72 public function index($modulepart, $original_file =
'')
76 if (empty($modulepart)) {
77 throw new RestException(400,
'bad value for parameter modulepart');
79 if (empty($original_file)) {
80 throw new RestException(400,
'bad value for parameter original_file');
84 if ($modulepart ==
'task' || $modulepart ==
'project_task') {
85 $modulepart =
'project_task';
89 $entity =
$conf->entity;
100 $relativefile = $original_file;
103 $accessallowed = $check_access[
'accessallowed'];
104 $sqlprotectagainstexternals = $check_access[
'sqlprotectagainstexternals'];
105 $original_file = $check_access[
'original_file'];
107 if (preg_match(
'/\.\./', $original_file) || preg_match(
'/[<>|]/', $original_file)) {
108 throw new RestException(403);
110 if (!$accessallowed) {
111 throw new RestException(403);
114 if (DolibarrApiAccess::$user->socid > 0) {
115 if ($sqlprotectagainstexternals) {
116 $resql = $this->db->query($sqlprotectagainstexternals);
118 $num = $this->db->num_rows($resql);
121 $obj = $this->db->fetch_object($resql);
122 if (DolibarrApiAccess::$user->socid != $obj->fk_soc) {
123 throw new RestException(403,
'Not allowed to download documents with such a ref');
131 $filename = basename($original_file);
132 $original_file_osencoded =
dol_osencode($original_file);
134 if (!file_exists($original_file_osencoded)) {
135 dol_syslog(
"Try to download not found file ".$original_file_osencoded, LOG_WARNING);
136 throw new RestException(404,
'File not found');
139 $file_content = file_get_contents($original_file_osencoded);
140 return array(
'filename' => $filename,
'content-type' =>
dol_mimetype($filename),
'filesize' => filesize($original_file),
'content' => base64_encode($file_content),
'encoding' =>
'base64');
174 public function builddoc($modulepart, $original_file =
'', $doctemplate =
'', $langcode =
'')
176 global
$conf, $langs;
178 if (empty($modulepart)) {
179 throw new RestException(400,
'bad value for parameter modulepart');
181 if (empty($original_file)) {
182 throw new RestException(400,
'bad value for parameter original_file');
185 $outputlangs = $langs;
186 if ($langcode && $langs->defaultlang != $langcode) {
188 $outputlangs->setDefaultLang($langcode);
192 $entity =
$conf->entity;
203 $relativefile = $original_file;
206 $accessallowed = $check_access[
'accessallowed'];
207 $sqlprotectagainstexternals = $check_access[
'sqlprotectagainstexternals'];
208 $original_file = $check_access[
'original_file'];
210 if (preg_match(
'/\.\./', $original_file) || preg_match(
'/[<>|]/', $original_file)) {
211 throw new RestException(403);
213 if (!$accessallowed) {
214 throw new RestException(403);
217 if (DolibarrApiAccess::$user->socid > 0) {
218 if ($sqlprotectagainstexternals) {
219 $resql = $this->db->query($sqlprotectagainstexternals);
221 $num = $this->db->num_rows($resql);
224 $obj = $this->db->fetch_object($resql);
225 if (DolibarrApiAccess::$user->socid != $obj->fk_soc) {
226 throw new RestException(403,
'Not allowed to download documents with such a ref');
241 if ($modulepart ==
'facture' || $modulepart ==
'invoice') {
242 require_once DOL_DOCUMENT_ROOT.
'/compta/facture/class/facture.class.php';
243 $tmpobject =
new Facture($this->db);
244 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
246 throw new RestException(404,
'Invoice not found');
249 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
250 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
252 throw new RestException(500,
'Error generating document');
254 } elseif ($modulepart ==
'facture_fournisseur' || $modulepart ==
'invoice_supplier') {
255 require_once DOL_DOCUMENT_ROOT .
'/fourn/class/fournisseur.facture.class.php';
257 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
259 throw new RestException(404,
'Supplier invoice not found');
262 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
263 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
265 throw new RestException(500,
'Error generating document');
267 } elseif ($modulepart ==
'commande' || $modulepart ==
'order') {
268 require_once DOL_DOCUMENT_ROOT.
'/commande/class/commande.class.php';
269 $tmpobject =
new Commande($this->db);
270 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
272 throw new RestException(404,
'Order not found');
274 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
275 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
277 throw new RestException(500,
'Error generating document');
279 } elseif ($modulepart ==
'propal' || $modulepart ==
'proposal') {
280 require_once DOL_DOCUMENT_ROOT.
'/comm/propal/class/propal.class.php';
281 $tmpobject =
new Propal($this->db);
282 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
284 throw new RestException(404,
'Proposal not found');
286 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
287 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
289 throw new RestException(500,
'Error generating document');
291 } elseif ($modulepart ==
'contrat' || $modulepart ==
'contract') {
292 require_once DOL_DOCUMENT_ROOT .
'/contrat/class/contrat.class.php';
294 $tmpobject =
new Contrat($this->db);
295 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
298 throw new RestException(404,
'Contract not found');
301 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
302 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
305 throw new RestException(500,
'Error generating document');
307 } elseif ($modulepart ==
'expedition' || $modulepart ==
'shipment') {
308 require_once DOL_DOCUMENT_ROOT .
'/expedition/class/expedition.class.php';
311 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
314 throw new RestException(404,
'Shipment not found');
317 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
318 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
321 throw new RestException(500,
'Error generating document');
323 } elseif ($modulepart ==
'mrp') {
324 require_once DOL_DOCUMENT_ROOT .
'/mrp/class/mo.class.php';
326 $tmpobject =
new Mo($this->db);
327 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
330 throw new RestException(404,
'MO not found');
333 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
334 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
337 throw new RestException(500,
'Error generating document');
339 } elseif ($modulepart ==
'expensereport') {
340 require_once DOL_DOCUMENT_ROOT.
'/expensereport/class/expensereport.class.php';
343 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
346 throw new RestException(404,
'Expense report not found');
349 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
350 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
353 throw new RestException(500,
'Error generating document');
355 } elseif ($modulepart ==
'holiday') {
356 require_once DOL_DOCUMENT_ROOT.
'/holiday/class/holiday.class.php';
358 $tmpobject =
new Holiday($this->db);
359 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
362 throw new RestException(404,
'Holiday not found');
365 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
366 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
369 throw new RestException(500,
'Error generating document');
371 } elseif ($modulepart ==
'product') {
372 require_once DOL_DOCUMENT_ROOT .
'/product/class/product.class.php';
374 $tmpobject =
new Product($this->db);
375 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
378 throw new RestException(404,
'Product not found');
381 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
382 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
385 throw new RestException(500,
'Error generating document');
387 } elseif ($modulepart ==
'stock' || $modulepart ==
'entrepot') {
388 require_once DOL_DOCUMENT_ROOT .
'/product/stock/class/entrepot.class.php';
390 $tmpobject =
new Entrepot($this->db);
391 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
394 throw new RestException(404,
'Warehouse not found');
397 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
398 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
401 throw new RestException(500,
'Error generating document');
403 } elseif ($modulepart ==
'fichinter' || $modulepart ==
'intervention') {
404 require_once DOL_DOCUMENT_ROOT .
'/fichinter/class/fichinter.class.php';
407 $result = $tmpobject->fetch(0, preg_replace(
'/\.[^\.]+$/',
'', basename($original_file)));
410 throw new RestException(404,
'Intervention not found');
413 $templateused = $doctemplate ? $doctemplate : $tmpobject->model_pdf;
414 $result = $tmpobject->generateDocument($templateused, $outputlangs, $hidedetails, $hidedesc, $hideref);
417 throw new RestException(500,
'Error generating document');
420 throw new RestException(403,
'Generation not available for this modulepart');
423 $filename = basename($original_file);
424 $original_file_osencoded =
dol_osencode($original_file);
426 if (!file_exists($original_file_osencoded)) {
427 throw new RestException(404,
'File not found');
430 $file_content = file_get_contents($original_file_osencoded);
431 return array(
'filename' => $filename,
'content-type' =>
dol_mimetype($filename),
'filesize' => filesize($original_file),
'content' => base64_encode($file_content),
'langcode' => $outputlangs->defaultlang,
'template' => $templateused,
'encoding' =>
'base64');
463 public function getDocumentsListByElement($modulepart,
$id = 0, $ref =
'', $sortfield =
'', $sortorder =
'', $limit = 100, $page = 0, $content_type =
'', $pagination_data =
false)
465 if (empty($modulepart)) {
466 throw new RestException(400,
'bad value for parameter modulepart');
469 if (empty(
$id) && empty($ref)) {
470 throw new RestException(400,
'bad value for parameter id or ref');
475 if ($modulepart ==
'facture_fournisseur') {
476 $modulepart =
'supplier_invoice';
480 $object = fetchObjectByElement(
$id, $modulepart, $ref);
482 throw new RestException(404,
'Module for modulepart = '.$modulepart.
" is not enabled (or not yet supported by API");
496 throw new RestException(403,
'Access not allowed to this object (refused by checkUserAccessToObject)');
500 if ($modulepart ==
'societe' || $modulepart ==
'thirdparty') {
501 if (!DolibarrApiAccess::$user->hasRight(
'societe',
'lire')) {
502 throw new RestException(403);
504 } elseif ($modulepart ==
'user') {
506 if (!DolibarrApiAccess::$user->hasRight(
'user',
'user',
'lire') && DolibarrApiAccess::$user->
id !=
$id) {
507 throw new RestException(403);
509 } elseif ($modulepart ==
'adherent' || $modulepart ==
'member') {
510 if (!DolibarrApiAccess::$user->hasRight(
'adherent',
'lire')) {
511 throw new RestException(403);
513 } elseif ($modulepart ==
'propal' || $modulepart ==
'proposal') {
514 if (!DolibarrApiAccess::$user->hasRight(
'propal',
'lire')) {
515 throw new RestException(403);
517 } elseif ($modulepart ==
'supplier_proposal') {
518 if (!DolibarrApiAccess::$user->hasRight(
'supplier_proposal',
'read')) {
519 throw new RestException(403);
521 } elseif ($modulepart ==
'commande' || $modulepart ==
'order') {
522 if (!DolibarrApiAccess::$user->hasRight(
'commande',
'lire')) {
523 throw new RestException(403);
525 } elseif ($modulepart ==
'commande_fournisseur' || $modulepart ==
'supplier_order') {
526 $modulepart =
'supplier_order';
527 if (!DolibarrApiAccess::$user->hasRight(
'fournisseur',
'commande',
'lire') && !DolibarrApiAccess::$user->hasRight(
'supplier_order',
'lire')) {
528 throw new RestException(403);
530 } elseif ($modulepart ==
'shipment' || $modulepart ==
'expedition') {
531 if (!DolibarrApiAccess::$user->hasRight(
'expedition',
'lire')) {
532 throw new RestException(403);
534 } elseif ($modulepart ==
'facture' || $modulepart ==
'invoice') {
535 if (!DolibarrApiAccess::$user->hasRight(
'facture',
'lire')) {
536 throw new RestException(403);
538 } elseif ($modulepart ==
'facture_fournisseur' || $modulepart ==
'supplier_invoice') {
539 $modulepart =
'supplier_invoice';
540 if (!DolibarrApiAccess::$user->hasRight(
'fournisseur',
'facture',
'lire') && !DolibarrApiAccess::$user->hasRight(
'supplier_invoice',
'lire')) {
541 throw new RestException(403);
543 } elseif ($modulepart ==
'produit' || $modulepart ==
'product' || $modulepart ==
'service') {
544 if (!DolibarrApiAccess::$user->hasRight(
'produit',
'lire')) {
545 throw new RestException(403);
547 } elseif ($modulepart ==
'agenda' || $modulepart ==
'action' || $modulepart ==
'event' || $modulepart ==
'actioncomm') {
548 if (!DolibarrApiAccess::$user->hasRight(
'agenda',
'myactions',
'read') && !DolibarrApiAccess::$user->hasRight(
'agenda',
'allactions',
'read')) {
549 throw new RestException(403);
551 } elseif ($modulepart ==
'expensereport') {
552 if (!DolibarrApiAccess::$user->hasRight(
'expensereport',
'read')) {
553 throw new RestException(403);
555 } elseif ($modulepart ==
'holiday') {
556 if (!DolibarrApiAccess::$user->hasRight(
'holiday',
'read')) {
557 throw new RestException(403);
559 } elseif ($modulepart ==
'ticket') {
560 if (!DolibarrApiAccess::$user->hasRight(
'ticket',
'read')) {
561 throw new RestException(403);
563 } elseif ($modulepart ==
'knowledgemanagement') {
564 if (!DolibarrApiAccess::$user->hasRight(
'knowledgemanagement',
'knowledgerecord',
'read')) {
565 throw new RestException(403);
567 } elseif ($modulepart ==
'categorie' || $modulepart ==
'category') {
568 if (!DolibarrApiAccess::$user->hasRight(
'categorie',
'lire')) {
569 throw new RestException(403);
571 } elseif ($modulepart ==
'ecm') {
572 throw new RestException(500,
'Modulepart Ecm not implemented yet.');
576 } elseif ($modulepart ==
'contrat' || $modulepart ==
'contract') {
577 $modulepart =
'contrat';
578 if (!DolibarrApiAccess::$user->hasRight(
'contrat',
'lire')) {
579 throw new RestException(403);
581 } elseif ($modulepart ==
'intervention' || $modulepart ==
'ficheinter') {
582 $modulepart =
'ficheinter';
583 if (!DolibarrApiAccess::$user->hasRight(
'ficheinter',
'lire')) {
584 throw new RestException(403);
586 } elseif ($modulepart ==
'projet' || $modulepart ==
'project') {
587 $modulepart =
'project';
588 if (!DolibarrApiAccess::$user->hasRight(
'projet',
'lire')) {
589 throw new RestException(403);
591 } elseif ($modulepart ==
'task' || $modulepart ==
'project_task') {
592 $modulepart =
'project_task';
593 if (!DolibarrApiAccess::$user->hasRight(
'projet',
'lire')) {
594 throw new RestException(403);
596 } elseif ($modulepart ==
'mrp') {
598 if (!DolibarrApiAccess::$user->hasRight(
'mrp',
'read')) {
599 throw new RestException(403);
601 } elseif ($modulepart ==
'contact' || $modulepart ==
'socpeople') {
602 $modulepart =
'contact';
603 if (!DolibarrApiAccess::$user->hasRight(
'societe',
'contact',
'lire')) {
604 throw new RestException(403);
606 } elseif ($modulepart ==
'stock') {
607 if (!DolibarrApiAccess::$user->hasRight(
'stock',
'lire')) {
608 throw new RestException(403);
611 throw new RestException(500,
'Modulepart '.$modulepart.
' not implemented yet.');
618 $objectType = $modulepart;
620 $objectType =
$object->table_element;
623 $filearray =
dol_dir_list($upload_dir, $type, $recursive,
'',
'(\.meta|_preview.*\.png)$', $sortfield, (strtolower($sortorder) ==
'desc' ? SORT_DESC : SORT_ASC), 1);
625 $countarray = is_array($filearray) ? count($filearray) : 0;
627 if (empty($filearray)) {
628 throw new RestException(404,
'Search for modulepart '.$modulepart.
' with Id '.
$id.(!empty($ref) ?
' or Ref '.$ref :
'').
' does not return any document.');
630 $filearray = array_slice($filearray, $limit * $page, $limit);
631 if ((
$object->id) > 0 && !empty($modulepart)) {
632 require_once DOL_DOCUMENT_ROOT.
'/ecm/class/ecmfiles.class.php';
634 $result = $ecmfile->fetchAll(
'',
'', 0, 0, array(
't.src_object_type' => $objectType,
't.src_object_id' =>
$object->id));
636 throw new RestException(503,
'Error when retrieve ecm list : '.$this->db->lasterror());
637 } elseif (is_array($ecmfile->lines) && count($ecmfile->lines) > 0) {
638 foreach ($filearray as &$fileitem) {
639 foreach ($ecmfile->lines as $line) {
640 if ($fileitem[
'name'] == $line->filename) {
643 $fileitem[
'ref'] = $line->ref;
644 $fileitem[
'label'] = $line->label;
645 $fileitem[
'filepath'] = $line->filepath;
646 $fileitem[
'filename'] = $line->filename;
647 $fileitem[
'fullpath_orig'] = $line->fullpath_orig;
648 $fileitem[
'position'] = $line->position;
649 $fileitem[
'gen_or_uploaded'] = $line->gen_or_uploaded;
650 $fileitem[
'description'] = $line->desc;
651 $fileitem[
'keywords'] = $line->keywords;
652 $fileitem[
'cover'] = $line->cover;
653 $fileitem[
'share'] = $line->share;
654 $fileitem[
'date_c'] = $line->date_c;
655 $fileitem[
'agenda_id'] = $line->agenda_id;
656 $fileitem[
'fk_user_c'] = $line->fk_user_c;
657 $fileitem[
'fk_user_m'] = $line->fk_user_m;
658 $fileitem[
'note_private'] = $line->note_private;
659 $fileitem[
'note_public'] = $line->note_public;
662 if (isset($fileitem[
'relativename'])) {
663 $fileitem[
'content-type'] =
dol_mimetype((
string) $fileitem[
'relativename']);
668 $arraycontenttype = explode(
",", $content_type);
669 if (!empty($content_type)) {
670 $filearray = array_filter(
676 static function ($fileitem) use (&$arraycontenttype) {
677 return in_array(($fileitem[
'content-type'] ?:
'UNKNOWN'), $arraycontenttype);
686 foreach ($filearray as $tmpkey => $tmpval) {
687 unset($filearray[$tmpkey][
'path']);
688 unset($filearray[$tmpkey][
'fullname']);
692 if ($pagination_data) {
694 'data' => $filearray,
696 'total' => (int) $countarray,
698 'page_count' => (
int) ceil((
int) $countarray / $limit),
758 public function post($filename, $modulepart, $ref =
'', $subdir =
'', $filecontent =
'', $fileencoding =
'', $overwriteifexists = 0, $createdirifnotexists = 1, $position = 0, $cover =
'', $array_options = [], $generateThumbs = 0, $share = 0)
762 $modulepartorig = $modulepart;
764 if (empty($modulepart)) {
765 throw new RestException(400,
'Modulepart not provided.');
768 $newfilecontent =
'';
769 if (empty($fileencoding)) {
770 $newfilecontent = $filecontent;
772 if ($fileencoding ==
'base64') {
773 $newfilecontent = base64_decode($filecontent);
777 $relativefile =
'UNSET';
781 $entity = DolibarrApiAccess::$user->entity;
782 if (empty($entity)) {
790 if ($modulepart ==
'facture' || $modulepart ==
'invoice') {
791 $modulepart =
'facture';
793 require_once DOL_DOCUMENT_ROOT.
'/compta/facture/class/facture.class.php';
795 } elseif ($modulepart ==
'facture_fournisseur' || $modulepart ==
'supplier_invoice') {
796 $modulepart =
'supplier_invoice';
798 require_once DOL_DOCUMENT_ROOT.
'/fourn/class/fournisseur.facture.class.php';
800 } elseif ($modulepart ==
'commande' || $modulepart ==
'order') {
801 $modulepart =
'commande';
803 require_once DOL_DOCUMENT_ROOT.
'/commande/class/commande.class.php';
805 } elseif ($modulepart ==
'commande_fournisseur' || $modulepart ==
'supplier_order') {
806 $modulepart =
'supplier_order';
808 require_once DOL_DOCUMENT_ROOT.
'/fourn/class/fournisseur.commande.class.php';
810 } elseif ($modulepart ==
'projet' || $modulepart ==
'project') {
811 require_once DOL_DOCUMENT_ROOT.
'/projet/class/project.class.php';
813 } elseif ($modulepart ==
'task' || $modulepart ==
'project_task') {
814 $modulepart =
'project_task';
816 require_once DOL_DOCUMENT_ROOT.
'/projet/class/task.class.php';
819 $task_result =
$object->fetch(0, $ref);
822 if ($task_result > 0) {
823 $project_result =
$object->fetchProject();
825 if ($project_result >= 0) {
829 throw new RestException(500,
'Error while fetching Task '.$ref);
831 } elseif ($modulepart ==
'product' || $modulepart ==
'produit' || $modulepart ==
'service' || $modulepart ==
'produit|service') {
832 require_once DOL_DOCUMENT_ROOT.
'/product/class/product.class.php';
834 } elseif ($modulepart ==
'expensereport') {
835 require_once DOL_DOCUMENT_ROOT.
'/expensereport/class/expensereport.class.php';
837 } elseif ($modulepart ==
'holiday') {
838 require_once DOL_DOCUMENT_ROOT.
'/holiday/class/holiday.class.php';
840 } elseif ($modulepart ==
'ficheinter' || $modulepart ==
'intervention') {
841 require_once DOL_DOCUMENT_ROOT.
'/fichinter/class/fichinter.class.php';
843 } elseif ($modulepart ==
'shipment' || $modulepart ==
'expedition') {
844 require_once DOL_DOCUMENT_ROOT.
'/expedition/class/expedition.class.php';
846 } elseif ($modulepart ==
'adherent' || $modulepart ==
'member') {
847 $modulepart =
'adherent';
848 require_once DOL_DOCUMENT_ROOT.
'/adherents/class/adherent.class.php';
850 } elseif ($modulepart ==
'proposal' || $modulepart ==
'propal' || $modulepart ==
'propale') {
851 $modulepart =
'propale';
852 require_once DOL_DOCUMENT_ROOT.
'/comm/propal/class/propal.class.php';
854 } elseif ($modulepart ==
'agenda' || $modulepart ==
'action' || $modulepart ==
'event') {
855 $modulepart =
'agenda';
856 require_once DOL_DOCUMENT_ROOT .
'/comm/action/class/actioncomm.class.php';
858 } elseif ($modulepart ==
'contact' || $modulepart ==
'socpeople') {
859 $modulepart =
'contact';
860 require_once DOL_DOCUMENT_ROOT.
'/contact/class/contact.class.php';
863 } elseif ($modulepart ==
'societe' || $modulepart ==
'company') {
864 $modulepart =
'societe';
865 require_once DOL_DOCUMENT_ROOT.
'/societe/class/societe.class.php';
868 } elseif ($modulepart ==
'knowledgemanagement') {
869 $modulepart =
'knowledgemanagement';
870 require_once DOL_DOCUMENT_ROOT.
'/knowledgemanagement/class/knowledgerecord.class.php';
873 } elseif ($modulepart ==
'ticket') {
874 $modulepart =
'ticket';
875 require_once DOL_DOCUMENT_ROOT.
'/ticket/class/ticket.class.php';
878 } elseif ($modulepart ==
'contrat' || $modulepart ==
'contract') {
879 $modulepart =
'contrat';
880 require_once DOL_DOCUMENT_ROOT .
'/contrat/class/contrat.class.php';
882 } elseif ($modulepart ==
'mrp') {
884 require_once DOL_DOCUMENT_ROOT .
'/mrp/class/mo.class.php';
886 } elseif ($modulepart ==
'stock') {
887 $modulepart =
'stock';
888 require_once DOL_DOCUMENT_ROOT .
'/product/stock/class/entrepot.class.php';
890 } elseif ($modulepart ==
'ecm') {
891 throw new RestException(500,
'Using a non empty "ref" is not compatible with using modulepart = '.$modulepart);
894 throw new RestException(500,
'Modulepart '.$modulepart.
' not implemented yet.');
900 $result =
$object->fetch((
int) $ref);
902 $result =
$object->fetch(0, $ref);
906 throw new RestException(404,
"Object with ref '".$ref.
"' was not found.");
907 } elseif ($result < 0) {
908 throw new RestException(500,
'Error while fetching object: '.
$object->errorsToString());
912 throw new RestException(404,
'The object '.$modulepart.
" with ref '".$ref.
"' was not found.");
917 if ($modulepart ==
'supplier_invoice') {
923 if ($modulepart ==
'societe') {
924 $relativefile = $tmpreldir.dol_sanitizeFileName((
string)
$object->id);
926 $relativefile = $tmpreldir.dol_sanitizeFileName((
string)
$object->ref);
929 if (empty($tmp[
'accessallowed'])) {
930 throw new RestException(403,
'Access not allowed to upload file into this directory');
932 $upload_dir = $tmp[
'original_file'];
940 if (empty($upload_dir) || $upload_dir ==
'/') {
941 throw new RestException(500,
'This value of modulepart ('.$modulepart.
') does not support yet usage of ref. Check modulepart parameter or try to use subdir parameter instead of ref.');
944 if ($modulepart ==
'invoice') {
945 $modulepart =
'facture';
947 if ($modulepart ==
'member') {
948 $modulepart =
'adherent';
952 if ($modulepart !=
'ecm') {
953 $relativefile = $subdir;
955 if (empty($tmp[
'accessallowed'])) {
956 throw new RestException(403,
'Access not allowed to upload file into this directory');
958 $upload_dir = $tmp[
'original_file'];
960 if (!DolibarrApiAccess::$user->hasRight(
'ecm',
'upload')) {
961 throw new RestException(403,
'Missing permission to upload files in ECM module');
963 $upload_dir =
$conf->medias->multidir_output[
$conf->entity];
966 if (empty($upload_dir) || $upload_dir ==
'/') {
967 if (!empty($tmp[
'error'])) {
968 throw new RestException(403,
'Error returned by dol_check_secure_access_document: '.$tmp[
'error']);
970 throw new RestException(400,
'This value of modulepart ('.$modulepart.
') is not allowed with this value of subdir ('.$relativefile.
')');
978 if (!empty($createdirifnotexists)) {
980 throw new RestException(500,
'Error while trying to create directory '.$upload_dir);
984 $destfile = $upload_dir.
'/'.$original_file;
985 $destfiletmp = DOL_DATA_ROOT.
'/admin/temp/'.$original_file;
990 throw new RestException(400,
'Directory does not exists : '.dirname($destfile));
993 if (!$overwriteifexists &&
dol_is_file($destfile)) {
994 throw new RestException(400,
"File with name '".$original_file.
"' already exists.");
1002 $fhandle = @fopen($destfiletmp,
'w');
1004 $nbofbyteswrote = fwrite($fhandle, $newfilecontent);
1008 throw new RestException(500,
"Failed to open file '".$destfiletmp.
"' for write");
1011 $disablevirusscan = 0;
1012 $src_file = $destfiletmp;
1013 $dest_file = $destfile;
1017 if (empty($disablevirusscan) && file_exists($src_file)) {
1019 if (count($checkvirusarray)) {
1020 dol_syslog(
'Files.lib::dol_move_uploaded_file File "'.$src_file.
'" (target name "'.$dest_file.
'") KO with antivirus: errors='.implode(
',', $checkvirusarray), LOG_WARNING);
1021 throw new RestException(500,
'ErrorFileIsInfectedWithAVirus: '.implode(
',', $checkvirusarray));
1030 $publicmediasdirwithslash =
$conf->medias->multidir_output[
$conf->entity];
1031 if (!preg_match(
'/\/$/', $publicmediasdirwithslash)) {
1032 $publicmediasdirwithslash .=
'/';
1035 if (strpos($upload_dir, $publicmediasdirwithslash) !== 0 || !
getDolGlobalInt(
"MAIN_DOCUMENT_DISABLE_NOEXE_IN_MEDIAS_DIR")) {
1036 $dest_file .=
'.noexe';
1042 if (preg_match(
'/^\./', basename($src_file)) || preg_match(
'/\.\./', $src_file) || preg_match(
'/[<>|]/', $src_file)) {
1043 dol_syslog(
"Refused to deliver file ".$src_file, LOG_WARNING);
1044 throw new RestException(500,
"Refused to deliver file ".$src_file);
1049 if (preg_match(
'/^\./', basename($dest_file)) || preg_match(
'/\.\./', $dest_file) || preg_match(
'/[<>|]/', $dest_file)) {
1050 dol_syslog(
"Refused to deliver file ".$dest_file, LOG_WARNING);
1051 throw new RestException(500,
"Refused to deliver file ".$dest_file);
1054 $moreinfo = array(
'note_private' =>
'File uploaded using API /documents from IP '.
getUserRemoteIP());
1057 $moreinfo[
'src_object_type'] =
$object->table_element;
1058 $moreinfo[
'src_object_id'] =
$object->id;
1060 if (!empty($array_options)) {
1061 $moreinfo = array_merge($moreinfo, [
"array_options" => $array_options]);
1063 if (!empty($position)) {
1064 $moreinfo = array_merge($moreinfo, [
"position" => $position]);
1066 if (!empty($cover)) {
1067 $moreinfo = array_merge($moreinfo, [
"cover" => $cover]);
1069 if (!empty($share)) {
1070 require_once DOL_DOCUMENT_ROOT.
'/core/lib/security2.lib.php';
1073 $moreinfo[
'gen_or_uploaded'] =
'api';
1076 $result =
dol_move($destfiletmp, $dest_file,
'0', $overwriteifexists, 1, 1, $moreinfo);
1078 throw new RestException(500,
"Failed to move file into '".$dest_file.
"'");
1081 if (is_object(
$object) && $generateThumbs) {
1082 require_once DOL_DOCUMENT_ROOT.
'/core/lib/files.lib.php';
1083 require_once DOL_DOCUMENT_ROOT.
'/core/lib/images.lib.php';
1085 $object->addThumbs($dest_file);
1111 public function delete($modulepart, $original_file)
1115 if (empty($modulepart)) {
1116 throw new RestException(400,
'bad value for parameter modulepart');
1118 if (empty($original_file)) {
1119 throw new RestException(400,
'bad value for parameter original_file');
1123 if ($modulepart ==
'task') {
1124 $modulepart =
'project_task';
1128 $entity =
$conf->entity;
1139 $relativefile = $original_file;
1142 $accessallowed = $check_access[
'accessallowed'];
1143 $sqlprotectagainstexternals = $check_access[
'sqlprotectagainstexternals'];
1144 $original_file = $check_access[
'original_file'];
1146 if (preg_match(
'/\.\./', $original_file) || preg_match(
'/[<>|]/', $original_file)) {
1147 throw new RestException(403);
1149 if (!$accessallowed) {
1150 throw new RestException(403);
1153 if (DolibarrApiAccess::$user->socid > 0) {
1154 if ($sqlprotectagainstexternals) {
1155 $resql = $this->db->query($sqlprotectagainstexternals);
1157 $num = $this->db->num_rows($resql);
1160 $obj = $this->db->fetch_object($resql);
1161 if (DolibarrApiAccess::$user->socid != $obj->fk_soc) {
1162 throw new RestException(403,
'Not allowed to download documents with such a ref');
1170 $filename = basename($original_file);
1171 $original_file_osencoded =
dol_osencode($original_file);
1173 if (!file_exists($original_file_osencoded)) {
1174 dol_syslog(
"Try to download not found file ".$original_file_osencoded, LOG_WARNING);
1175 throw new RestException(404,
'File not found');
1178 if (@unlink($original_file_osencoded)) {
1182 'message' =>
'Document deleted'
1187 throw new RestException(403);