require_once 'cls/clsSetting.php'; require_once 'cls/clsThumbnail.php'; require_once 'cls/clsUser.php'; require_once 'include/messages.php'; session_start(); clsSetting::load_settings(); try { if (!isset($_SESSION['objUser'])) { $objUser = clsUser::getCookie(); } else { $objUser = $_SESSION['objUser']; } $objPicture = new clsPicture(); $objPicture->getFromRequest(array('id')); $objPicture->load(); if ($objPicture->isnew()) { throw new Exception('exception_invalidrequest'); } $objAlbum = new clsAlbum($objPicture->get('album_id')); if (!$objAlbum->canView($objUser)) { throw new Exception('exception_invalidrequest'); } if (isset($_REQUEST['tn']) || isset($_REQUEST['action']) && $_REQUEST['action'] == 'tn') { $intWidth = isset($_REQUEST['w']) ? $_REQUEST['w'] : -1; $intHeight = isset($_REQUEST['h']) ? $_REQUEST['h'] : -1; if (!is_numeric($intWidth) || $intWidth < 0 || $intWidth > MAX_X) { throw new Exception('exception_invalidrequest'); } if (!is_numeric($intHeight) || $intHeight < 0 || $intHeight > MAX_Y) { throw new Exception('exception_invalidrequest'); }