summaryrefslogtreecommitdiff
path: root/img_auth.php
diff options
context:
space:
mode:
Diffstat (limited to 'img_auth.php')
-rw-r--r--img_auth.php7
1 files changed, 7 insertions, 0 deletions
diff --git a/img_auth.php b/img_auth.php
index cfe005e9..8794bc78 100644
--- a/img_auth.php
+++ b/img_auth.php
@@ -12,31 +12,38 @@ wfProfileIn( 'img_auth.php' );
require_once( './includes/StreamFile.php' );
if( !isset( $_SERVER['PATH_INFO'] ) ) {
+ wfDebugLog( 'img_auth', "missing PATH_INFO" );
wfForbidden();
}
# Get filenames/directories
+wfDebugLog( 'img_auth', "PATH_INFO is: " . $_SERVER['PATH_INFO'] );
$filename = realpath( $wgUploadDirectory . $_SERVER['PATH_INFO'] );
$realUploadDirectory = realpath( $wgUploadDirectory );
$imageName = $wgContLang->getNsText( NS_IMAGE ) . ":" . wfBaseName( $_SERVER['PATH_INFO'] );
# Check if the filename is in the correct directory
if ( substr( $filename, 0, strlen( $realUploadDirectory ) ) != $realUploadDirectory ) {
+ wfDebugLog( 'img_auth', "requested path not in upload dir: $filename" );
wfForbidden();
}
if ( is_array( $wgWhitelistRead ) && !in_array( $imageName, $wgWhitelistRead ) && !$wgUser->getID() ) {
+ wfDebugLog( 'img_auth', "not logged in and requested file not in whitelist: $imageName" );
wfForbidden();
}
if( !file_exists( $filename ) ) {
+ wfDebugLog( 'img_auth', "requested file does not exist: $filename" );
wfForbidden();
}
if( is_dir( $filename ) ) {
+ wfDebugLog( 'img_auth', "requested file is a directory: $filename" );
wfForbidden();
}
# Write file
+wfDebugLog( 'img_auth', "streaming file: $filename" );
wfStreamFile( $filename );
wfLogProfilingData();