Fix usage of PMA_DBI_get_columns
[phpmyadmin.git] / file_echo.php
blob5e92cb7d1b0924865c4fbabbada1cbedc076eefb
1 <?php
2 /* vim: set expandtab sw=4 ts=4 sts=4: */
3 /**
4 * "Echo" service to allow force downloading of exported charts (png or svg)
5 * and server status monitor settings
7 * @package phpMyAdmin
8 */
10 require_once './libraries/common.inc.php';
12 if (isset($_REQUEST['filename']) && isset($_REQUEST['image'])) {
13 $allowed = array(
14 'image/png' => 'png',
15 'image/svg+xml' => 'svg',
18 /* Check whether MIME type is allowed */
19 if (! isset($allowed[$_REQUEST['type']])) {
20 die('Invalid export type');
24 * Check file name to match mime type and not contain new lines
25 * to prevent response splitting.
27 $extension = $allowed[$_REQUEST['type']];
28 $valid_match = '/^[^\n\r]*\.' . $extension . '$/';
29 if (! preg_match($valid_match, $_REQUEST['filename'])) {
30 if (! preg_match('/^[^\n\r]*$/', $_REQUEST['filename'])) {
31 /* Filename is unsafe, discard it */
32 $filename = 'download.' . $extension;
33 } else {
34 /* Add extension */
35 $filename = $_REQUEST['filename'] . '.' . $extension;
37 } else {
38 /* Filename from request should be safe here */
39 $filename = $_REQUEST['filename'];
42 /* Decode data */
43 if ($extension != 'svg') {
44 $data = substr($_REQUEST['image'], strpos($_REQUEST['image'], ',') + 1);
45 $data = base64_decode($data);
46 } else {
47 $data = $_REQUEST['image'];
50 /* Send download header */
51 PMA_download_header($filename, $_REQUEST['type'], strlen($data));
53 /* Send data */
54 echo $data;
56 } else if (isset($_REQUEST['monitorconfig'])) {
57 PMA_download_header('monitor.cfg', 'application/force-download');
58 echo urldecode($_REQUEST['monitorconfig']);
59 } else if (isset($_REQUEST['import'])) {
60 echo '<html><body>' . file_get_contents($_FILES['file']['tmp_name']) . '</body></html>';