Exemplo n.º 1
0
/**
 * Handle uploaded plugin
 *
 * @return   string      HTML: redirect or main plugin screen + error message
 */
function plugin_upload()
{
    global $_CONF, $_TABLES;
    $retval = '';
    $path_admin = $_CONF['path_html'] . substr($_CONF['site_admin_url'], strlen($_CONF['site_url']) + 1) . '/';
    $upload_success = false;
    // If an error occured while uploading the file.
    $error_msg = plugin_getUploadError($_FILES['plugin']);
    if (!empty($error_msg)) {
        $retval .= plugin_main($error_msg);
    } else {
        $plugin_file = $_CONF['path_data'] . $_FILES['plugin']['name'];
        // Name the plugin file
        $archive = new Unpacker($_FILES['plugin']['tmp_name'], $_FILES['plugin']['type']);
        $tmp = $archive->getList();
        // Grab the contents of the tarball to see what the plugin name is
        $dirName = preg_replace('/\\/.*$/', '', $tmp[0]['filename']);
        if (empty($dirName)) {
            // If $dirname is blank it's probably because the user uploaded a non Tarball file.
            COM_redirect($_CONF['site_admin_url'] . '/plugins.php?msg=100');
        } else {
            $pi_did_exist = false;
            // plugin directory already existed
            $pi_had_entry = false;
            // plugin had an entry in the database
            $pi_was_enabled = false;
            // plugin was enabled
            if (file_exists($_CONF['path'] . 'plugins/' . $dirName)) {
                $pi_did_exist = true;
                // plugin directory already exists
                $pstatus = DB_query("SELECT pi_name, pi_enabled FROM {$_TABLES['plugins']} WHERE pi_name = '{$dirName}'");
                $A = DB_fetchArray($pstatus);
                if (isset($A['pi_name'])) {
                    $pi_had_entry = true;
                    $pi_was_enabled = $A['pi_enabled'] == 1;
                }
                $callback = 'plugin_enablestatechange_' . $dirName;
                if ($pi_was_enabled) {
                    // disable temporarily while we move the files around
                    if (is_callable($callback)) {
                        changePluginStatus($dirName);
                    } else {
                        DB_change($_TABLES['plugins'], 'pi_enabled', 0, 'pi_name', $dirName);
                    }
                }
                $plugin_dir = $_CONF['path'] . 'plugins/' . $dirName;
                if (file_exists($plugin_dir . '.previous')) {
                    Geeklog\FileSystem::remove($plugin_dir . '.previous');
                }
                if (file_exists($plugin_dir)) {
                    rename($plugin_dir, $plugin_dir . '.previous');
                }
                $public_dir = $_CONF['path_html'] . $dirName;
                if (file_exists($public_dir . '.previous')) {
                    Geeklog\FileSystem::remove($public_dir . '.previous');
                }
                if (file_exists($public_dir)) {
                    rename($public_dir, $public_dir . '.previous');
                }
                $admin_dir = $path_admin . 'plugins/' . $dirName;
                if (file_exists($admin_dir . '.previous')) {
                    Geeklog\FileSystem::remove($admin_dir . '.previous');
                }
                if (file_exists($admin_dir)) {
                    rename($admin_dir, $admin_dir . '.previous');
                }
            }
            /**
             * Install the plugin
             * This doesn't work if the public_html & public_html/admin/plugins directories aren't 777
             */
            // Extract the tarball to data so we can get the $pi_name name from admin/install.php
            $archive->unpack($_CONF['path'] . 'data/', array($dirName . '/admin/install.php'));
            $plugin_inst = $_CONF['path'] . 'data/' . $dirName . '/admin/install.php';
            $fileData = @file_get_contents($plugin_inst);
            /*
                        // Remove the plugin from data/
                        Geeklog\FileSystem::remove($_CONF['path'] . 'data/' . $dirname);
            */
            // Some plugins seem to expect files under the data directory to
            // be unchanged while they are disabled.  Let's leave the files untouched.
            /**
             * One time I wanted to install a muffler on my car and
             * needed to match up the outside diameter of the car's
             * exhaust pipe to the inside diameter of the muffler.
             * Unfortunately, when I went to the auto parts store they
             * didn't have a coupling adapter that would perfectly
             * match the two pipes, only a bunch of smaller adapters.
             * I ended up using about 4 small adapters to step down
             * one size at a time to the size of the muffler's input.
             * It's kind of like this regular expression:
             */
            $fileData = str_replace(array("\n", ' '), '', $fileData);
            $pi_name = preg_replace('/^.*\\$pi\\_name=\'/', '', $fileData);
            $pi_name = preg_replace('/\'.*$/', '', $pi_name);
            // Some plugins don't have $pi_name set in their install.php file,
            // This means our regex won't work and we should just use $dirname
            if (empty($pi_name) || preg_match('/\\<\\?php/', $pi_name) || preg_match('/--/', $pi_name)) {
                $pi_name = $dirName;
            }
            // Extract the uploaded archive to the plugins directory
            $upload_success = $archive->unpack($_CONF['path'] . 'plugins/');
            $plg_path = $_CONF['path'] . 'plugins/' . $pi_name . '/';
            if ($upload_success) {
                if (file_exists($plg_path . 'public_html')) {
                    rename($plg_path . 'public_html', $_CONF['path_html'] . $pi_name);
                }
                if (file_exists($plg_path . 'admin')) {
                    rename($plg_path . 'admin', $path_admin . 'plugins/' . $pi_name);
                }
            }
            unset($archive);
            // Collect some garbage
            // cleanup when uploading a new version
            if ($pi_did_exist) {
                $plugin_dir = $_CONF['path'] . 'plugins/' . $dirName;
                if (file_exists($plugin_dir . '.previous')) {
                    Geeklog\FileSystem::remove($plugin_dir . '.previous');
                }
                $public_dir = $_CONF['path_html'] . $dirName;
                if (file_exists($public_dir . '.previous')) {
                    Geeklog\FileSystem::remove($public_dir . '.previous');
                }
                $admin_dir = $path_admin . 'plugins/' . $dirName;
                if (file_exists($admin_dir . '.previous')) {
                    Geeklog\FileSystem::remove($admin_dir . '.previous');
                }
                if ($pi_was_enabled) {
                    // Enable the plugin again
                    if (is_callable($callback)) {
                        changePluginStatus($dirName);
                    } else {
                        DB_change($_TABLES['plugins'], 'pi_enabled', 1, 'pi_name', $dirName);
                    }
                }
            }
            $msg_with_plugin_name = false;
            if ($pi_did_exist) {
                if ($pi_was_enabled) {
                    // check if we have to perform an update
                    $pi_version = DB_getItem($_TABLES['plugins'], 'pi_version', "pi_name = '{$dirName}'");
                    $code_version = PLG_chkVersion($dirName);
                    if (!empty($code_version) && $code_version != $pi_version) {
                        /**
                         * At this point, we would have to call PLG_upgrade().
                         * However, we've loaded the plugin's old functions.inc
                         * (in lib-common.php). We can't load the new one here
                         * now since that would result in duplicate function
                         * definitions. Solution: Trigger a reload (with the new
                         * functions.inc) and continue there.
                         */
                        $url = $_CONF['site_admin_url'] . '/plugins.php' . '?mode=continue_upgrade' . '&amp;codeversion=' . urlencode($code_version) . '&amp;piversion=' . urlencode($pi_version) . '&amp;plugin=' . urlencode($dirName);
                        COM_redirect($url);
                    } else {
                        $msg = 98;
                        // successfully uploaded
                    }
                } else {
                    $msg = 98;
                    // successfully uploaded
                }
            } elseif (file_exists($plg_path . 'autoinstall.php')) {
                // if the plugin has an autoinstall.php, install it now
                if (plugin_autoinstall($pi_name)) {
                    PLG_pluginStateChange($pi_name, 'installed');
                    $msg = 44;
                    // successfully installed
                } else {
                    $msg = 72;
                    // an error occured while installing the plugin
                }
            } else {
                $msg = 98;
                // successfully uploaded
            }
            $url = $_CONF['site_admin_url'] . '/plugins.php?msg=' . $msg;
            if ($msg_with_plugin_name) {
                $url .= '&amp;plugin=' . $dirName;
            }
            COM_redirect($url);
        }
    }
    return $retval;
}
Exemplo n.º 2
0
/**
 * Unpack a db backup file, if necessary
 * Note: This requires a minimal PEAR setup (incl. Tar and Zip classes) and a
 *       way to set the PEAR include path. But if that doesn't work on your
 *       setup, then chances are you won't get Geeklog up and running anyway ...
 *
 * @param    string $backupPath path to the "backups" directory
 * @param    string $backupFile backup file name
 * @param    string $display    reference to HTML string (for error msg)
 * @return   mixed                  file name of unpacked file or false: error
 */
function INST_unpackFile($backupPath, $backupFile, &$display)
{
    global $_CONF, $LANG_MIGRATE;
    if (!preg_match('/\\.(zip|tar\\.gz|tgz)$/i', $backupFile)) {
        // not packed
        return $backupFile;
    }
    require_once $_CONF['path'] . 'systems/classes/Autoload.php';
    Geeklog\Autoload::initialize();
    $archive = new Unpacker($backupPath . $backupFile);
    // we're going to extract the first .sql file we find in the archive
    $dirName = '';
    $foundSqlFile = false;
    $files = $archive->getList();
    foreach ($files as $file) {
        if (!isset($file['folder']) || !$file['folder']) {
            if (preg_match('/\\.sql$/', $file['filename'])) {
                $dirName = preg_replace('/\\/.*$/', '', $file['filename']);
                $foundSqlFile = true;
                break;
            }
        }
    }
    if (!$foundSqlFile) {
        // no .sql file found in archive
        $display .= INST_getAlertMsg(sprintf($LANG_MIGRATE[40], $backupFile));
        return false;
    }
    if (isset($file) && $dirName === $file['filename']) {
        $dirName = '';
        // no directory
    }
    if (empty($dirName)) {
        $unpacked_file = $file['filename'];
    } else {
        $unpacked_file = substr($file['filename'], strlen($dirName) + 1);
    }
    $success = $archive->unpack($backupPath, array($file['filename']));
    if (!$success || !file_exists($backupPath . $unpacked_file)) {
        // error unpacking file
        $display .= INST_getAlertMsg(sprintf($LANG_MIGRATE[41], $unpacked_file));
        return false;
    }
    unset($archive);
    return $unpacked_file;
}
Exemplo n.º 3
0
  */
 case 1:
     // If 'file_uploads' is enabled in php.ini and the plugin directories are writable by the web server.
     $upload_enabled = ini_get('file_uploads') && is_writable($_CONF['path'] . 'plugins/') && is_writable($_CONF['path_html']) && is_writable($installer->getAdminPath() . 'plugins/');
     $display .= '<p>' . $LANG_PLUGINS[3] . ($upload_enabled ? ' ' . $LANG_PLUGINS[4] : '') . '</p>' . PHP_EOL;
     // Check if a plugin file was uploaded
     $upload_success = false;
     if (isset($_FILES['plugin'])) {
         if ($error_msg = $installer->getUploadError($_FILES['plugin'])) {
             // If an error occured while uploading the file.
             $display .= '<div class="notice"><span class="error">' . $LANG_INSTALL[38] . '</span> ' . $error_msg . '</div>' . PHP_EOL;
         } else {
             $plugin_file = $_CONF['path_data'] . $_FILES['plugin']['name'];
             // Name the plugin file
             $archive = new Unpacker($_CONF['path_data'] . $_FILES['plugin']['name'], $_FILES['plugin']['type']);
             $contents = $archive->getList();
             $dirName = preg_replace('/\\/.*$/', '', $contents[0]['filename']);
             if (empty($dirName)) {
                 // If $dirname is blank it's probably because the user uploaded a non Tarball file.
                 $display .= '<div class="notice"><span class="error">' . $LANG_INSTALL[38] . '</span> ' . $LANG_PLUGINS[5] . '</div>' . PHP_EOL;
             } elseif (file_exists($_CONF['path'] . 'plugins/' . $dirName)) {
                 // If plugin directory already exists
                 $display .= '<div class="notice"><span class="error">' . $LANG_INSTALL[38] . '</span> ' . $LANG_PLUGINS[6] . '</div>' . PHP_EOL;
             } else {
                 /**
                  * Install the plugin
                  * This doesn't work if the public_html & public_html/admin/plugins directories aren't 777
                  */
                 // Extract the archive to data so we can get the $pi_name name from admin/install.php
                 $archive->unpack($_CONF['path'] . 'data/', array($dirName . '/admin/install.php'));
                 $plugin_inst = $_CONF['path'] . 'data/' . $dirName . '/admin/install.php';