xref: /webtrees/app/Http/RequestHandlers/MediaFileDownload.php (revision 1558ebe91cf8aee21751e57fb864e4b0813c3468)
1<?php
2
3/**
4 * webtrees: online genealogy
5 * Copyright (C) 2020 webtrees development team
6 * This program is free software: you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation, either version 3 of the License, or
9 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program. If not, see <http://www.gnu.org/licenses/>.
16 */
17
18declare(strict_types=1);
19
20namespace Fisharebest\Webtrees\Http\RequestHandlers;
21
22use Fig\Http\Message\StatusCodeInterface;
23use Fisharebest\Webtrees\Auth;
24use Fisharebest\Webtrees\Exceptions\HttpNotFoundException;
25use Fisharebest\Webtrees\Factory;
26use Fisharebest\Webtrees\Tree;
27use Psr\Http\Message\ResponseInterface;
28use Psr\Http\Message\ServerRequestInterface;
29use Psr\Http\Server\RequestHandlerInterface;
30
31use function addcslashes;
32use function assert;
33use function redirect;
34use function response;
35use function strlen;
36
37/**
38 * Download a media file.
39 */
40class MediaFileDownload implements RequestHandlerInterface
41{
42    /**
43     * Download a non-image media file.
44     *
45     * @param ServerRequestInterface $request
46     *
47     * @return ResponseInterface
48     */
49    public function handle(ServerRequestInterface $request): ResponseInterface
50    {
51        $tree = $request->getAttribute('tree');
52        assert($tree instanceof Tree);
53
54        $data_filesystem = Factory::filesystem()->data();
55
56        $disposition = $request->getQueryParams()['disposition'] ?? 'inline';
57        assert($disposition === 'inline' || $disposition === 'attachment');
58
59        $params  = $request->getQueryParams();
60        $xref    = $params['xref'];
61        $fact_id = $params['fact_id'];
62        $media   = Factory::media()->make($xref, $tree);
63        $media   = Auth::checkMediaAccess($media);
64
65        foreach ($media->mediaFiles() as $media_file) {
66            if ($media_file->factId() === $fact_id) {
67                if ($media_file->isExternal()) {
68                    return redirect($media_file->filename());
69                }
70
71                if ($media_file->fileExists($data_filesystem)) {
72                    $data = $media_file->media()->tree()->mediaFilesystem($data_filesystem)->read($media_file->filename());
73
74                    return response($data, StatusCodeInterface::STATUS_OK, [
75                        'Content-Type'        => $media_file->mimeType(),
76                        'Content-Length'      => (string) strlen($data),
77                        'Content-Disposition' => $disposition . '; filename="' . addcslashes($media_file->filename(), '"') . '"',
78                    ]);
79                }
80            }
81        }
82
83        throw new HttpNotFoundException();
84    }
85}
86