65function dol_dir_list($utf8_path, $types =
"all", $recursive = 0, $filter =
"", $excludefilter =
null, $sortcriteria =
"name", $sortorder = SORT_ASC, $mode = 0, $nohook = 0, $relativename =
"", $donotfollowsymlinks = 0, $nbsecondsold = 0)
70 if ($recursive <= 1) {
75 if (!empty($filter) && !is_array($filter)) {
76 if (strlen($filter) > 25000) {
77 dol_syslog(
"Value for filter is too large", LOG_ERR);
81 if ((
int) preg_match(
'/(?:^|[^\\\\])\//', $filter) > 0) {
82 $excludefilter_ok =
false;
83 $error_info .=
" error='filter_has_unescaped_slash'";
84 dol_syslog(
"'$filter' has unescaped '/'", LOG_ERR);
90 $excludefilter_ok =
true;
91 $exclude_array = ($excludefilter ===
null || $excludefilter ===
'') ? array() : (is_array($excludefilter) ? $excludefilter : array($excludefilter));
92 foreach ($exclude_array as $f) {
94 if ((
int) preg_match(
'/(?:^|[^\\\\])\//', $f) > 0) {
95 $excludefilter_ok =
false;
96 $error_info .=
" error='excludefilter_has_unescaped_slash'";
101 dol_syslog(
"files.lib.php::dol_dir_list path=".$utf8_path.
" types=".$types.
" recursive=".$recursive.
" filter=".json_encode($filter).
" excludefilter=".json_encode($excludefilter).$error_info);
103 if (!$filter_ok || !$excludefilter_ok) {
109 $exclude_array = ($excludefilter ===
null || $excludefilter ===
'') ? array() : (is_array($excludefilter) ? $excludefilter : array($excludefilter));
113 $excludefilterarray = array_merge(array(
'^\.'), $exclude_array);
115 $loaddate = ($mode == 1 || $mode == 2 || $nbsecondsold != 0 || $sortcriteria ==
'date');
116 $loadsize = ($mode == 1 || $mode == 3 || $sortcriteria ==
'size');
117 $loadperm = ($mode == 1 || $mode == 4 || $sortcriteria ==
'perm');
121 $file_list = array();
124 $utf8_path = preg_replace(
'/([\\/]+)$/',
'', $utf8_path);
126 if (preg_match(
'/\*/', $utf8_path)) {
127 $utf8_path_array = glob($utf8_path, GLOB_ONLYDIR);
130 $utf8_path_array = array($utf8_path);
133 foreach ($utf8_path_array as $utf8_path_cursor) {
135 if (!$nohook && $hookmanager instanceof
HookManager) {
136 $hookmanager->resArray = array();
138 $hookmanager->initHooks(array(
'fileslib'));
143 'recursive' => $recursive,
145 'excludefilter' => $exclude_array,
146 'sortcriteria' => $sortcriteria,
147 'sortorder' => $sortorder,
148 'loaddate' => $loaddate,
149 'loadsize' => $loadsize,
152 $reshook = $hookmanager->executeHooks(
'getDirList', $parameters,
$object);
156 if (empty($reshook)) {
157 if (!is_dir($os_path)) {
161 if (($dir = opendir($os_path)) ===
false) {
169 while (
false !== ($os_file = readdir($dir))) {
170 $os_fullpathfile = ($os_path ? $os_path.
'/' :
'').$os_file;
173 $utf8_file = mb_convert_encoding($os_file,
'UTF-8',
'ISO-8859-1');
175 $utf8_file = $os_file;
178 $utf8_fullpathfile = $utf8_path_cursor.
"/".$utf8_file;
182 foreach ($excludefilterarray as $filt) {
183 if (preg_match(
'/'.$filt.
'/i', $utf8_file) || preg_match(
'/'.$filt.
'/i', $utf8_fullpathfile)) {
191 $isdir = is_dir($os_fullpathfile);
195 if (($types ==
"directories") || ($types ==
"all")) {
196 if ($loaddate || $sortcriteria ==
'date') {
199 if ($loadsize || $sortcriteria ==
'size') {
202 if ($loadperm || $sortcriteria ==
'perm') {
206 $qualifiedforfilter = 0;
207 if (empty($filter)) {
208 $qualifiedforfilter = 1;
210 $testpregmatch =
false;
211 if (is_array($filter)) {
212 $chunks = array_chunk($filter, 500);
213 foreach ($chunks as $chunk) {
214 $testpregmatch = preg_match(
'/'.implode(
'|', $chunk).
'/i', $utf8_file);
215 if ($testpregmatch) {
220 $testpregmatch = preg_match(
'/'.$filter.
'/i', $utf8_file);
222 if ($testpregmatch) {
223 $qualifiedforfilter = 1;
227 if ($qualifiedforfilter) {
229 preg_match(
'/([^\/]+)\/[^\/]+$/', $utf8_fullpathfile, $reg);
230 $level1name = (isset($reg[1]) ? $reg[1] :
'');
231 $file_list[] = array(
232 "name" => $utf8_file,
233 "path" => $utf8_path,
234 "level1name" => $level1name,
235 "relativename" => ($relativename ? $relativename.
'/' :
'').$utf8_file,
236 "fullname" => $utf8_fullpathfile,
246 if ($recursive > 0) {
247 if (empty($donotfollowsymlinks) || !is_link($os_fullpathfile)) {
249 $file_list = array_merge($file_list,
dol_dir_list($utf8_fullpathfile, $types, $recursive + 1, $filter, $exclude_array, $sortcriteria, $sortorder, $mode, $nohook, ($relativename !=
'' ? $relativename.
'/' :
'').$utf8_file, $donotfollowsymlinks, $nbsecondsold));
252 } elseif (in_array($types, array(
"files",
"all"))) {
254 if ($loaddate || $sortcriteria ==
'date') {
257 if ($loadsize || $sortcriteria ==
'size') {
261 $qualifiedforfilter = 0;
262 if (empty($filter)) {
263 $qualifiedforfilter = 1;
265 $testpregmatch =
false;
266 if (is_array($filter)) {
267 $chunks = array_chunk($filter, 500);
268 foreach ($chunks as $chunk) {
269 $testpregmatch = preg_match(
'/'.implode(
'|', $chunk).
'/i', $utf8_file);
270 if ($testpregmatch) {
275 $testpregmatch = preg_match(
'/'.$filter.
'/i', $utf8_file);
277 if ($testpregmatch) {
278 $qualifiedforfilter = 1;
282 if ($qualifiedforfilter) {
283 if (empty($nbsecondsold) || $filedate <= ($now - $nbsecondsold)) {
284 preg_match(
'/([^\/]+)\/[^\/]+$/', $utf8_fullpathfile, $reg);
285 $level1name = (isset($reg[1]) ? $reg[1] :
'');
286 $file_list[] = array(
287 "name" => $utf8_file,
288 "path" => $utf8_path,
289 "level1name" => $level1name,
290 "relativename" => ($relativename ? $relativename.
'/' :
'').$utf8_file,
291 "fullname" => $utf8_fullpathfile,
306 if (!empty($sortcriteria) && $sortorder) {
307 $file_list =
dol_sort_array($file_list, $sortcriteria, ($sortorder == SORT_ASC ?
'asc' :
'desc'));
310 if ($hookmanager instanceof
HookManager && is_array($hookmanager->resArray)) {
311 $file_list = array_merge($file_list, $hookmanager->resArray);
1161function dol_move($srcfile, $destfile, $newmask =
'0', $overwriteifexists = 1, $testvirus = 0, $indexdatabase = 1, $moreinfo = array(), $entity =
null)
1166 dol_syslog(
"files.lib.php::dol_move srcfile=".$srcfile.
" destfile=".$destfile.
" newmask=".$newmask.
" overwritifexists=".$overwriteifexists);
1171 dol_syslog(
"files.lib.php::dol_move srcfile does not exists. we ignore the move request.");
1175 if ($overwriteifexists || !$destexists) {
1180 $testvirusarray = array();
1183 $testvirusarray =
dolCheckVirus($newpathofsrcfile, $newpathofdestfile);
1184 if (count($testvirusarray)) {
1185 dol_syslog(
"files.lib.php::dol_move canceled because a virus was found into source file. We ignore the move request.", LOG_WARNING);
1191 if (count($testvirusarray)) {
1192 dol_syslog(
"files.lib.php::dol_move canceled because a virus was found into source file. We ignore the move request.", LOG_WARNING);
1197 global $dolibarr_main_restrict_os_commands;
1198 if (!empty($dolibarr_main_restrict_os_commands)) {
1199 $arrayofallowedcommand = explode(
',', $dolibarr_main_restrict_os_commands);
1200 $arrayofallowedcommand = array_map(
'trim', $arrayofallowedcommand);
1201 if (in_array(basename($destfile), $arrayofallowedcommand)) {
1204 dol_syslog(
"files.lib.php::dol_move canceled because target filename ".basename($destfile).
" is using a reserved command name. we ignore the move request.", LOG_WARNING);
1209 $result = @rename($newpathofsrcfile, $newpathofdestfile);
1212 dol_syslog(
"files.lib.php::dol_move Failed. We try to delete target first and move after.", LOG_WARNING);
1215 $result = @rename($newpathofsrcfile, $newpathofdestfile);
1217 dol_syslog(
"files.lib.php::dol_move Failed.", LOG_WARNING);
1222 if ($result && $indexdatabase) {
1224 $rel_filetorenamebefore = preg_replace(
'/^'.preg_quote(DOL_DATA_ROOT,
'/').
'/',
'', $srcfile);
1225 $rel_filetorenameafter = preg_replace(
'/^'.preg_quote(DOL_DATA_ROOT,
'/').
'/',
'', $destfile);
1226 if (!preg_match(
'/([\\/]temp[\\/]|[\\/]thumbs|\.meta$)/', $rel_filetorenameafter)) {
1227 $rel_filetorenamebefore = preg_replace(
'/^[\\/]/',
'', $rel_filetorenamebefore);
1228 $rel_filetorenameafter = preg_replace(
'/^[\\/]/',
'', $rel_filetorenameafter);
1231 dol_syslog(
"Try to rename also entries in database for full relative path before = ".$rel_filetorenamebefore.
" after = ".$rel_filetorenameafter, LOG_DEBUG);
1232 include_once DOL_DOCUMENT_ROOT.
'/ecm/class/ecmfiles.class.php';
1234 $ecmfiletarget =
new EcmFiles($db);
1235 $resultecmtarget = $ecmfiletarget->fetch(0,
'', $rel_filetorenameafter,
'',
'',
'', 0, $entity);
1236 if ($resultecmtarget > 0) {
1237 $ecmfiletarget->delete($user);
1241 $resultecm = $ecmfile->fetch(0,
'', $rel_filetorenamebefore,
'',
'',
'', 0, $entity);
1242 if ($resultecm > 0) {
1243 $filename = basename($rel_filetorenameafter);
1244 $rel_dir = dirname($rel_filetorenameafter);
1245 $rel_dir = preg_replace(
'/[\\/]$/',
'', $rel_dir);
1246 $rel_dir = preg_replace(
'/^[\\/]/',
'', $rel_dir);
1248 $ecmfile->filepath = $rel_dir;
1249 $ecmfile->filename = $filename;
1251 $resultecm = $ecmfile->update($user);
1252 } elseif ($resultecm == 0) {
1253 $filename = basename($rel_filetorenameafter);
1254 $rel_dir = dirname($rel_filetorenameafter);
1255 $rel_dir = preg_replace(
'/[\\/]$/',
'', $rel_dir);
1256 $rel_dir = preg_replace(
'/^[\\/]/',
'', $rel_dir);
1258 $ecmfile->filepath = $rel_dir;
1259 $ecmfile->filename = $filename;
1261 $ecmfile->fullpath_orig = basename($srcfile);
1262 if (!empty($moreinfo) && !empty($moreinfo[
'gen_or_uploaded'])) {
1263 $ecmfile->gen_or_uploaded = $moreinfo[
'gen_or_uploaded'];
1265 $ecmfile->gen_or_uploaded =
'unknown';
1267 if (!empty($moreinfo) && !empty($moreinfo[
'description'])) {
1268 $ecmfile->description = $moreinfo[
'description'];
1270 $ecmfile->description =
'';
1272 if (!empty($moreinfo) && !empty($moreinfo[
'keywords'])) {
1273 $ecmfile->keywords = $moreinfo[
'keywords'];
1275 $ecmfile->keywords =
'';
1277 if (!empty($moreinfo) && !empty($moreinfo[
'note_private'])) {
1278 $ecmfile->note_private = $moreinfo[
'note_private'];
1280 if (!empty($moreinfo) && !empty($moreinfo[
'note_public'])) {
1281 $ecmfile->note_public = $moreinfo[
'note_public'];
1283 if (!empty($moreinfo) && !empty($moreinfo[
'src_object_type'])) {
1284 $ecmfile->src_object_type = $moreinfo[
'src_object_type'];
1286 if (!empty($moreinfo) && !empty($moreinfo[
'src_object_id'])) {
1287 $ecmfile->src_object_id = $moreinfo[
'src_object_id'];
1289 if (!empty($moreinfo) && !empty($moreinfo[
'agenda_id'])) {
1290 $ecmfile->agenda_id = $moreinfo[
'agenda_id'];
1292 if (!empty($moreinfo) && !empty($moreinfo[
'position'])) {
1293 $ecmfile->position = $moreinfo[
'position'];
1295 if (!empty($moreinfo) && !empty($moreinfo[
'cover'])) {
1296 $ecmfile->cover = $moreinfo[
'cover'];
1298 if (!empty($moreinfo) && !empty($moreinfo[
'share'])) {
1299 $ecmfile->share = $moreinfo[
'share'];
1301 if (! empty($entity)) {
1302 $ecmfile->entity = $entity;
1305 $resultecm = $ecmfile->create($user);
1306 if ($resultecm < 0) {
1307 setEventMessages($ecmfile->error, $ecmfile->errors,
'warnings');
1309 if (!empty($moreinfo) && !empty($moreinfo[
'array_options']) && is_array($moreinfo[
'array_options'])) {
1310 $ecmfile->array_options = $moreinfo[
'array_options'];
1311 $resultecm = $ecmfile->insertExtraFields();
1312 if ($resultecm < 0) {
1313 setEventMessages($ecmfile->error, $ecmfile->errors,
'warnings');
1317 } elseif ($resultecm < 0) {
1318 setEventMessages($ecmfile->error, $ecmfile->errors,
'warnings');
1321 if ($resultecm > 0) {
1329 if (empty($newmask)) {
1336 dolChmod($newpathofdestfile, $newmask);
2112function dol_add_file_process($upload_dir, $allowoverwrite = 0, $updatesessionordb = 0, $keyforsourcefile =
'addedfile', $savingdocmask =
'', $link =
null, $trackid =
'', $generatethumbs = 1,
$object =
null, $forceFullTextIndexation =
'', $mode = 0)
2114 global $db, $user,
$conf, $langs;
2120 $_FILES = array($keyforsourcefile => array());
2121 $_FILES[$keyforsourcefile][
'tmp_name'] = $keyforsourcefile;
2122 $_FILES[$keyforsourcefile][
'name'] = $keyforsourcefile;
2126 if (!empty($_FILES[$keyforsourcefile])) {
2127 dol_syslog(
'dol_add_file_process varfiles = '.$keyforsourcefile.
' upload_dir='.$upload_dir.
' allowoverwrite='.$allowoverwrite.
' updatesessionordb='.$updatesessionordb.
' savingdocmask='.$savingdocmask, LOG_DEBUG);
2128 $maxfilesinform =
getDolGlobalInt(
"MAIN_SECURITY_MAX_ATTACHMENT_ON_FORMS", 10);
2129 if (is_array($_FILES[$keyforsourcefile][
"name"]) && count($_FILES[$keyforsourcefile][
"name"]) > $maxfilesinform) {
2130 $langs->load(
"errors");
2131 setEventMessages($langs->trans(
"ErrorTooMuchFileInForm", $maxfilesinform),
null,
"errors");
2139 $TFile = $_FILES[$keyforsourcefile];
2141 if (!is_array($TFile[
'name'])) {
2142 foreach ($TFile as $key => &$val) {
2147 $nbfile = count($TFile[
'name']);
2149 for ($i = 0; $i < $nbfile; $i++) {
2150 if (empty($TFile[
'name'][$i])) {
2155 $destfile = trim($TFile[
'name'][$i]);
2156 $destfull = $upload_dir.
"/".$destfile;
2157 $destfilewithoutext = preg_replace(
'/\.[^\.]+$/',
'', $destfile);
2159 if ($savingdocmask && strpos($savingdocmask, $destfilewithoutext) !== 0) {
2160 $destfile = trim(preg_replace(
'/__file__/', $TFile[
'name'][$i], $savingdocmask));
2161 $destfull = $upload_dir.
"/".$destfile;
2164 $filenameto = basename($destfile);
2165 if (preg_match(
'/^\./', $filenameto)) {
2166 $langs->load(
"errors");
2167 setEventMessages($langs->trans(
"ErrorFilenameCantStartWithDot", $filenameto),
null,
'errors');
2171 $info = pathinfo($destfull);
2172 $destfull = $info[
'dirname'].
'/'.
dol_sanitizeFileName($info[
'filename'].($info[
'extension'] !=
'' ? (
'.'.strtolower($info[
'extension'])) :
''));
2173 $info = pathinfo($destfile);
2174 $destfile =
dol_sanitizeFileName($info[
'filename'].($info[
'extension'] !=
'' ? (
'.'.strtolower($info[
'extension'])) :
''));
2177 $defaultexecutableextensions = function_exists(
'getExecutableContent') ? implode(
',',
getExecutableContent()) :
'htm,html,shtml,js,phar,php,php3,php4,php5,phtml,pht,pl,py,cgi,ksh,sh,bash,bat,cmd,wpk,exe';
2178 $fileextensionrestriction =
getDolGlobalString(
"MAIN_FILE_EXTENSION_UPLOAD_RESTRICTION", $defaultexecutableextensions);
2179 if (!empty($fileextensionrestriction)) {
2180 $arrayofregexextension = explode(
",", $fileextensionrestriction);
2182 foreach ($arrayofregexextension as $fileextension) {
2183 if (preg_match(
'/\.'.preg_quote(trim($fileextension),
'/').
'$/i', $destfull)) {
2184 $langs->load(
"errors");
2185 setEventMessages($langs->trans(
"ErrorFilenameExtensionNotAllowed", $filenameto),
null,
'errors');
2197 global $dolibarr_main_restrict_os_commands;
2198 if (!empty($dolibarr_main_restrict_os_commands)) {
2199 $arrayofallowedcommand = explode(
',', $dolibarr_main_restrict_os_commands);
2200 $arrayofallowedcommand = array_map(
'trim', $arrayofallowedcommand);
2201 if (in_array($destfile, $arrayofallowedcommand)) {
2202 $langs->load(
"errors");
2203 setEventMessages($langs->trans(
"ErrorFilenameReserved", $destfile),
null,
'errors');
2209 $resupload =
dol_move_uploaded_file($TFile[
'tmp_name'][$i], $destfull, $allowoverwrite, 0, $TFile[
'error'][$i], 0, $keyforsourcefile, $upload_dir, $mode);
2211 if (is_numeric($resupload) && $resupload > 0) {
2212 include_once DOL_DOCUMENT_ROOT.
'/core/lib/images.lib.php';
2215 $maxwidthsmall = $tmparraysize[
'maxwidthsmall'];
2216 $maxheightsmall = $tmparraysize[
'maxheightsmall'];
2217 $maxwidthmini = $tmparraysize[
'maxwidthmini'];
2218 $maxheightmini = $tmparraysize[
'maxheightmini'];
2223 if ($generatethumbs) {
2229 $imgThumbSmall =
vignette($destfull, $maxwidthsmall, $maxheightsmall,
'_small', $quality,
"thumbs");
2232 $imgThumbMini =
vignette($destfull, $maxwidthmini, $maxheightmini,
'_mini', $quality,
"thumbs");
2237 if (empty($updatesessionordb)) {
2238 include_once DOL_DOCUMENT_ROOT.
'/core/class/html.formmail.class.php';
2240 $formmail->trackid = $trackid;
2241 $formmail->add_attached_files($destfull, $destfile, $TFile[
'type'][$i]);
2245 if ($updatesessionordb == 1) {
2247 if ($TFile[
'type'][$i] ==
'application/pdf' && strpos($_SERVER[
"REQUEST_URI"],
'product') !==
false &&
getDolGlobalString(
'PRODUCT_ALLOW_EXTERNAL_DOWNLOAD')) {
2252 if ($allowoverwrite) {
2256 $result =
addFileIntoDatabaseIndex($upload_dir, basename($destfile).($resupload == 2 ?
'.noexe' :
''), $TFile[
'name'][$i],
'uploaded', $sharefile,
$object, $forceFullTextIndexation);
2258 if ($allowoverwrite) {
2261 setEventMessages(
'WarningFailedToAddFileIntoDatabaseIndex',
null,
'warnings');
2268 $langs->load(
"errors");
2269 if (is_numeric($resupload) && $resupload < 0) {
2270 setEventMessages($langs->trans(
"ErrorFileNotUploaded"),
null,
'errors');
2272 setEventMessages($langs->trans($resupload),
null,
'errors');
2278 setEventMessages($langs->trans(
"FileTransferComplete"),
null,
'mesgs');
2281 setEventMessages($langs->trans(
"ErrorFailedToCreateDir", $upload_dir),
null,
'errors');
2284 require_once DOL_DOCUMENT_ROOT.
'/core/class/link.class.php';
2285 $linkObject =
new Link($db);
2286 $linkObject->entity =
$conf->entity;
2287 $linkObject->url = $link;
2288 $linkObject->objecttype =
GETPOST(
'objecttype',
'alpha');
2289 $linkObject->objectid =
GETPOSTINT(
'objectid');
2290 $linkObject->label =
GETPOST(
'label',
'alpha');
2291 $res = $linkObject->create($user);
2294 setEventMessages($langs->trans(
"LinkComplete"),
null,
'mesgs');
2296 setEventMessages($langs->trans(
"ErrorFileNotLinked"),
null,
'errors');
2299 $langs->load(
"errors");
2300 setEventMessages($langs->trans(
"ErrorFieldRequired", $langs->transnoentities(
"File")),
null,
'errors');
3072 global
$conf, $db, $user, $hookmanager;
3073 global $dolibarr_main_data_root, $dolibarr_main_document_root_alt;
3076 if (!is_object($fuser)) {
3080 if (empty($modulepart)) {
3081 return 'ErrorBadParameter';
3084 $originalmodulepart = $modulepart;
3086 if (empty($entity)) {
3099 if ($modulepart ==
'facture') {
3100 $modulepart =
'invoice';
3101 } elseif ($modulepart ==
'users') {
3102 $modulepart =
'user';
3103 } elseif ($modulepart ==
'tva') {
3104 $modulepart =
'tax-vat';
3105 } elseif ($modulepart ==
'expedition' && strpos($original_file,
'receipt/') === 0) {
3107 $modulepart =
'delivery';
3108 } elseif ($modulepart ==
'propale') {
3109 $modulepart =
'propal';
3114 if (preg_match(
'/(\w+)@(\w+)$/', $modulepart, $reg)) {
3115 $modulepart = $reg[2];
3119 dol_syslog(
'dol_check_secure_access_document modulepart='.$modulepart.
' original_file='.$original_file.
' entity='.$entity);
3123 $sqlprotectagainstexternals =
'';
3127 if (empty($refname)) {
3128 $refname = basename(dirname($original_file).
"/");
3129 if ($refname ==
'thumbs' || $refname ==
'temp') {
3131 $refname = basename(dirname(dirname($original_file)).
"/");
3138 $download =
'download';
3139 if ($mode ==
'write') {
3142 $download =
'upload';
3143 } elseif ($mode ==
'delete') {
3144 $lire =
'supprimer';
3146 $download =
'upload';
3150 if ($modulepart ==
'common') {
3153 $original_file = DOL_DOCUMENT_ROOT.
'/public/theme/common/'.$original_file;
3154 } elseif ($modulepart ==
'medias' && !empty($dolibarr_main_data_root)) {
3156 if (empty($entity)) {
3160 if ($mode ==
'write') {
3161 if ($fuser->hasRight(
'website',
'write')) {
3167 $original_file = (empty(
$conf->medias->multidir_output[$entity]) ? (empty(
$conf->medias->dir_output) ? DOL_DATA_ROOT.
'/medias' :
$conf->medias->dir_output) :
$conf->medias->multidir_output[$entity]).
'/'.$original_file;
3168 } elseif ($modulepart ==
'logs' && !empty($dolibarr_main_data_root)) {
3170 $accessallowed = ($user->admin && basename($original_file) == $original_file && preg_match(
'/^dolibarr.*\.(log|json)$/', basename($original_file)));
3171 $original_file = $dolibarr_main_data_root.
'/'.$original_file;
3172 } elseif ($modulepart ==
'doctemplates' && !empty($dolibarr_main_data_root)) {
3173 $accessallowed = $user->admin;
3174 $relative_file = $original_file;
3175 $ent = ($entity > 0 ? $entity :
$conf->entity);
3176 $path_with_entity = $dolibarr_main_data_root .
'/' . $ent .
'/doctemplates/' . $relative_file;
3177 if ($ent > 1 && file_exists(
dol_osencode($path_with_entity))) {
3178 $original_file = $path_with_entity;
3180 $original_file = $dolibarr_main_data_root .
'/doctemplates/' . $relative_file;
3182 } elseif ($modulepart ==
'doctemplateswebsite' && !empty($dolibarr_main_data_root)) {
3184 $accessallowed = ($fuser->hasRight(
'website',
'write') && preg_match(
'/\.jpg$/i', basename($original_file)));
3185 $original_file = $dolibarr_main_data_root.
'/doctemplates/websites/'.$original_file;
3186 } elseif ($modulepart ==
'packages' && !empty($dolibarr_main_data_root)) {
3189 $tmp = explode(
',', $dolibarr_main_document_root_alt);
3192 $accessallowed = ($user->admin && preg_match(
'/^module_.*\.zip$/', basename($original_file)));
3193 $original_file = $dirins.
'/'.$original_file;
3194 } elseif ($modulepart ==
'mycompany' && !empty(
$conf->mycompany->dir_output)) {
3197 $original_file =
$conf->mycompany->dir_output.
'/'.$original_file;
3198 } elseif ($modulepart ==
'userphoto' && !empty(
$conf->user->dir_output)) {
3201 if (preg_match(
'/^\d+\/photos\//', $original_file)) {
3204 $original_file =
$conf->user->dir_output.
'/'.$original_file;
3205 } elseif ($modulepart ==
'userphotopublic' && !empty(
$conf->user->dir_output)) {
3210 if (preg_match(
'/^(\d+)\/photos\//', $original_file, $reg)) {
3211 if ((
int) $reg[1]) {
3212 $tmpobject =
new User($db);
3213 $tmpobject->fetch((
int) $reg[1],
'',
'', 1);
3215 $securekey =
GETPOST(
'securekey',
'alpha', 1);
3217 global $dolibarr_main_cookie_cryptkey, $dolibarr_main_instance_unique_id;
3218 $valuetouse = $dolibarr_main_instance_unique_id ? $dolibarr_main_instance_unique_id : $dolibarr_main_cookie_cryptkey;
3219 $encodedsecurekey =
dol_hash($valuetouse.
'uservirtualcard'.$tmpobject->id.
'-'.$tmpobject->login,
'md5');
3220 if ($encodedsecurekey == $securekey) {
3229 $original_file =
$conf->user->dir_output.
'/'.$original_file;
3230 } elseif (($modulepart ==
'companylogo') && !empty(
$conf->mycompany->dir_output)) {
3233 $original_file =
$conf->mycompany->dir_output.
'/logos/'.$original_file;
3234 } elseif ($modulepart ==
'memberphoto' && !empty(
$conf->member->dir_output)) {
3238 if (preg_match(
'/^\d+\/photos\//', $original_file)) {
3242 if (preg_match(
'/^MEM\d\d\d\d-\d\d\d\d\/photos\//', $original_file)) {
3245 $original_file =
$conf->member->dir_output.
'/'.$original_file;
3246 } elseif ($modulepart ==
'apercufacture' && !empty(
$conf->invoice->multidir_output[$entity])) {
3248 if ($fuser->hasRight(
'facture', $lire)) {
3251 $original_file =
$conf->invoice->multidir_output[$entity].
'/'.$original_file;
3252 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"facture WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'invoice').
")";
3253 } elseif ($modulepart ==
'apercupropal' && !empty(
$conf->propal->multidir_output[$entity])) {
3255 if ($fuser->hasRight(
'propal', $lire)) {
3258 $original_file =
$conf->propal->multidir_output[$entity].
'/'.$original_file;
3259 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"propal WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'propal').
")";
3260 } elseif ($modulepart ==
'apercucommande' && !empty(
$conf->order->multidir_output[$entity])) {
3262 if ($fuser->hasRight(
'commande', $lire)) {
3265 $original_file =
$conf->order->multidir_output[$entity].
'/'.$original_file;
3266 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"commande WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'order').
")";
3267 } elseif (($modulepart ==
'apercufichinter' || $modulepart ==
'apercuficheinter') && !empty(
$conf->ficheinter->multidir_output[$entity])) {
3269 if ($fuser->hasRight(
'ficheinter', $lire)) {
3272 $original_file =
$conf->ficheinter->multidir_output[$entity].
'/'.$original_file;
3273 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"fichinter WHERE ref='".$db->escape($refname).
"' AND entity=".((int)
$conf->entity);
3274 } elseif (($modulepart ==
'apercucontract') && !empty(
$conf->contract->multidir_output[$entity])) {
3276 if ($fuser->hasRight(
'contrat', $lire)) {
3279 $original_file =
$conf->contract->multidir_output[$entity].
'/'.$original_file;
3280 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"contrat WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'contract').
")";
3281 } elseif (($modulepart ==
'apercusupplier_proposal') && !empty(
$conf->supplier_proposal->dir_output)) {
3283 if ($fuser->hasRight(
'supplier_proposal', $lire)) {
3286 $original_file =
$conf->supplier_proposal->dir_output.
'/'.$original_file;
3287 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"supplier_proposal WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'supplier_proposal').
")";
3288 } elseif (($modulepart ==
'apercusupplier_order') && !empty(
$conf->fournisseur->commande->dir_output)) {
3290 if ($fuser->hasRight(
'fournisseur',
'commande', $lire)) {
3293 $original_file =
$conf->fournisseur->commande->dir_output.
'/'.$original_file;
3294 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"commande_fournisseur WHERE ref='".$db->escape($refname).
"' AND entity=".((int)
$conf->entity);
3295 } elseif (($modulepart ==
'apercusupplier_invoice') && !empty(
$conf->fournisseur->facture->dir_output)) {
3297 if ($fuser->hasRight(
'fournisseur', $lire)) {
3300 $original_file =
$conf->fournisseur->facture->dir_output.
'/'.$original_file;
3301 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"facture_fourn WHERE ref='".$db->escape($refname).
"' AND entity=".((int)
$conf->entity);
3302 } elseif (($modulepart ==
'holiday') && !empty(
$conf->holiday->dir_output)) {
3303 if ($fuser->hasRight(
'holiday', $read) || $fuser->hasRight(
'holiday',
'readall') || preg_match(
'/^specimen/i', $original_file)) {
3306 if ($refname && !$fuser->hasRight(
'holiday',
'readall') && !preg_match(
'/^specimen/i', $original_file)) {
3307 include_once DOL_DOCUMENT_ROOT.
'/holiday/class/holiday.class.php';
3308 $tmpholiday =
new Holiday($db);
3309 $tmpholiday->fetch(0, $refname);
3310 $accessallowed =
checkUserAccessToObject($user, array(
'holiday'), $tmpholiday,
'holiday',
'',
'',
'rowid',
'');
3313 $original_file =
$conf->holiday->dir_output.
'/'.$original_file;
3314 } elseif (($modulepart ==
'salaries') && !empty(
$conf->salaries->dir_output)) {
3316 if ($fuser->hasRight(
'salaries', $read) || $fuser->hasRight(
'salaries',
'readall') || preg_match(
'/^specimen/i', $original_file)) {
3322 if ($refname && !$fuser->hasRight(
'salaries',
'readall') && !preg_match(
'/^specimen/i', $original_file)) {
3323 include_once DOL_DOCUMENT_ROOT.
'/salaries/class/salary.class.php';
3324 $tmpsalary =
new Salary($db);
3325 $tmpsalary->fetch((
int) $refname);
3330 $accessallowed = ($tmpsalary->fk_user > 0 && in_array($tmpsalary->fk_user, $fuser->getAllChildIds(1))) ? 1 : 0;
3333 $original_file =
$conf->salaries->dir_output.
'/'.$original_file;
3334 } elseif (($modulepart ==
'expensereport') && !empty(
$conf->expensereport->dir_output)) {
3335 if ($fuser->hasRight(
'expensereport', $lire) || $fuser->hasRight(
'expensereport',
'readall') || preg_match(
'/^specimen/i', $original_file)) {
3338 if ($refname && !$fuser->hasRight(
'expensereport',
'readall') && !preg_match(
'/^specimen/i', $original_file)) {
3339 include_once DOL_DOCUMENT_ROOT.
'/expensereport/class/expensereport.class.php';
3341 $tmpexpensereport->fetch(0, $refname);
3342 $accessallowed =
checkUserAccessToObject($user, array(
'expensereport'), $tmpexpensereport,
'expensereport',
'',
'',
'rowid',
'');
3345 $original_file =
$conf->expensereport->dir_output.
'/'.$original_file;
3346 } elseif (($modulepart ==
'apercuexpensereport') && !empty(
$conf->expensereport->dir_output)) {
3348 if ($fuser->hasRight(
'expensereport', $lire)) {
3351 if ($fuser->socid > 0) {
3355 $original_file =
$conf->expensereport->dir_output.
'/'.$original_file;
3356 } elseif ($modulepart ==
'propalstats' && !empty(
$conf->propal->multidir_temp[$entity])) {
3358 if ($fuser->hasRight(
'propal', $lire)) {
3361 $original_file =
$conf->propal->multidir_temp[$entity].
'/'.$original_file;
3362 } elseif ($modulepart ==
'orderstats' && !empty(
$conf->order->dir_temp)) {
3364 if ($fuser->hasRight(
'commande', $lire)) {
3367 $original_file =
$conf->order->dir_temp.
'/'.$original_file;
3368 } elseif ($modulepart ==
'orderstatssupplier' && !empty(
$conf->fournisseur->dir_output)) {
3369 if ($fuser->hasRight(
'fournisseur',
'commande', $lire)) {
3372 $original_file =
$conf->fournisseur->commande->dir_temp.
'/'.$original_file;
3373 } elseif ($modulepart ==
'billstats' && !empty(
$conf->invoice->dir_temp)) {
3375 if ($fuser->hasRight(
'facture', $lire)) {
3378 $original_file =
$conf->invoice->dir_temp.
'/'.$original_file;
3379 } elseif ($modulepart ==
'billstatssupplier' && !empty(
$conf->fournisseur->dir_output)) {
3380 if ($fuser->hasRight(
'fournisseur',
'facture', $lire)) {
3383 $original_file =
$conf->fournisseur->facture->dir_temp.
'/'.$original_file;
3384 } elseif ($modulepart ==
'expeditionstats' && !empty(
$conf->expedition->dir_temp)) {
3386 if ($fuser->hasRight(
'expedition', $lire)) {
3389 $original_file =
$conf->expedition->dir_temp.
'/'.$original_file;
3390 } elseif ($modulepart ==
'memberstats' && !empty(
$conf->member->dir_temp)) {
3392 if ($fuser->hasRight(
'adherent', $lire)) {
3395 $original_file =
$conf->member->dir_temp.
'/'.$original_file;
3396 } elseif (preg_match(
'/^productstats_/i', $modulepart) && !empty(
$conf->product->dir_temp)) {
3398 if ($fuser->hasRight(
'produit', $lire) || $fuser->hasRight(
'service', $lire)) {
3401 $original_file = (!empty(
$conf->product->multidir_temp[$entity]) ?
$conf->product->multidir_temp[$entity] :
$conf->service->multidir_temp[$entity]).
'/'.$original_file;
3402 } elseif (in_array($modulepart, array(
'tax',
'tax-vat',
'tva')) && !empty(
$conf->tax->dir_output)) {
3404 if ($fuser->hasRight(
'tax',
'charges', $lire)) {
3407 $modulepartsuffix = str_replace(
'tax-',
'', $modulepart);
3408 $original_file =
$conf->tax->dir_output.
'/'.($modulepartsuffix !=
'tax' ? $modulepartsuffix.
'/' :
'').$original_file;
3409 } elseif (($modulepart ==
'actions' || $modulepart ==
'actioncomm') && !empty(
$conf->agenda->dir_output)) {
3411 if ($fuser->hasRight(
'agenda',
'myactions', $read)) {
3414 if ($refname && !preg_match(
'/^specimen/i', $original_file)) {
3415 include_once DOL_DOCUMENT_ROOT.
'/comm/action/class/actioncomm.class.php';
3417 $tmpobject->fetch((
int) $refname);
3418 $accessallowed =
checkUserAccessToObject($user, array(
'agenda'), $tmpobject->id,
'actioncomm&societe',
'myactions|allactions',
'fk_soc',
'id',
'');
3419 if ($user->socid && $tmpobject->socid) {
3424 $original_file =
$conf->agenda->dir_output.
'/'.$original_file;
3425 } elseif ($modulepart ==
'category' && !empty(
$conf->categorie->multidir_output[$entity])) {
3427 if (empty($entity) || empty(
$conf->categorie->multidir_output[$entity])) {
3428 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3430 if ($fuser->hasRight(
"categorie", $lire) || $fuser->hasRight(
"takepos",
"run")) {
3433 $original_file =
$conf->categorie->multidir_output[$entity].
'/'.$original_file;
3434 } elseif ($modulepart ==
'prelevement' && !empty(
$conf->prelevement->dir_output)) {
3436 if ($fuser->hasRight(
'prelevement',
'bons', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3439 $original_file =
$conf->prelevement->dir_output.
'/'.$original_file;
3440 } elseif ($modulepart ==
'graph_stock' && !empty(
$conf->stock->dir_temp)) {
3443 $original_file =
$conf->stock->dir_temp.
'/'.$original_file;
3444 } elseif ($modulepart ==
'graph_fourn' && !empty(
$conf->fournisseur->dir_temp)) {
3447 $original_file =
$conf->fournisseur->dir_temp.
'/'.$original_file;
3448 } elseif ($modulepart ==
'graph_product' && !empty(
$conf->product->dir_temp)) {
3451 $original_file =
$conf->product->multidir_temp[$entity].
'/'.$original_file;
3452 } elseif ($modulepart ==
'barcode') {
3457 $original_file =
'';
3458 } elseif ($modulepart ==
'iconmailing' && !empty(
$conf->mailing->dir_temp)) {
3461 $original_file =
$conf->mailing->dir_temp.
'/'.$original_file;
3462 } elseif ($modulepart ==
'scanner_user_temp' && !empty(
$conf->scanner->dir_temp)) {
3465 $original_file =
$conf->scanner->dir_temp.
'/'.$fuser->id.
'/'.$original_file;
3466 } elseif ($modulepart ==
'fckeditor' && !empty(
$conf->fckeditor->dir_output)) {
3469 $original_file =
$conf->fckeditor->dir_output.
'/'.$original_file;
3470 } elseif ($modulepart ==
'user' && !empty(
$conf->user->dir_output)) {
3472 $canreaduser = (!empty($fuser->admin) || $fuser->hasRight(
'user',
'user', $lire));
3473 if ($fuser->id == (
int) $refname) {
3476 if ($canreaduser || preg_match(
'/^specimen/i', $original_file)) {
3479 $original_file =
$conf->user->dir_output.
'/'.$original_file;
3480 } elseif (($modulepart ==
'company' || $modulepart ==
'societe' || $modulepart ==
'thirdparty') && !empty(
$conf->societe->multidir_output[$entity])) {
3482 if (empty($entity) || empty(
$conf->societe->multidir_output[$entity])) {
3483 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3485 if ($fuser->hasRight(
'societe', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3488 $original_file =
$conf->societe->multidir_output[$entity].
'/'.$original_file;
3489 $sqlprotectagainstexternals =
"SELECT rowid as fk_soc FROM ".MAIN_DB_PREFIX.
"societe WHERE rowid = ".((int) $refname).
" AND entity IN (".
getEntity(
'societe').
")";
3490 } elseif (($modulepart ==
'contact' || $modulepart ==
'socpeople') && !empty(
$conf->societe->multidir_output[$entity])) {
3492 if (empty($entity) || empty(
$conf->societe->multidir_output[$entity])) {
3493 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3495 if ($fuser->hasRight(
'societe',
'contact', $lire)) {
3498 $original_file =
$conf->societe->multidir_output[$entity].
'/contact/'.$original_file;
3499 $sqlprotectagainstexternals =
"SELECT fk_soc FROM ".MAIN_DB_PREFIX.
"socpeople WHERE rowid = ".((int) $refname).
" AND entity IN (".
getEntity(
'contact').
")";
3500 } elseif (($modulepart ==
'facture' || $modulepart ==
'invoice') && !empty(
$conf->invoice->multidir_output[$entity])) {
3502 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3505 $original_file =
$conf->invoice->multidir_output[$entity].
'/'.$original_file;
3506 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"facture WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'invoice').
")";
3507 } elseif ($modulepart ==
'massfilesarea_proposals' && !empty(
$conf->propal->multidir_output[$entity])) {
3509 if ($fuser->hasRight(
'propal', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3512 $original_file =
$conf->propal->multidir_output[$entity].
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3513 } elseif ($modulepart ==
'massfilesarea_orders') {
3514 if ($fuser->hasRight(
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3517 $original_file =
$conf->order->multidir_output[$entity].
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3518 } elseif ($modulepart ==
'massfilesarea_sendings') {
3519 if ($fuser->hasRight(
'expedition', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3522 $original_file =
$conf->expedition->dir_output.
'/sending/temp/massgeneration/'.$user->id.
'/'.$original_file;
3523 } elseif ($modulepart ==
'massfilesarea_receipts') {
3524 if ($fuser->hasRight(
'reception', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3527 $original_file =
$conf->reception->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3528 } elseif ($modulepart ==
'massfilesarea_invoices') {
3529 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3532 $original_file =
$conf->invoice->multidir_output[$entity].
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3533 } elseif ($modulepart ==
'massfilesarea_expensereport') {
3534 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3537 $original_file =
$conf->expensereport->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3538 } elseif ($modulepart ==
'massfilesarea_interventions') {
3539 if ($fuser->hasRight(
'ficheinter', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3542 $original_file =
$conf->ficheinter->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3543 } elseif ($modulepart ==
'massfilesarea_supplier_proposal' && !empty(
$conf->supplier_proposal->dir_output)) {
3544 if ($fuser->hasRight(
'supplier_proposal', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3547 $original_file =
$conf->supplier_proposal->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3548 } elseif ($modulepart ==
'massfilesarea_supplier_order') {
3549 if ($fuser->hasRight(
'fournisseur',
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3552 $original_file =
$conf->fournisseur->commande->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3553 } elseif ($modulepart ==
'massfilesarea_supplier_invoice') {
3554 if ($fuser->hasRight(
'fournisseur',
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3557 $original_file =
$conf->fournisseur->facture->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3558 } elseif ($modulepart ==
'massfilesarea_contract' && !empty(
$conf->contract->dir_output)) {
3559 if ($fuser->hasRight(
'contrat', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3562 $original_file =
$conf->contract->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3563 } elseif ($modulepart ==
'massfilesarea_stock' && !empty(
$conf->stock->dir_output)) {
3564 if ($fuser->hasRight(
'stock', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3567 $original_file =
$conf->stock->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3568 } elseif (($modulepart ==
'fichinter' || $modulepart ==
'ficheinter') && !empty(
$conf->ficheinter->multidir_output[$entity])) {
3570 if ($fuser->hasRight(
'ficheinter', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3573 $original_file =
$conf->ficheinter->multidir_output[$entity].
'/'.$original_file;
3574 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"fichinter WHERE ref='".$db->escape($refname).
"' AND entity=".((int)
$conf->entity);
3575 } elseif (($modulepart ==
'propal' || $modulepart ==
'propale') && isset(
$conf->propal->multidir_output[$entity])) {
3577 if ($fuser->hasRight(
'propal', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3580 $original_file =
$conf->propal->multidir_output[$entity].
'/'.$original_file;
3581 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"propal WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'propal').
")";
3582 } elseif (($modulepart ==
'commande' || $modulepart ==
'order') && !empty(
$conf->order->multidir_output[$entity])) {
3584 if ($fuser->hasRight(
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3587 $original_file =
$conf->order->multidir_output[$entity].
'/'.$original_file;
3588 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"commande WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'order').
")";
3589 } elseif ($modulepart ==
'project' && !empty(
$conf->project->multidir_output[$entity])) {
3591 if ($fuser->hasRight(
'projet', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3594 if ($refname && !preg_match(
'/^specimen/i', $original_file)) {
3595 include_once DOL_DOCUMENT_ROOT.
'/projet/class/project.class.php';
3596 $tmpproject =
new Project($db);
3597 $tmpproject->fetch(0, $refname);
3598 $accessallowed =
checkUserAccessToObject($user, array(
'projet'), $tmpproject->id,
'projet&project',
'',
'',
'rowid',
'');
3601 $original_file =
$conf->project->multidir_output[$entity].
'/'.$original_file;
3602 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"projet WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'project').
")";
3603 } elseif ($modulepart ==
'project_task' && !empty(
$conf->project->multidir_output[$entity])) {
3604 if ($fuser->hasRight(
'projet', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3607 if ($refname && !preg_match(
'/^specimen/i', $original_file)) {
3608 include_once DOL_DOCUMENT_ROOT.
'/projet/class/task.class.php';
3609 $tmptask =
new Task($db);
3610 $tmptask->fetch(0, $refname);
3611 $accessallowed =
checkUserAccessToObject($user, array(
'projet_task'), $tmptask->id,
'projet_task&project',
'',
'',
'rowid',
'');
3614 $original_file =
$conf->project->multidir_output[$entity].
'/'.$original_file;
3615 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"projet WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'project').
")";
3616 } elseif (($modulepart ==
'commande_fournisseur' || $modulepart ==
'order_supplier' || $modulepart ==
'supplier_order') && !empty(
$conf->fournisseur->commande->dir_output)) {
3618 if ($fuser->hasRight(
'fournisseur',
'commande', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3621 $original_file =
$conf->fournisseur->commande->dir_output.
'/'.$original_file;
3622 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"commande_fournisseur WHERE ref='".$db->escape($refname).
"' AND entity = ".((int)
$conf->entity);
3623 } elseif (($modulepart ==
'facture_fournisseur' || $modulepart ==
'invoice_supplier' || $modulepart ==
'supplier_invoice') && !empty(
$conf->fournisseur->facture->dir_output)) {
3625 if ($fuser->hasRight(
'fournisseur',
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3628 $original_file =
$conf->fournisseur->facture->dir_output.
'/'.$original_file;
3629 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"facture_fourn WHERE ref='".$db->escape($refname).
"' AND entity=".((int)
$conf->entity);
3630 } elseif ($modulepart ==
'supplier_payment') {
3632 if ($fuser->hasRight(
'fournisseur',
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3635 $original_file = preg_replace(
"/payment\//",
"", $original_file);
3636 $original_file =
$conf->fournisseur->payment->dir_output.
'/'.$original_file;
3637 $sqlprotectagainstexternals =
"SELECT f.fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"paiementfourn as p";
3638 $sqlprotectagainstexternals .=
" INNER JOIN ".MAIN_DB_PREFIX.
"paiementfourn_facturefourn as pf ON pf.fk_paiementfourn = p.rowid";
3639 $sqlprotectagainstexternals .=
" INNER JOIN ".MAIN_DB_PREFIX.
"facture_fourn as f ON pf.fk_facturefourn = p.rowid";
3640 $sqlprotectagainstexternals .=
" WHERE p.ref = '".$db->escape($refname).
"' AND p.entity=".((int)
$conf->entity);
3641 } elseif ($modulepart ==
'payment') {
3643 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3646 $original_file =
$conf->compta->payment->dir_output.
'/'.$original_file;
3647 } elseif ($modulepart ==
'facture_paiement' && !empty(
$conf->invoice->dir_output)) {
3649 if ($fuser->hasRight(
'facture', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3652 if ($fuser->socid > 0) {
3653 $original_file =
$conf->invoice->dir_output.
'/payments/private/'.$fuser->id.
'/'.$original_file;
3655 $original_file =
$conf->invoice->dir_output.
'/payments/'.$original_file;
3662 } elseif ($modulepart ==
'accounting' && !empty(
$conf->accounting->dir_output)) {
3664 if ($fuser->hasRight(
'accounting',
'bind',
'write') || $fuser->hasRight(
'accounting',
'mouvements',
'export') || preg_match(
'/^specimen/i', $original_file)) {
3667 $original_file =
$conf->accounting->dir_output.
'/'.$original_file;
3668 } elseif (($modulepart ==
'expedition' || $modulepart ==
'shipment' || $modulepart ==
'shipping') && !empty(
$conf->expedition->dir_output)) {
3670 if ($fuser->hasRight(
'expedition', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3673 $original_file =
$conf->expedition->dir_output.
"/".(strpos($original_file,
'sending/') === 0 ?
'' :
'sending/').$original_file;
3675 } elseif (($modulepart ==
'livraison' || $modulepart ==
'delivery') && !empty(
$conf->expedition->dir_output)) {
3677 if ($fuser->hasRight(
'expedition',
'delivery', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3680 $original_file =
$conf->expedition->dir_output.
"/".(strpos($original_file,
'receipt/') === 0 ?
'' :
'receipt/').$original_file;
3681 } elseif ($modulepart ==
'actionsreport' && !empty(
$conf->agenda->dir_temp)) {
3683 if ($fuser->hasRight(
'agenda',
'allactions', $read) || preg_match(
'/^specimen/i', $original_file)) {
3686 $original_file =
$conf->agenda->dir_temp.
"/".$original_file;
3687 } elseif ($modulepart ==
'product' || $modulepart ==
'produit' || $modulepart ==
'service' || $modulepart ==
'produit|service') {
3689 if (empty($entity) || (empty(
$conf->product->multidir_output[$entity]) && empty(
$conf->service->multidir_output[$entity]))) {
3690 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3692 if (($fuser->hasRight(
'produit', $lire) || $fuser->hasRight(
'service', $lire)) || preg_match(
'/^specimen/i', $original_file)) {
3696 $original_file =
$conf->product->multidir_output[$entity].
'/'.$original_file;
3698 $original_file =
$conf->service->multidir_output[$entity].
'/'.$original_file;
3700 } elseif ($modulepart ==
'product_batch' || $modulepart ==
'produitlot') {
3702 if (empty($entity) || (empty(
$conf->productbatch->multidir_output[$entity]))) {
3703 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3705 if (($fuser->hasRight(
'produit', $lire)) || preg_match(
'/^specimen/i', $original_file)) {
3709 $original_file =
$conf->productbatch->multidir_output[$entity].
'/'.$original_file;
3711 } elseif ($modulepart ==
'movement' || $modulepart ==
'mouvement') {
3713 if (empty($entity) || empty(
$conf->stock->multidir_output[$entity])) {
3714 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3716 if (($fuser->hasRight(
'stock', $lire) || $fuser->hasRight(
'stock',
'movement', $lire) || $fuser->hasRight(
'stock',
'mouvement', $lire)) || preg_match(
'/^specimen/i', $original_file)) {
3720 $original_file =
$conf->stock->multidir_output[$entity].
'/movement/'.$original_file;
3722 } elseif ($modulepart ==
'inventory') {
3724 if (empty($entity) || empty(
$conf->stock->multidir_output[$entity])) {
3725 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3727 if ($fuser->hasRight(
'stock', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3731 $original_file =
$conf->stock->multidir_output[$entity].
'/inventory/'.$original_file;
3733 } elseif ($modulepart ==
'entrepot') {
3735 if (empty($entity) || empty(
$conf->stock->multidir_output[$entity])) {
3736 return array(
'accessallowed' => 0,
'error' =>
'Value entity must be provided');
3738 if (($fuser->hasRight(
'stock', $lire) || $fuser->hasRight(
'stock',
'movement', $lire) || $fuser->hasRight(
'stock',
'mouvement', $lire)) || preg_match(
'/^specimen/i', $original_file)) {
3742 $original_file =
$conf->stock->multidir_output[$entity].
'/'.$original_file;
3744 } elseif ($modulepart ==
'contract' && !empty(
$conf->contract->multidir_output[$entity])) {
3746 if ($fuser->hasRight(
'contrat', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3749 $original_file =
$conf->contract->multidir_output[$entity].
'/'.$original_file;
3750 $sqlprotectagainstexternals =
"SELECT fk_soc as fk_soc FROM ".MAIN_DB_PREFIX.
"contrat WHERE ref='".$db->escape($refname).
"' AND entity IN (".
getEntity(
'contract').
")";
3751 } elseif ($modulepart ==
'donation' && !empty(
$conf->don->dir_output)) {
3753 if ($fuser->hasRight(
'don', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3756 $original_file =
$conf->don->dir_output.
'/'.$original_file;
3757 } elseif ($modulepart ==
'dolresource' && !empty(
$conf->resource->dir_output)) {
3759 if ($fuser->hasRight(
'resource', $read) || preg_match(
'/^specimen/i', $original_file)) {
3762 $original_file =
$conf->resource->dir_output.
'/'.$original_file;
3763 } elseif (($modulepart ==
'remisecheque' || $modulepart ==
'chequereceipt') && !empty(
$conf->bank->dir_output)) {
3765 if ($fuser->hasRight(
'banque', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3768 $original_file =
$conf->bank->dir_output.
'/checkdeposits/'.$original_file;
3769 } elseif (($modulepart ==
'banque' || $modulepart ==
'bank') && !empty(
$conf->bank->dir_output)) {
3772 if ($fuser->hasRight(
'banque', ($mode ==
'read' ?
'lire' :
'modifier'))) {
3775 $original_file =
$conf->bank->dir_output.
'/'.$original_file;
3776 } elseif ($modulepart ==
'export' && !empty(
$conf->export->dir_temp)) {
3779 $accessallowed = $user->hasRight(
'export',
'lire');
3780 $original_file =
$conf->export->dir_temp.
'/'.$fuser->id.
'/'.$original_file;
3781 } elseif ($modulepart ==
'import' && !empty(
$conf->import->dir_temp)) {
3783 $accessallowed = $user->hasRight(
'import',
'run');
3784 $original_file =
$conf->import->dir_temp.
'/'.$original_file;
3785 } elseif ($modulepart ==
'recruitment' && !empty(
$conf->recruitment->dir_output)) {
3787 $accessallowed = $user->hasRight(
'recruitment',
'recruitmentjobposition',
'read');
3788 $original_file =
$conf->recruitment->dir_output.
'/'.$original_file;
3789 } elseif ($modulepart ==
'hrm' && !empty(
$conf->hrm->dir_output)) {
3791 $accessallowed = $user->hasRight(
'hrm',
'all',
'read');
3792 $original_file =
$conf->hrm->dir_output.
'/'.$original_file;
3793 } elseif ($modulepart ==
'editor' && !empty(
$conf->fckeditor->dir_output)) {
3796 $original_file =
$conf->fckeditor->dir_output.
'/'.$original_file;
3797 } elseif ($modulepart ==
'systemtools' && !empty(
$conf->admin->dir_output)) {
3799 if ($fuser->admin) {
3802 $original_file =
$conf->admin->dir_output.
'/'.$original_file;
3803 } elseif ($modulepart ==
'admin_temp' && !empty(
$conf->admin->dir_temp)) {
3805 if ($fuser->admin) {
3808 $original_file =
$conf->admin->dir_temp.
'/'.$original_file;
3809 } elseif ($modulepart ==
'bittorrent' && !empty(
$conf->bittorrent->dir_output)) {
3813 if (
dol_mimetype($original_file) ==
'application/x-bittorrent') {
3816 $original_file =
$conf->bittorrent->dir_output.
'/'.$dir.
'/'.$original_file;
3817 } elseif ($modulepart ==
'member' && !empty(
$conf->member->dir_output)) {
3819 if ($fuser->hasRight(
'adherent', $lire) || preg_match(
'/^specimen/i', $original_file)) {
3822 $original_file =
$conf->member->dir_output.
'/'.$original_file;
3823 } elseif ($modulepart ==
'ticket' && !empty(
$conf->ticket->multidir_output[$entity])) {
3825 if ($fuser->hasRight(
'ticket', $read)) {
3828 if (!isset($_SESSION[
'email_customer'])) {
3830 $sqlprotectagainstexternals =
"SELECT fk_soc FROM ".MAIN_DB_PREFIX.
"ticket WHERE ref='".$db->escape($refname).
"' AND entity=".((int)
$conf->entity);
3832 $email_split = explode(
'@', $_SESSION[
'email_customer']);
3834 $sqlprotectagainstexternals =
'SELECT t.rowid, t.fk_soc FROM '.MAIN_DB_PREFIX.
'ticket t';
3835 $sqlprotectagainstexternals .=
' LEFT JOIN '.MAIN_DB_PREFIX.
'element_contact ec ON ec.element_id = t.rowid';
3836 $sqlprotectagainstexternals .=
' LEFT JOIN '.MAIN_DB_PREFIX.
'socpeople c ON c.rowid = ec.fk_socpeople';
3837 $sqlprotectagainstexternals .=
' LEFT JOIN '.MAIN_DB_PREFIX.
'c_type_contact tc ON tc.element = "ticket" AND tc.rowid = ec.fk_c_type_contact';
3838 $sqlprotectagainstexternals .=
" WHERE t.ref LIKE '".$db->escape($refname).
"'";
3839 $sqlprotectagainstexternals .=
' AND (';
3840 $sqlprotectagainstexternals .=
' (';
3841 $sqlprotectagainstexternals .=
' tc.rowid IS NOT NULL';
3842 $sqlprotectagainstexternals .=
" AND c.email = '".$db->escape($email_split[0]).
'@'.$db->sanitize($email_split[1]).
"'";
3843 $sqlprotectagainstexternals .=
' )';
3844 $sqlprotectagainstexternals .=
" OR t.origin_email = '".$db->escape($email_split[0]).
'@'.$db->sanitize($email_split[1]).
"'";
3845 $sqlprotectagainstexternals .=
' )';
3847 $original_file =
$conf->ticket->multidir_output[$entity].
'/'.$original_file;
3857 if (preg_match(
'/^specimen/i', $original_file)) {
3860 if ($fuser->admin) {
3865 $tmpmodulepart = explode(
'-', $modulepart);
3866 if (!empty($tmpmodulepart[1])) {
3867 $modulepart = $tmpmodulepart[0];
3868 $original_file = $tmpmodulepart[1].
'/'.$original_file;
3873 if (preg_match(
'/^([a-z]+)_user_temp$/i', $modulepart, $reg)) {
3874 $tmpmodule = $reg[1];
3875 if (empty(
$conf->$tmpmodule->dir_temp)) {
3876 dol_print_error(
null,
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3879 if ($fuser->hasRight($tmpmodule, $lire) || $fuser->hasRight($tmpmodule, $read) || $fuser->hasRight($tmpmodule, $download)) {
3882 $original_file =
$conf->{$reg[1]}->dir_temp.
'/'.$fuser->id.
'/'.$original_file;
3883 } elseif (preg_match(
'/^([a-z]+)_temp$/i', $modulepart, $reg)) {
3884 $tmpmodule = $reg[1];
3885 if (empty(
$conf->$tmpmodule->dir_temp)) {
3886 dol_print_error(
null,
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3889 if ($fuser->hasRight($tmpmodule, $lire) || $fuser->hasRight($tmpmodule, $read) || $fuser->hasRight($tmpmodule, $download)) {
3892 $original_file =
$conf->$tmpmodule->dir_temp.
'/'.$original_file;
3893 } elseif (preg_match(
'/^([a-z]+)_user$/i', $modulepart, $reg)) {
3894 $tmpmodule = $reg[1];
3895 if (empty(
$conf->$tmpmodule->dir_output)) {
3896 dol_print_error(
null,
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3899 if ($fuser->hasRight($tmpmodule, $lire) || $fuser->hasRight($tmpmodule, $read) || $fuser->hasRight($tmpmodule, $download)) {
3902 $original_file =
$conf->$tmpmodule->dir_output.
'/'.$fuser->id.
'/'.$original_file;
3903 } elseif (preg_match(
'/^massfilesarea_([a-z]+)$/i', $modulepart, $reg)) {
3904 $tmpmodule = $reg[1];
3905 if (empty(
$conf->$tmpmodule->dir_output)) {
3906 dol_print_error(
null,
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
')');
3911 $partsofdirinoriginalfile = explode(
'/', $original_file);
3912 if (!empty($partsofdirinoriginalfile[1])) {
3913 $partofdirinoriginalfile = $partsofdirinoriginalfile[0];
3914 if (($partofdirinoriginalfile && $fuser->hasRight($tmpmodule, $partofdirinoriginalfile,
'read')) || preg_match(
'/^specimen/i', $original_file)) {
3918 if ($fuser->hasRight($tmpmodule, $read) || preg_match(
'/^specimen/i', $original_file)) {
3921 $original_file =
$conf->$tmpmodule->dir_output.
'/temp/massgeneration/'.$user->id.
'/'.$original_file;
3924 if (empty(
$conf->$modulepart->dir_output)) {
3925 dol_print_error(
null,
'Error call dol_check_secure_access_document with not supported value for modulepart parameter ('.$modulepart.
'). The module for this modulepart value may not be activated.');
3930 $partsofdirinoriginalfile = explode(
'/', $original_file);
3931 if (!empty($partsofdirinoriginalfile[1])) {
3932 $partofdirinoriginalfile = $partsofdirinoriginalfile[0];
3933 if ($partofdirinoriginalfile && ($fuser->hasRight($modulepart, $partofdirinoriginalfile,
'lire') || $fuser->hasRight($modulepart, $partofdirinoriginalfile,
'read'))) {
3937 if (($fuser->hasRight($modulepart, $lire) || $fuser->hasRight($modulepart, $read)) || ($fuser->hasRight($modulepart,
'all', $lire) || $fuser->hasRight($modulepart,
'all', $read))) {
3943 if (preg_match(
'/^(\w+)@(\w+)$/', $originalmodulepart, $regs)) {
3944 $subdir = $regs[1].
'/';
3947 if (is_array(
$conf->$modulepart->multidir_output) && !empty(
$conf->$modulepart->multidir_output[$entity])) {
3948 $original_file =
$conf->$modulepart->multidir_output[$entity].
'/'.$subdir.$original_file;
3950 $original_file =
$conf->$modulepart->dir_output.
'/'.$subdir.$original_file;
3958 $parameters = array(
3959 'modulepart' => $modulepart,
3960 'original_file' => $original_file,
3961 'entity' => $entity,
3966 $reshook = $hookmanager->executeHooks(
'checkSecureAccess', $parameters,
$object);
3968 if (!empty($hookmanager->resArray[
'original_file'])) {
3969 $original_file = $hookmanager->resArray[
'original_file'];
3971 if (!empty($hookmanager->resArray[
'accessallowed'])) {
3972 $accessallowed = $hookmanager->resArray[
'accessallowed'];
3974 if (!empty($hookmanager->resArray[
'sqlprotectagainstexternals'])) {
3975 $sqlprotectagainstexternals = $hookmanager->resArray[
'sqlprotectagainstexternals'];
3981 'accessallowed' => ($accessallowed ? 1 : 0),
3982 'sqlprotectagainstexternals' => $sqlprotectagainstexternals,
3983 'original_file' => $original_file