. /** * This page is used to fetch files while in maintenance mode. * * It should avoid as much as possible using code Moodle API. * * @package auth_outage * @author Daniel Thee Roperto * @copyright 2016 Catalyst IT * @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later * * @var stdClass $CFG */ // This file does not use Moodle initialization as a requirement. Supress Warning. define('MOODLE_INTERNAL', true); defined('MOODLE_INTERNAL') || die(); // File should have at least 3 characters as we will check the extension below. if (!isset($_GET['file'])) { http_response_code(400); die('Missing file parameter.'); } $rawfile = $_GET['file']; if (!preg_match('/^[a-zA-Z0-9_\-\.\/]+$/', $rawfile)) { http_response_code(400); die('Invalid file parameter.'); } $parts = explode('.', $rawfile); if (count($parts) != 2) { http_response_code(400); die('Invalid file requested.'); } $extension = strtolower(pathinfo($parts[0], PATHINFO_EXTENSION)); $allowedmimes = [ 'css' => 'text/css', 'png' => 'image/png', 'jpg' => 'image/jpeg', 'jpeg' => 'image/jpeg', 'gif' => 'image/gif', ]; if (!array_key_exists($extension, $allowedmimes)) { http_response_code(400); die('Unsupported file type.'); } $mime = $allowedmimes[$extension]; header('Content-Type: ' . $mime); // Use cache. $lifetime = 60 * 60 * 24; // 1 day. header('Expires: ' . gmdate('D, d M Y H:i:s', time() + $lifetime) . ' GMT'); header('Pragma: '); header('Cache-Control: public, max-age=' . $lifetime); header('Accept-Ranges: none'); /** * Callback used in bootstrap. */ function auth_outage_bootstrap_callback() { // Not using classes as classloader has not been initialized yet. Keep it minimalist. require_once(__DIR__ . '/lib.php'); $file = auth_outage_get_climaintenance_resource_file($_GET['file']); if (is_null($file)) { // @codingStandardsIgnoreStart error_log('Invalid file: '.$_GET['file']); // @codingStandardsIgnoreEnd http_response_code(404); die('File not found.'); } // Ensure there is nothing in the output buffer. // otherwise the file will not be read correctly. ob_clean(); readfile($file); exit(0); } // @codingStandardsIgnoreStart require_once(__DIR__.'/../../config.php'); // @codingStandardsIgnoreEnd // We should never reach here if config.php and auth/outage/bootstrap.php intercepted it correctly. // If config.php did not execute the callback function we can use the debugging function here. debugging('Your config.php is not properly configured for auth/outage plugin. ' . 'Please check the plugin settings for information.');