4 if (empty($User['admin']))
5 abort("geen beheersrechten", '401 unauthorised');
8 $response = ['uploaded' => 0];
10 $img = @$_FILES['upload'];
11 $response['fileName'] = $img['name'];
12 if (!$img or $img['error'] !== UPLOAD_ERR_OK)
13 throw new Exception('bestand niet goed ontvangen: '.$img['error']);
15 $datadir = implode('/', ['data', date('Y')]);
16 if (!file_exists($datadir) and !@mkdir($datadir, 0777, TRUE)) {
17 throw new Exception("bestand kon niet geplaatst worden in $datadir");
20 $target = $datadir.'/'.$img['name'];
21 $response['url'] = str_replace('%2F', '/', urlencode($target));
22 if (!@move_uploaded_file($img['tmp_name'], $target)) {
23 throw new Exception('bestand kon niet worden opgeslagen');
25 $response['uploaded']++;
27 catch (Exception $e) {
28 $response['error'] = ['message' => $e->getMessage()];
31 switch (@$_GET['output']) {
33 print json_encode($response);
36 if (empty($response['url'])) break;
37 printf('<script>window.parent.CKEDITOR.tools.callFunction(%s)</script>',
38 "{$_GET['CKEditorFuncNum']}, '{$response['url']}'"
42 if (empty($response['url'])) break;
46 if (isset($response['error'])) {
47 abort($response['error']['message'], '409 upload error');
53 abort("niets te doen", '405 post error');
55 abort("geen bestand aangeleverd", '409 input error');
57 $filename = ltrim($Args, '/').'.html';
58 if (preg_match('{^\.}', $filename))
59 abort("ongeldige bestandsnaam: $filename", '403 input error');
60 if (file_exists($filename) and !is_writable($filename))
61 abort("onwijzigbaar bestand: $filename", '403 input error');
63 if (!isset($_POST['body']))
64 abort("geen inhoud aangeleverd", '409 input error');
66 $upload = $_POST['body'];
68 if (!strlen($upload)) {
69 if (file_exists($filename) and !unlink($filename))
70 abort("fout bij het verwijderen van $filename", '500 delete error');
72 abort("Bestand verwijderd");
75 if (!file_exists(dirname($filename)) and !mkdir(dirname($filename), 0777, TRUE))
76 abort("fout bij aanmaken van map voor $filename", '500 save error');
78 if (!file_put_contents($filename, $upload))
79 abort("fout bij schrijven van $filename", '500 save error');
81 if (is_writable('../.git')) {
82 $gitmsg = preg_replace('/\.html$/', '', $filename).": edit from {$_SERVER['REMOTE_ADDR']}";
84 $gitcmd .= ' -c user.name='.escapeshellarg($User['name']);
85 $gitcmd .= ' -c user.email='.escapeshellarg("{$User['name']}@lijtweg.nl");
86 $gitcmd .= ' commit -q';
87 $gitcmd .= ' -m '.escapeshellarg($gitmsg);
88 $gitcmd .= ' -- '.escapeshellarg($filename);
89 exec("$gitcmd 2>&1", $gitlog, $gitstatus);
91 trigger_error("git commit failure $gitstatus: ".implode("\n", $gitlog), E_USER_WARNING);
95 abort("Bestand opgeslagen");