| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182 | <?php/** * upload.php * * Copyright 2013, Moxiecode Systems AB * Released under GPL License. * * License: http://www.plupload.com/license * Contributing: http://www.plupload.com/contributing */#!! IMPORTANT:#!! this file is just an example, it doesn't incorporate any security checks and#!! is not recommended to be used in production environment as it is. Be sure to#!! revise it and customize to your needs.// Make sure file is not cached (as it happens for example on iOS devices)header("Expires: Mon, 26 Jul 1997 05:00:00 GMT");header("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT");header("Cache-Control: no-store, no-cache, must-revalidate");header("Cache-Control: post-check=0, pre-check=0", false);header("Pragma: no-cache");// Support CORS// header("Access-Control-Allow-Origin: *");// other CORS headers if any...if ($_SERVER['REQUEST_METHOD'] == 'OPTIONS') {    exit; // finish preflight CORS requests here}if ( !empty($_REQUEST[ 'debug' ]) ) {    $random = rand(0, intval($_REQUEST[ 'debug' ]) );    if ( $random === 0 ) {        header("HTTP/1.0 500 Internal Server Error");        exit;    }}// 5 minutes execution time@set_time_limit(5 * 60);// Uncomment this one to fake upload timeusleep(5000);// Settings// $targetDir = ini_get("upload_tmp_dir") . DIRECTORY_SEPARATOR . "plupload";$targetDir = 'upload_tmp';$uploadDir = 'upload';$cleanupTargetDir = true; // Remove old files$maxFileAge = 5 * 3600; // Temp file age in seconds// Create target dirif (!file_exists($targetDir)) {    @mkdir($targetDir);}// Create target dirif (!file_exists($uploadDir)) {    @mkdir($uploadDir);}// Get a file nameif (isset($_REQUEST["name"])) {    $fileName = $_REQUEST["name"];} elseif (!empty($_FILES)) {    $fileName = $_FILES["file"]["name"];} else {    $fileName = uniqid("file_");}$md5File = @file('md5list.txt', FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES);$md5File = $md5File ? $md5File : array();if (isset($_REQUEST["md5"]) && array_search($_REQUEST["md5"], $md5File ) !== FALSE ) {    die('{"jsonrpc" : "2.0", "result" : null, "id" : "id", "exist": 1}');}$filePath = $targetDir . DIRECTORY_SEPARATOR . $fileName;$uploadPath = $uploadDir . DIRECTORY_SEPARATOR . $fileName;// Chunking might be enabled$chunk = isset($_REQUEST["chunk"]) ? intval($_REQUEST["chunk"]) : 0;$chunks = isset($_REQUEST["chunks"]) ? intval($_REQUEST["chunks"]) : 1;// Remove old temp filesif ($cleanupTargetDir) {    if (!is_dir($targetDir) || !$dir = opendir($targetDir)) {        die('{"jsonrpc" : "2.0", "error" : {"code": 100, "message": "Failed to open temp directory."}, "id" : "id"}');    }    while (($file = readdir($dir)) !== false) {        $tmpfilePath = $targetDir . DIRECTORY_SEPARATOR . $file;        // If temp file is current file proceed to the next        if ($tmpfilePath == "{$filePath}_{$chunk}.part" || $tmpfilePath == "{$filePath}_{$chunk}.parttmp") {            continue;        }        // Remove temp file if it is older than the max age and is not the current file        if (preg_match('/\.(part|parttmp)$/', $file) && (@filemtime($tmpfilePath) < time() - $maxFileAge)) {            @unlink($tmpfilePath);        }    }    closedir($dir);}// Open temp fileif (!$out = @fopen("{$filePath}_{$chunk}.parttmp", "wb")) {    die('{"jsonrpc" : "2.0", "error" : {"code": 102, "message": "Failed to open output stream."}, "id" : "id"}');}if (!empty($_FILES)) {    if ($_FILES["file"]["error"] || !is_uploaded_file($_FILES["file"]["tmp_name"])) {        die('{"jsonrpc" : "2.0", "error" : {"code": 103, "message": "Failed to move uploaded file."}, "id" : "id"}');    }    // Read binary input stream and append it to temp file    if (!$in = @fopen($_FILES["file"]["tmp_name"], "rb")) {        die('{"jsonrpc" : "2.0", "error" : {"code": 101, "message": "Failed to open input stream."}, "id" : "id"}');    }} else {    if (!$in = @fopen("php://input", "rb")) {        die('{"jsonrpc" : "2.0", "error" : {"code": 101, "message": "Failed to open input stream."}, "id" : "id"}');    }}while ($buff = fread($in, 4096)) {    fwrite($out, $buff);}@fclose($out);@fclose($in);rename("{$filePath}_{$chunk}.parttmp", "{$filePath}_{$chunk}.part");$index = 0;$done = true;for( $index = 0; $index < $chunks; $index++ ) {    if ( !file_exists("{$filePath}_{$index}.part") ) {        $done = false;        break;    }}if ( $done ) {    if (!$out = @fopen($uploadPath, "wb")) {        die('{"jsonrpc" : "2.0", "error" : {"code": 102, "message": "Failed to open output stream."}, "id" : "id"}');    }    if ( flock($out, LOCK_EX) ) {        for( $index = 0; $index < $chunks; $index++ ) {            if (!$in = @fopen("{$filePath}_{$index}.part", "rb")) {                break;            }            while ($buff = fread($in, 4096)) {                fwrite($out, $buff);            }            @fclose($in);            @unlink("{$filePath}_{$index}.part");        }                flock($out, LOCK_UN);    }    @fclose($out);    array_push($md5File, md5(file_get_contents($uploadPath)));    $md5File = array_unique($md5File);    file_put_contents('md5list.txt', join($md5File, "\n"));}// Return Success JSON-RPC responsedie('{"jsonrpc" : "2.0", "result" : null, "id" : "id"}');
 |