diff options
author | Philip Häusler <msquare@notrademark.de> | 2011-06-11 17:09:30 +0200 |
---|---|---|
committer | Philip Häusler <msquare@notrademark.de> | 2011-06-11 17:09:30 +0200 |
commit | 3a31cebd1d39a6bcec2c22cbced60ca9d6177a42 (patch) | |
tree | 3cce86da26c408841e69bdee4e2ba012e0c72e47 /www-ssl/ShowUserPicture.php | |
parent | ebecae2ccc37c8930245a562852c035d5ce8d5a1 (diff) | |
parent | 80a1a65aefcd2f33951dc60c72d29df1ad19b187 (diff) |
merge special_includes_camp
Diffstat (limited to 'www-ssl/ShowUserPicture.php')
-rw-r--r-- | www-ssl/ShowUserPicture.php | 86 |
1 files changed, 42 insertions, 44 deletions
diff --git a/www-ssl/ShowUserPicture.php b/www-ssl/ShowUserPicture.php index 0b61d153..5a222c07 100644 --- a/www-ssl/ShowUserPicture.php +++ b/www-ssl/ShowUserPicture.php @@ -1,58 +1,56 @@ -<?PHP +<?php +// Momentan keine Avatar-Funktionen +die(); -include ("../includes/config.php"); -include ("../includes/error_handler.php"); -include ("../includes/config_db.php"); -if( !isset($_SESSION)) session_start(); -include ("../includes/secure.php"); +require_once ('bootstrap.php'); +include "config/config.php"; +include "includes/error_handler.php"; +include "config/config_db.php"; + +if (!isset ($_SESSION)) + session_start(); + +include "includes/secure.php"; // Parameter check -if( !isset($_GET["UID"]) ) - $_GET["UID"]= "-1"; - -$SQL= "SELECT * FROM `UserPicture` WHERE `UID`='". $_GET["UID"]. "'"; -$res = mysql_query( $SQL, $con); - -if( mysql_num_rows($res) == 1) -{ - //genügend rechte - if( !isset($_SESSION['UID']) || $_SESSION['UID'] == -1) - { - header( "HTTP/1.0 403 Forbidden"); - die( "403 Forbidden"); +if (!isset ($_GET["UID"])) + $_GET["UID"] = "-1"; + +$SQL = "SELECT * FROM `UserPicture` WHERE `UID`='" . $_GET["UID"] . "'"; +$res = mysql_query($SQL, $con); + +if (mysql_num_rows($res) == 1) { + // genuegend rechte + if (!isset ($_SESSION['UID']) || $_SESSION['UID'] == -1) { + header("HTTP/1.0 403 Forbidden"); + die("403 Forbidden"); } - + // ist das bild sichtbar? - if( (mysql_result($res, 0, "show")=="N") AND - ($_SESSION['UID']!=$_GET["UID"]) AND - ($_SESSION['CVS'][ "admin/UserPicture.php" ] == "N")) - { - $SQL= "SELECT * FROM `UserPicture` WHERE `UID`='-1'"; - $res = mysql_query( $SQL, $con); - if( mysql_num_rows($res) != 1) - { - header( 'HTTP/1.0 404 Not Found'); - die( "404 Not Found"); + if ((mysql_result($res, 0, "show") == "N") AND ($_SESSION['UID'] != $_GET["UID"]) AND ($_SESSION['CVS']["admin/UserPicture.php"] == "N")) { + $SQL = "SELECT * FROM `UserPicture` WHERE `UID`='-1'"; + $res = mysql_query($SQL, $con); + + if (mysql_num_rows($res) != 1) { + header("HTTP/1.0 404 Not Found"); + die("404 Not Found"); } } - /// bild aus db auslesen + // bild aus db auslesen $bild = mysql_result($res, 0, "Bild"); - + // ausgabe bild - header( "Accept-Ranges: bytes"); - header( "Content-Length: ". strlen($bild)); - header( "Content-type: ". mysql_result($res, 0, "ContentType")); - header( "Cache-control: public"); - header( "Cache-request-directive: min-fresh = 120"); - header( "Cache-request-directive: max-age = 360"); + header("Accept-Ranges: bytes"); + header("Content-Length: " . strlen($bild)); + header("Content-type: " . mysql_result($res, 0, "ContentType")); + header("Cache-control: public"); + header("Cache-request-directive: min-fresh = 120"); + header("Cache-request-directive: max-age = 360"); echo $bild; +} else { + header("HTTP/1.0 404 Not Found"); + die("404 Not Found"); } -else -{ - header( 'HTTP/1.0 404 Not Found'); - die( "404 Not Found"); -} - ?> |