PHP script downloads PDFs but not images (PNG/JPG) from files located outside the root - Hack The Tech - Latest News related to Computer and Technology

Hack The Tech - Latest News related to Computer and Technology

Get Daily Latest News related to Computer and Technology and hack the world.

Tuesday, May 16, 2023

PHP script downloads PDFs but not images (PNG/JPG) from files located outside the root

My PHP script has difficulty downloading PNG and JPG images from a folder (outside of the root), resulting in corrupted files. PDF files, on the other hand, can be downloaded without issues. I have confirmed that the files exist, have the correct MIME types (image/png and image/jpeg), and are not empty (file size not empty).

The files also exist in the uploads folder, and I can open them with preview tools, etc., so the file in the server works as intended, and I suspect I set my headers wrong.

The file download gets triggered when the file is clicked that starts a page load with GET parameters (I'm using a front controller)

container.addEventListener('click', () => {

    // ... Get the user id and file name ...

    // Construct the URL to the PHP script that gets the correct file
    const open = `/view/?user=${user}&file=${file}&open=true`;

    // Open in a new page (used for inline, not attachments)
    window.open(open, '_blank');
});

My view file:

// Make sure the user is authenticated...

// If download, user, and file parameters are set, download the file:
if(isset($_GET['open']) && isset($_GET['user']) && isset($_GET['file'])){
    if(!Files::open($_GET['file'], $_GET['user'])){
        Report::error("Error");
    }

    Report::success("Success");
    exit();
}

My Files::open() function:

/**
 * Open a requested file.
 * 
 * @param string $file
 * The file to open.
 * 
 * @param string $folder
 * The folder where the file is located.
 * 
 * @return bool
 * True if the file was opened successfully, false otherwise.
 */
public static function open(string $file, string $folder = ''): bool {

    // Path to the file, this currently only picks
    // files from the uploads folder:
    $path = dirname(__DIR__, 2) . "/uploads/$folder/$file";
    Report::notice("Opening the file '$file' from the '$folder' folder.");

    // If the file does not exist, return false:
    if (!file_exists($path)) {
        Report::warning("The file '$file' does not exist in the '$folder' folder.");
        return false;
    }

    // Create a new Fileinfo object:
    $finfo = new finfo(FILEINFO_MIME_TYPE);

    // Get the mime type:
    $mime = $finfo->file($path);

    // Get the mime type:
    Report::notice("The mime type of the file '$file' is '$mime'.");

    // Set the headers (usually inline, attachment for testing):
    header("Content-Type: $mime");
    header("Content-Disposition: attachment; filename=$file");
    header("Content-Length: " . filesize($path));

    // Read the file
    readfile($path);

    // Return true:
    return true;
}

Any ideas about what could be causing the issue?



source https://stackoverflow.com/questions/76209097/php-script-downloads-pdfs-but-not-images-png-jpg-from-files-located-outside-th

No comments:

Post a Comment