forked from PrestaShop/PrestaShop
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathbackup.php
110 lines (95 loc) · 3.34 KB
/
backup.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
<?php
/**
* 2007-2018 PrestaShop
*
* NOTICE OF LICENSE
*
* This source file is subject to the Open Software License (OSL 3.0)
* that is bundled with this package in the file LICENSE.txt.
* It is also available through the world-wide-web at this URL:
* https://opensource.org/licenses/OSL-3.0
* If you did not receive a copy of the license and are unable to
* obtain it through the world-wide-web, please send an email
* to license@prestashop.com so we can send you a copy immediately.
*
* DISCLAIMER
*
* Do not edit or add to this file if you wish to upgrade PrestaShop to newer
* versions in the future. If you wish to customize PrestaShop for your
* needs please refer to http://www.prestashop.com for more information.
*
* @author PrestaShop SA <contact@prestashop.com>
* @copyright 2007-2018 PrestaShop SA
* @license https://opensource.org/licenses/OSL-3.0 Open Software License (OSL 3.0)
* International Registered Trademark & Property of PrestaShop SA
*/
if (!defined('_PS_ADMIN_DIR_')) {
define('_PS_ADMIN_DIR_', getcwd());
}
include(_PS_ADMIN_DIR_.'/../config/config.inc.php');
if (!Context::getContext()->employee->isLoggedBack()) {
Tools::redirectAdmin(Context::getContext()->link->getAdminLink('AdminLogin'));
}
$tabAccess = Profile::getProfileAccess(
Context::getContext()->employee->id_profile,
Tab::getIdFromClassName('AdminBackup')
);
if ($tabAccess['view'] !== '1') {
die(Context::getContext()->getTranslator()->trans(
'You do not have permission to view this.',
array(),
'Admin.Advparameters.Notification'
));
}
$backupdir = realpath(PrestaShopBackup::getBackupPath());
if ($backupdir === false) {
die(Context::getContext()->getTranslator()->trans(
'There is no "/backup" directory.',
array(),
'Admin.Advparameters.Notification'
));
}
if (!$backupfile = Tools::getValue('filename')) {
die(Context::getContext()->getTranslator()->trans(
'No file has been specified.',
array(),
'Admin.Advparameters.Notification'
));
}
// Check the realpath so we can validate the backup file is under the backup directory
$backupfile = realpath($backupdir.DIRECTORY_SEPARATOR.$backupfile);
if ($backupfile === false || strncmp($backupdir, $backupfile, strlen($backupdir)) != 0) {
die(Tools::dieOrLog('The backup file does not exist.'));
}
if (substr($backupfile, -4) == '.bz2') {
$contentType = 'application/x-bzip2';
} elseif (substr($backupfile, -3) == '.gz') {
$contentType = 'application/x-gzip';
} else {
$contentType = 'text/x-sql';
}
$fp = @fopen($backupfile, 'r');
if ($fp === false) {
die(Context::getContext()->getTranslator()->trans(
'Unable to open backup file(s).',
array(),
'Admin.Advparameters.Notification'
).' "'.addslashes($backupfile).'"'
);
}
// Add the correct headers, this forces the file is saved
header('Content-Type: '.$contentType);
header('Content-Disposition: attachment; filename="'.Tools::getValue('filename'). '"');
if (ob_get_level() && ob_get_length() > 0) {
ob_clean();
}
$ret = @fpassthru($fp);
fclose($fp);
if ($ret === false) {
die(Context::getContext()->getTranslator()->trans(
'Unable to display backup file(s).',
array(),
'Admin.Advparameters.Notification'
).' "'.addslashes($backupfile).'"'
);
}