2019-08-21 20:56:46 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
if (!isset($_GET["file_id"])) {
|
|
|
|
header("Location: $URL_BASE");
|
|
|
|
exit();
|
|
|
|
}
|
|
|
|
|
2019-09-06 23:55:10 +00:00
|
|
|
if (!isset($_SESSION["user_id"]))
|
2019-09-07 11:42:36 +00:00
|
|
|
require_once "server_files/403.php";
|
2019-09-06 23:55:10 +00:00
|
|
|
|
2019-08-21 20:56:46 +00:00
|
|
|
$id = htmlspecialchars($_GET["file_id"]);
|
|
|
|
$type = "SOLUTION";
|
|
|
|
|
|
|
|
$req = $DB->query("SELECT * FROM `solutions` WHERE `file_id` = '$id';");
|
|
|
|
if (($data = $req->fetch()) === false) {
|
|
|
|
$req = $DB->query("SELECT * FROM `syntheses` WHERE `file_id` = '$id';");
|
|
|
|
$type = "SYNTHESE";
|
|
|
|
|
|
|
|
if (($data = $req->fetch()) === false) {
|
|
|
|
$req = $DB->query("SELECT * FROM `documents` WHERE `file_id` = '$id';");
|
|
|
|
$type = "DOCUMENT";
|
|
|
|
$data = $req->fetch();
|
|
|
|
}
|
|
|
|
}
|
2019-08-26 14:27:55 +00:00
|
|
|
|
2019-08-21 20:56:46 +00:00
|
|
|
if ($data !== false) {
|
2019-09-06 23:33:05 +00:00
|
|
|
$team = Team::fromId($data["team"]);
|
|
|
|
$tournament = Tournament::fromId($data["tournament"]);
|
|
|
|
$trigram = $team->getTrigram();
|
2019-08-21 20:56:46 +00:00
|
|
|
if ($type == "SOLUTION") {
|
|
|
|
$problem = $data["problem"];
|
|
|
|
$name = "Problème $problem $trigram.pdf";
|
2019-09-06 23:55:10 +00:00
|
|
|
|
|
|
|
if (($_SESSION["role"] == Role::PARTICIPANT || $_SESSION["role"] == Role::ENCADRANT) && (!isset($_SESSION["team"]) || $_SESSION["team"]->getId() != $team->getId()))
|
2019-09-07 11:42:36 +00:00
|
|
|
require_once "server_files/403.php";
|
2019-09-06 23:55:10 +00:00
|
|
|
|
|
|
|
// TODO Seuls les organisateurs concernés doivent pouvoir télécharger les fichiers
|
2019-08-21 20:56:46 +00:00
|
|
|
}
|
|
|
|
else if ($type == "SYNTHESE") {
|
|
|
|
$dest = $data["dest"];
|
|
|
|
$name = "Note de synthèse $trigram pour " . ($dest == "OPPOSANT" ? "l'opposant" : "le rapporteur") . ".pdf";
|
2019-09-06 23:55:10 +00:00
|
|
|
|
|
|
|
// TODO Seuls les organisateurs, défenseurs, opposants et rapporteurs doivent pouvoir télécharger les fichiers
|
2019-08-21 20:56:46 +00:00
|
|
|
}
|
|
|
|
else if ($type == "DOCUMENT") {
|
|
|
|
$user_id = $data["user"];
|
2019-09-06 23:55:10 +00:00
|
|
|
$user = User::fromId($user_id);
|
|
|
|
|
|
|
|
if (($_SESSION["role"] == Role::PARTICIPANT || $_SESSION["role"] == Role::ENCADRANT) && $user_id != $_SESSION["user_id"])
|
2019-09-07 11:42:36 +00:00
|
|
|
require_once "server_files/403.php";
|
2019-09-06 23:55:10 +00:00
|
|
|
|
|
|
|
// TODO Seuls les organisateurs concernés doivent pouvoir télécharger les fichiers
|
|
|
|
|
|
|
|
$surname = $user->getSurname();
|
|
|
|
$first_name = $user->getFirstName();
|
2019-08-21 20:56:46 +00:00
|
|
|
switch ($data["type"]) {
|
|
|
|
case "PARENTAL_CONSENT":
|
|
|
|
$name = "Autorisation parentale";
|
|
|
|
break;
|
|
|
|
case "PHOTO_CONSENT":
|
|
|
|
$name = "Autorisation de droit à l'image";
|
|
|
|
break;
|
|
|
|
case "SANITARY_PLUG":
|
|
|
|
$name = "Fiche sanitaire";
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
$name .= " de $first_name $surname.pdf";
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else {
|
2019-09-07 11:42:36 +00:00
|
|
|
require_once "server_files/404.php";
|
2019-08-21 20:56:46 +00:00
|
|
|
http_response_code(404);
|
|
|
|
exit();
|
|
|
|
}
|
|
|
|
|
|
|
|
header("Content-Type: application/pdf");
|
|
|
|
header("Content-Disposition: inline; filename=\"$name\"");
|
|
|
|
|
|
|
|
readfile("$URL_BASE/files/$id");
|
|
|
|
|
|
|
|
exit();
|