || $modulepart ==
'societe' || $modulepart ==
'thirdparty') && !empty($conf->societe->multidir_output[$entity])) {
2916 if (empty($entity) || empty($conf->societe->multidir_output[$entity])) {
2917 return array(
'accessallowed'=>0,
'error'=>
'Value entity must be provided');
2919 if ($fuser->hasRight(
'societe', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2922 $original_file = $conf->societe->multidir_output[$entity].
'/'.$original_file;
2923 $sqlprotectagainstexternals =
"SELECT rowid as fk_soc FROM ".MAIN_DB_PREFIX.
"societe WHERE rowid='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'societe').
")";
2924 } elseif ($modulepart ==
'contact' && !empty($conf->societe->multidir_output[$entity])) {
2926 if (empty($entity) || empty($conf->societe->multidir_output[$entity])) {
2927 return array(
'accessallowed'=>0,
'error'=>
'Value entity must be provided');
2929 if ($fuser->hasRight(
'societe', $lire)) {
2932 $original_file = $conf->societe->multidir_output[$entity].
'/contact/'.$original_file;
2933 } elseif (($modulepart ==
'facture' || $modulepart ==
'invoice') && !empty($conf->facture->multidir_output[$entity])) {
2935 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2938 $original_file = $conf->facture->multidir_output[$entity].
'/'.$original_file;
2939 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"facture WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'invoice').
")";
2940 } elseif ($modulepart ==
'massfilesarea_proposals' && !empty($conf->propal->multidir_output[$entity])) {
2942 if ($fuser->hasRight(
'propal', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2945 $original_file = $conf->propal->multidir_output[$entity].
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2946 } elseif ($modulepart ==
'massfilesarea_orders') {
2947 if ($fuser->hasRight(
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2950 $original_file = $conf->commande->multidir_output[$entity].
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2951 } elseif ($modulepart ==
'massfilesarea_sendings') {
2952 if ($fuser->hasRight(
'expedition', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2955 $original_file = $conf->expedition->dir_output.
'/sending/temp/massgeneration/'.$user->id.
'/'.$original_file;
2956 } elseif ($modulepart ==
'massfilesarea_invoices') {
2957 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2960 $original_file = $conf->facture->multidir_output[$entity].
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2961 } elseif ($modulepart ==
'massfilesarea_expensereport') {
2962 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2965 $original_file = $conf->expensereport->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2966 } elseif ($modulepart ==
'massfilesarea_interventions') {
2967 if ($fuser->hasRight(
'ficheinter', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2970 $original_file = $conf->ficheinter->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2971 } elseif ($modulepart ==
'massfilesarea_supplier_proposal' && !empty($conf->supplier_proposal->dir_output)) {
2972 if ($fuser->hasRight(
'supplier_proposal', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2975 $original_file = $conf->supplier_proposal->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2976 } elseif ($modulepart ==
'massfilesarea_supplier_order') {
2977 if ($fuser->hasRight(
'fournisseur',
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2980 $original_file = $conf->fournisseur->commande->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2981 } elseif ($modulepart ==
'massfilesarea_supplier_invoice') {
2982 if ($fuser->hasRight(
'fournisseur',
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2985 $original_file = $conf->fournisseur->facture->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2986 } elseif ($modulepart ==
'massfilesarea_contract' && !empty($conf->contrat->dir_output)) {
2987 if ($fuser->hasRight(
'contrat', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2990 $original_file = $conf->contrat->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
2991 } elseif (($modulepart ==
'fichinter' || $modulepart ==
'ficheinter') && !empty($conf->ficheinter->dir_output)) {
2993 if ($fuser->hasRight(
'ficheinter', $lire) || preg_match(
'/^specimen/i', $original_file)) {
2996 $original_file = $conf->ficheinter->dir_output.
'/'.$original_file;
2997 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"fichinter WHERE ref='".$db->escape($refname).
"' AND entity=".$conf->entity;
2998 } elseif ($modulepart ==
'deplacement' && !empty($conf->deplacement->dir_output)) {
3000 if ($fuser->hasRight(
'deplacement', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3003 $original_file = $conf->deplacement->dir_output.
'/'.$original_file;
3005 } elseif (($modulepart ==
'propal' || $modulepart ==
'propale') && isset($conf->propal->multidir_output[$entity])) {
3007 if ($fuser->hasRight(
'propal', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3010 $original_file = $conf->propal->multidir_output[$entity].
'/'.$original_file;
3011 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"propal WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'propal').
")";
3012 } elseif (($modulepart ==
'commande' || $modulepart ==
'order') && !empty($conf->commande->multidir_output[$entity])) {
3014 if ($fuser->hasRight(
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3017 $original_file = $conf->commande->multidir_output[$entity].
'/'.$original_file;
3018 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"commande WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'order').
")";
3019 } elseif ($modulepart ==
'project' && !empty($conf->project->multidir_output[$entity])) {
3021 if ($fuser->hasRight(
'projet', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3024 if ($refname && !preg_match(
'/^specimen/i', $original_file)) {
3025 include_once DOL_DOCUMENT_ROOT.
'/projet/class/project.class.php';
3026 $tmpproject =
new Project($db);
3027 $tmpproject->fetch(
'', $refname);
3028 $accessallowed =
checkUserAccessToObject($user, array(
'projet'), $tmpproject->id,
'projet&project',
'',
'',
'rowid',
'');
3031 $original_file = $conf->project->multidir_output[$entity].
'/'.$original_file;
3032 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"projet WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'project').
")";
3033 } elseif ($modulepart ==
'project_task' && !empty($conf->project->multidir_output[$entity])) {
3034 if ($fuser->hasRight(
'projet', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3037 if ($refname && !preg_match(
'/^specimen/i', $original_file)) {
3038 include_once DOL_DOCUMENT_ROOT.
'/projet/class/task.class.php';
3039 $tmptask =
new Task($db);
3040 $tmptask->fetch(
'', $refname);
3041 $accessallowed =
checkUserAccessToObject($user, array(
'projet_task'), $tmptask->id,
'projet_task&project',
'',
'',
'rowid',
'');
3044 $original_file = $conf->project->multidir_output[$entity].
'/'.$original_file;
3045 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"projet WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'project').
")";
3046 } elseif (($modulepart ==
'commande_fournisseur' || $modulepart ==
'order_supplier') && !empty($conf->fournisseur->commande->dir_output)) {
3048 if ($fuser->hasRight(
'fournisseur',
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3051 $original_file = $conf->fournisseur->commande->dir_output.
'/'.$original_file;
3052 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"commande_fournisseur WHERE ref='".$db->escape($refname).
"' AND entity=".$conf->entity;
3053 } elseif (($modulepart ==
'facture_fournisseur' || $modulepart ==
'invoice_supplier') && !empty($conf->fournisseur->facture->dir_output)) {
3055 if ($fuser->hasRight(
'fournisseur',
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3058 $original_file = $conf->fournisseur->facture->dir_output.
'/'.$original_file;
3059 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"facture_fourn WHERE ref='".$db->escape($refname).
"' AND entity=".$conf->entity;
3060 } elseif ($modulepart ==
'supplier_payment') {
3062 if ($fuser->hasRight(
'fournisseur',
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3065 $original_file = $conf->fournisseur->payment->dir_output.
'/'.$original_file;
3066 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"paiementfournisseur WHERE ref='".$db->escape($refname).
"' AND entity=".$conf->entity;
3067 } elseif ($modulepart ==
'facture_paiement' && !empty($conf->facture->dir_output)) {
3069 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3072 if ($fuser->socid > 0) {
3073 $original_file = $conf->facture->dir_output.
'/payments/private/'.$fuser->id.
'/'.$original_file;
3075 $original_file = $conf->facture->dir_output.
'/payments/'.$original_file;
3077 } elseif ($modulepart ==
'export_compta' && !empty($conf->accounting->dir_output)) {
3079 if ($fuser->hasRight(
'accounting',
'bind',
'write') || preg_match(
'/^specimen/i', $original_file)) {
3082 $original_file = $conf->accounting->dir_output.
'/'.$original_file;
3083 } elseif (($modulepart ==
'expedition' || $modulepart ==
'shipment') && !empty($conf->expedition->dir_output)) {
3085 if ($fuser->hasRight(
'expedition', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3088 $original_file = $conf->expedition->dir_output.
"/".(strpos($original_file,
'sending/') === 0 ?
'' :
'sending/').$original_file;
3090 } elseif (($modulepart ==
'livraison' || $modulepart ==
'delivery') && !empty($conf->expedition->dir_output)) {
3092 if ($fuser->hasRight(
'expedition',
'delivery', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3095 $original_file = $conf->expedition->dir_output.
"/".(strpos($original_file,
'receipt/') === 0 ?
'' :
'receipt/').$original_file;
3096 } elseif ($modulepart ==
'actions' && !empty($conf->agenda->dir_output)) {
3098 if ($fuser->hasRight(
'agenda',
'myactions', $read) || preg_match(
'/^specimen/i', $original_file)) {
3101 $original_file = $conf->agenda->dir_output.
'/'.$original_file;
3102 } elseif ($modulepart ==
'actionsreport' && !empty($conf->agenda->dir_temp)) {
3104 if ($fuser->hasRight(
'agenda',
'allactions', $read) || preg_match(
'/^specimen/i', $original_file)) {
3107 $original_file = $conf->agenda->dir_temp.
"/".$original_file;
3108 } elseif ($modulepart ==
'product' || $modulepart ==
'produit' || $modulepart ==
'service' || $modulepart ==
'produit|service') {
3110 if (empty($entity) || (empty($conf->product->multidir_output[$entity]) && empty($conf->service->multidir_output[$entity]))) {
3111 return array(
'accessallowed'=>0,
'error'=>
'Value entity must be provided');
3113 if (($fuser->hasRight(
'produit', $lire) || $fuser->hasRight(
'service', $lire)) || preg_match(
'/^specimen/i', $original_file)) {
3116 if (isModEnabled(
"product")) {
3117 $original_file = $conf->product->multidir_output[$entity].
'/'.$original_file;
3118 } elseif (isModEnabled(
"service")) {
3119 $original_file = $conf->service->multidir_output[$entity].
'/'.$original_file;
3121 } elseif ($modulepart ==
'product_batch' || $modulepart ==
'produitlot') {
3123 if (empty($entity) || (empty($conf->productbatch->multidir_output[$entity]))) {
3124 return array(
'accessallowed'=>0,
'error'=>
'Value entity must be provided');
3126 if (($fuser->hasRight(
'produit', $lire)) || preg_match(
'/^specimen/i', $original_file)) {
3129 if (isModEnabled(
'productbatch')) {
3130 $original_file = $conf->productbatch->multidir_output[$entity].
'/'.$original_file;
3132 } elseif ($modulepart ==
'movement' || $modulepart ==
'mouvement') {
3134 if (empty($entity) || empty($conf->stock->multidir_output[$entity])) {
3135 return array(
'accessallowed'=>0,
'error'=>
'Value entity must be provided');
3137 if (($fuser->hasRight(
'stock', $lire) || $fuser->hasRight(
'stock',
'movement', $lire) || $fuser->hasRight(
'stock',
'mouvement', $lire)) || preg_match(
'/^specimen/i', $original_file)) {
3140 if (isModEnabled(
'stock')) {
3141 $original_file = $conf->stock->multidir_output[$entity].
'/movement/'.$original_file;
3143 } elseif ($modulepart ==
'contract' && !empty($conf->contrat->multidir_output[$entity])) {
3145 if ($fuser->hasRight(
'contrat', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3148 $original_file = $conf->contrat->multidir_output[$entity].
'/'.$original_file;
3149 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"contrat WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'contract').
")";
3150 } elseif ($modulepart ==
'donation' && !empty($conf->don->dir_output)) {
3152 if ($fuser->hasRight(
'don', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3155 $original_file = $conf->don->dir_output.
'/'.$original_file;
3156 } elseif ($modulepart ==
'dolresource' && !empty($conf->resource->dir_output)) {
3158 if ($fuser->hasRight(
'resource', $read) || preg_match(
'/^specimen/i', $original_file)) {
3161 $original_file = $conf->resource->dir_output.
'/'.$original_file;
3162 } elseif (($modulepart ==
'remisecheque' || $modulepart ==
'chequereceipt') && !empty($conf->bank->dir_output)) {
3164 if ($fuser->hasRight(
'banque', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3168 $original_file = $conf->bank->dir_output.
'/checkdeposits/'.$original_file;
3169 } elseif (($modulepart ==
'banque' || $modulepart ==
'bank') && !empty($conf->bank->dir_output)) {
3171 if ($fuser->hasRight(
'banque', $lire)) {
3174 $original_file = $conf->bank->dir_output.
'/'.$original_file;
3175 } elseif ($modulepart ==
'export' && !empty($conf->export->dir_temp)) {
3178 $accessallowed = $user->rights->export->lire;
3179 $original_file = $conf->export->dir_temp.
'/'.$fuser->id.
'/'.$original_file;
3180 } elseif ($modulepart ==
'import' && !empty($conf->import->dir_temp)) {
3182 $accessallowed = $user->rights->import->run;
3183 $original_file = $conf->import->dir_temp.
'/'.$original_file;
3184 } elseif ($modulepart ==
'recruitment' && !empty($conf->recruitment->dir_output)) {
3186 $accessallowed = $user->hasRight(
'recruitment',
'recruitmentjobposition',
'read');
3187 $original_file = $conf->recruitment->dir_output.
'/'.$original_file;
3188 } elseif ($modulepart ==
'editor' && !empty($conf->fckeditor->dir_output)) {
3191 $original_file = $conf->fckeditor->dir_output.
'/'.$original_file;
3192 } elseif ($modulepart ==
'systemtools' && !empty($conf->admin->dir_output)) {
3194 if ($fuser->admin) {
3197 $original_file = $conf->admin->dir_output.
'/'.$original_file;
3198 } elseif ($modulepart ==
'admin_temp' && !empty($conf->admin->dir_temp)) {
3200 if ($fuser->admin) {
3203 $original_file = $conf->admin->dir_temp.
'/'.$original_file;
3204 } elseif ($modulepart ==
'bittorrent' && !empty($conf->bittorrent->dir_output)) {
3208 if (
dol_mimetype($original_file) ==
'application/x-bittorrent') {
3211 $original_file = $conf->bittorrent->dir_output.
'/'.$dir.
'/'.$original_file;
3212 } elseif ($modulepart ==
'member' && !empty($conf->adherent->dir_output)) {
3214 if ($fuser->hasRight(
'adherent', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3217 $original_file = $conf->adherent->dir_output.
'/'.$original_file;
3218 } elseif ($modulepart ==
'scanner_user_temp' && !empty($conf->scanner->dir_temp)) {
3221 $original_file = $conf->scanner->dir_temp.
'/'.$fuser->id.
'/'.$original_file;
3231 if (preg_match(
'/^specimen/i', $original_file)) {
3234 if ($fuser->admin) {
3238 $tmpmodulepart = explode(
'-', $modulepart);
3239 if (!empty($tmpmodulepart[1])) {
3240 $modulepart = $tmpmodulepart[0];
3241 $original_file = $tmpmodulepart[1].
'/'.$original_file;
3246 if (preg_match(
'/^([a-z]+)_user_temp$/i', $modulepart, $reg)) {
3247 $tmpmodule = $reg[1];
3248 if (empty($conf->$tmpmodule->dir_temp)) {
3249 dol_print_error(
'',
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3252 if ($fuser->hasRight($tmpmodule, $lire) || $fuser->hasRight($tmpmodule, $read) || $fuser->hasRight($tmpmodule, $download)) {
3255 $original_file = $conf->{$reg[1]}->dir_temp.
'/'.$fuser->id.
'/'.$original_file;
3256 } elseif (preg_match(
'/^([a-z]+)_temp$/i', $modulepart, $reg)) {
3257 $tmpmodule = $reg[1];
3258 if (empty($conf->$tmpmodule->dir_temp)) {
3259 dol_print_error(
'',
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3262 if ($fuser->hasRight($tmpmodule, $lire) || $fuser->hasRight($tmpmodule, $read) || $fuser->hasRight($tmpmodule, $download)) {
3265 $original_file = $conf->$tmpmodule->dir_temp.
'/'.$original_file;
3266 } elseif (preg_match(
'/^([a-z]+)_user$/i', $modulepart, $reg)) {
3267 $tmpmodule = $reg[1];
3268 if (empty($conf->$tmpmodule->dir_output)) {
3269 dol_print_error(
'',
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3272 if ($fuser->hasRight($tmpmodule, $lire) || $fuser->hasRight($tmpmodule, $read) || $fuser->hasRight($tmpmodule, $download)) {
3275 $original_file = $conf->$tmpmodule->dir_output.
'/'.$fuser->id.
'/'.$original_file;
3276 } elseif (preg_match(
'/^massfilesarea_([a-z]+)$/i', $modulepart, $reg)) {
3277 $tmpmodule = $reg[1];
3278 if (empty($conf->$tmpmodule->dir_output)) {
3279 dol_print_error(
'',
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3282 if ($fuser->hasRight($tmpmodule, $lire) || preg_match(
'/^specimen/i', $original_file)) {
3285 $original_file = $conf->$tmpmodule->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3287 if (empty($conf->$modulepart->dir_output)) {
3288 dol_print_error(
'',
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
'). The module for this modulepart value may not be activated.');
3293 $partsofdirinoriginalfile = explode(
'/', $original_file);
3294 if (!empty($partsofdirinoriginalfile[1])) {
3295 $partofdirinoriginalfile = $partsofdirinoriginalfile[0];
3296 if ($partofdirinoriginalfile && ($fuser->hasRight($modulepart, $partofdirinoriginalfile,
'lire') || $fuser->hasRight($modulepart, $partofdirinoriginalfile,
'read'))) {
3300 if ($fuser->hasRight($modulepart, $lire) || $fuser->hasRight($modulepart, $read)) {
3304 if (is_array($conf->$modulepart->multidir_output) && !empty($conf->$modulepart->multidir_output[$entity])) {
3305 $original_file = $conf->$modulepart->multidir_output[$entity].
'/'.$original_file;
3307 $original_file = $conf->$modulepart->dir_output.
'/'.$original_file;
3311 $parameters = array(
3312 'modulepart' => $modulepart,
3313 'original_file' => $original_file,
3314 'entity' => $entity,
3319 $reshook = $hookmanager->executeHooks(
'checkSecureAccess', $parameters, $object);
3321 if (!empty($hookmanager->resArray[
'original_file'])) {
3322 $original_file = $hookmanager->resArray[
'original_file'];
3324 if (!empty($hookmanager->resArray[
'accessallowed'])) {
3325 $accessallowed = $hookmanager->resArray[
'accessallowed'];
3327 if (!empty($hookmanager->resArray[
'sqlprotectagainstexternals'])) {
3328 $sqlprotectagainstexternals = $hookmanager->resArray[
'sqlprotectagainstexternals'];
3334 'accessallowed' => ($accessallowed ? 1 : 0),
3335 'sqlprotectagainstexternals' => $sqlprotectagainstexternals,
3336 'original_file' => $original_file