xref: /webtrees/app/Http/RequestHandlers/MediaFileDownload.php (revision 81b729d3a9a6e0a0e8b96285d1ad7955d2d0c659)
1<?php
2
3/**
4 * webtrees: online genealogy
5 * Copyright (C) 2021 webtrees development team
6 * This program is free software: you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation, either version 3 of the License, or
9 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program. If not, see <https://www.gnu.org/licenses/>.
16 */
17
18declare(strict_types=1);
19
20namespace Fisharebest\Webtrees\Http\RequestHandlers;
21
22use Fig\Http\Message\StatusCodeInterface;
23use Fisharebest\Webtrees\Auth;
24use Fisharebest\Webtrees\Contracts\UserInterface;
25use Fisharebest\Webtrees\Registry;
26use Fisharebest\Webtrees\Tree;
27use Psr\Http\Message\ResponseInterface;
28use Psr\Http\Message\ServerRequestInterface;
29use Psr\Http\Server\RequestHandlerInterface;
30
31use function assert;
32use function redirect;
33
34/**
35 * Download a media file.
36 */
37class MediaFileDownload implements RequestHandlerInterface
38{
39    /**
40     * Download a non-image media file.
41     *
42     * @param ServerRequestInterface $request
43     *
44     * @return ResponseInterface
45     */
46    public function handle(ServerRequestInterface $request): ResponseInterface
47    {
48        $tree = $request->getAttribute('tree');
49        assert($tree instanceof Tree);
50
51        $user = $request->getAttribute('user');
52        assert($user instanceof UserInterface);
53
54        $image_factory = Registry::imageFactory();
55
56        $disposition = $request->getQueryParams()['disposition'] ?? 'inline';
57        assert($disposition === 'inline' || $disposition === 'attachment');
58
59        $params  = $request->getQueryParams();
60        $xref    = $params['xref'] ?? '';
61        $fact_id = $params['fact_id'] ?? '';
62        $media   = Registry::mediaFactory()->make($xref, $tree);
63        $media   = Auth::checkMediaAccess($media);
64
65        foreach ($media->mediaFiles() as $media_file) {
66            if ($media_file->factId() === $fact_id) {
67                if ($media_file->isExternal()) {
68                    return redirect($media_file->filename());
69                }
70
71                $watermark = $media_file->isImage() && $image_factory->fileNeedsWatermark($media_file, $user);
72                $download  = $disposition === 'attachment';
73
74                $response = $image_factory->mediaFileResponse($media_file, $watermark, $download);
75
76                return $response->withHeader('Cache-Control', 'public,max-age=31536000');
77            }
78        }
79
80        return $image_factory->replacementImageResponse((string) StatusCodeInterface::STATUS_NOT_FOUND);
81    }
82}
83