Play images and video from Synology PhotoStation server

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775
  1. <?php
  2. require_once('shared_album.inc.php');
  3. require_once('photoutil.php');
  4. class SharedAlbumAPI extends WebAPI
  5. {
  6. private $TableName, $PhotoTableName, $VideoTableName, $UserID;
  7. private $allowSortByArray = array('filename' => 'upper(name)', 'share_status' => 'share_status', 'createdate' => 'create_date');
  8. function __construct()
  9. {
  10. parent::__construct(SZ_WEBAPI_API_DESCRIPTION_PATH);
  11. }
  12. protected function Process()
  13. {
  14. if (!strcasecmp($this->method, "getinfo_public")) {
  15. $this->GetInfoPublic();
  16. return;
  17. }
  18. csSYNOPhotoDB::GetDBInstance()->SetSessionCache();
  19. csSYNOPhotoMisc::CheckSessionTimeOut(true);
  20. $this->UserID = isset($_SESSION[SYNOPHOTO_ADMIN_USER]['reg_syno_userid']) ? $_SESSION[SYNOPHOTO_ADMIN_USER]['reg_syno_userid'] : 0;
  21. if ($this->UserID === 0) {
  22. $this->TableName = SHARED_ALBUM_ADMIN_TABLE_NAME;
  23. $this->PhotoTableName = SHARED_ALBUM_PHOTO_ADMIN_TABLE_NAME;
  24. $this->VideoTableName = SHARED_ALBUM_VIDEO_ADMIN_TABLE_NAME;
  25. } else {
  26. $this->TableName = SHARED_ALBUM_TABLE_NAME;
  27. $this->PhotoTableName = SHARED_ALBUM_PHOTO_TABLE_NAME;
  28. $this->VideoTableName = SHARED_ALBUM_VIDEO_TABLE_NAME;
  29. }
  30. if (!strcasecmp($this->method, "list")) {
  31. $this->SharedAlbumList();
  32. } else if (!strcasecmp($this->method, "getinfo")) {
  33. $this->GetInfo();
  34. } else if (!strcasecmp($this->method, "create")) {
  35. $this->Create();
  36. } else if (!strcasecmp($this->method, "edit")) {
  37. $this->Edit();
  38. } else if (!strcasecmp($this->method, "delete")) {
  39. $this->Delete();
  40. } else if (!strcasecmp($this->method, "add_items")) {
  41. $this->AddItems();
  42. } else if (!strcasecmp($this->method, "remove_items")) {
  43. $this->RemoveItems();
  44. } else if (!strcasecmp($this->method, "edit_public_share")) {
  45. $this->EditPublicShare();
  46. } else if (!strcasecmp($this->method, "get_single_item")) {
  47. $this->GetSingleItem();
  48. } else if (!strcasecmp($this->method, "set_single_item")) {
  49. $this->SetSingleItem();
  50. }
  51. }
  52. private function SharedAlbumList()
  53. {
  54. $ret = false;
  55. if (!isset($_REQUEST['offset']) || !isset($_REQUEST['limit']) || !is_numeric($_REQUEST['offset']) || !is_numeric($_REQUEST['limit'])) {
  56. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  57. goto End;
  58. }
  59. $offset = $_REQUEST['offset'] + 0;
  60. $limit = $_REQUEST['limit'] + 0;
  61. $sortBy = $this->allowSortByArray['filename'];
  62. $sortDirection = 'ASC';
  63. $additional = array();
  64. if (isset($_REQUEST['sort_by']) && array_key_exists($_REQUEST['sort_by'], $this->allowSortByArray)) {
  65. $sortBy = $this->allowSortByArray[$_REQUEST['sort_by']];
  66. }
  67. if (isset($_REQUEST['sort_direction']) && strtolower($_REQUEST['sort_direction']) === 'desc') {
  68. $sortDirection = 'DESC';
  69. }
  70. if (isset($_REQUEST['additional'])) {
  71. $additional = explode(",", $_REQUEST['additional']);
  72. }
  73. $query = "SELECT COUNT(*) FROM " . $this->TableName . " WHERE hidden = 'f' AND ";
  74. $sqlParams = array();
  75. $this->appendUserIDCond($query, $sqlParams);
  76. $db_result = PHOTO_DB_Query($query, $sqlParams);
  77. $row = PHOTO_DB_FetchRow($db_result);
  78. $total = intval($row[0]) + 1; // 1 is sharedalbum_single
  79. $query = "SELECT id FROM " . $this->TableName . " WHERE hidden = 'f' AND ";
  80. $sqlParams = array();
  81. $this->appendUserIDCond($query, $sqlParams);
  82. // we will add sharedalbum_single in this method,
  83. // so regulate the offset/limit to get correct shared_album information
  84. if ($offset === 0) {
  85. $shared_limit = $limit -1;
  86. $shared_offset = 0;
  87. } else {
  88. $shared_limit = $limit;
  89. $shared_offset = $offset - 1;
  90. }
  91. $limitOffsetString = PHOTO_DB_GetLimitOffsetString($shared_limit, $shared_offset);
  92. if ('share_status' === $sortBy) {
  93. $currentDate = 'root' === SYNOPHOTO_ADMIN_USER ? 'current_date' : "date('now')";
  94. $query .= "ORDER BY CASE " .
  95. "WHEN is_shared = 'f' THEN 0 " . // none
  96. "WHEN start_time IS NULL OR end_time IS NULL THEN 2 ". // valid
  97. "WHEN start_time > $currentDate OR end_time < $currentDate THEN 1 ". // invalid
  98. "ELSE 2 ". // valid
  99. "END $sortDirection, upper(name) ASC";
  100. } else {
  101. $query .= "ORDER BY $sortBy $sortDirection";
  102. }
  103. $query .= " $limitOffsetString";
  104. $db_result = PHOTO_DB_Query($query, $sqlParams);
  105. $result['items'] = array();
  106. $i = 0;
  107. if ((int)$offset === 0) {
  108. $sharedAlbum = SharedAlbum::GetHiddenAlbumInfo(NULL, $additional);
  109. if ($sharedAlbum !== NULL) {
  110. $sharedAlbum = $this->GetInfoById(explode("_", $sharedAlbum['id'])[1], $additional);
  111. }
  112. if ($sharedAlbum !== NULL) {
  113. $sharedAlbum['id'] = 'sharedalbum_single';
  114. if (isset($sharedAlbum['additional']['public_share']['public_share_url'])) {
  115. unset($sharedAlbum['additional']['public_share']['public_share_url']);
  116. }
  117. $result['items'][$i] = $sharedAlbum;
  118. $i ++;
  119. }
  120. }
  121. while(($idRow = PHOTO_DB_FetchRow($db_result))) {
  122. $sharedAlbum = $this->GetInfoById($idRow[0], $additional);
  123. if (NULL === $sharedAlbum) {
  124. continue;
  125. }
  126. $result['items'][$i] = $sharedAlbum;
  127. $i ++;
  128. }
  129. $result['total'] = $total;
  130. $result['offset'] = (-1 == $limit || $offset + $limit > $total) ? $total : $offset + $limit;
  131. $this->SetResponse($result);
  132. $ret = true;
  133. End:
  134. return $ret;
  135. }
  136. private function GetInfo()
  137. {
  138. $ret = false;
  139. if (!isset($_REQUEST['id'])) {
  140. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  141. goto End;
  142. }
  143. $additional = array();
  144. if (isset($_REQUEST['additional'])) {
  145. $additional = explode(',', $_REQUEST['additional']);
  146. }
  147. $ids = explode(',', $_REQUEST['id']);
  148. $result['shared_albums'] = array();
  149. $success_count = 0;
  150. foreach ($ids as $id) {
  151. $id_arr = explode("_", $id);
  152. if (2 !== count($id_arr) || 'sharedalbum' != $id_arr[0]) {
  153. continue;
  154. }
  155. if ($id_arr[1] === 'single') {
  156. $sharedAlbum = SharedAlbum::GetHiddenAlbumInfo(NULL, $additional);
  157. $sharedAlbum['id'] = 'sharedalbum_single';
  158. if (isset($sharedAlbum['additional']['public_share']['public_share_url'])) {
  159. unset($sharedAlbum['additional']['public_share']['public_share_url']);
  160. }
  161. $result['shared_albums'][] = $sharedAlbum;
  162. $success_count ++;
  163. continue;
  164. }
  165. $sharedAlbumId = $id_arr[1];
  166. if (FALSE === $this->CheckExistenceById($sharedAlbumId)) {
  167. continue;
  168. }
  169. $sharedAlbum = $this->GetInfoById($sharedAlbumId, $additional);
  170. if (NULL === $sharedAlbum) {
  171. continue;
  172. }
  173. $result['shared_albums'][] = $sharedAlbum;
  174. $success_count ++;
  175. }
  176. if ($success_count === 0) {
  177. $this->SetError(PHOTOSTATION_SHARED_ALBUM_GET_INFO_ERROR);
  178. goto End;
  179. }
  180. $this->SetResponse($result);
  181. $ret = true;
  182. End:
  183. return $ret;
  184. }
  185. private function Create()
  186. {
  187. $ret = false;
  188. if (!isset($_REQUEST['name'])) {
  189. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  190. goto End;
  191. }
  192. $name = $_REQUEST['name'];
  193. $itemIds = array();
  194. if (isset($_REQUEST['item_id'])) {
  195. $itemIds = explode(",", $_REQUEST['item_id']);
  196. }
  197. // check existence
  198. if (FALSE !== $this->CheckExistenceByName($name)) {
  199. $this->SetError(PHOTOSTATION_SHARED_ALBUM_HAS_EXISTED);
  200. goto End;
  201. }
  202. $sqlParams = array();
  203. if ($this->UserID !== 0) {
  204. $query = "INSERT INTO " . $this->TableName . " (userid, name, is_shared, hidden) VALUES (?, ?, 'f', 'f')";
  205. $sqlParams = array($this->UserID, $name);
  206. } else {
  207. $query = "INSERT INTO " . $this->TableName . " (name, is_shared, hidden) VALUES (?, 'f', 'f')";
  208. $sqlParams = array($name);
  209. }
  210. $db_result = PHOTO_DB_Query($query, $sqlParams);
  211. if (FALSE === ($sharedAlbumId = $this->CheckExistenceByName($name))) {
  212. $this->SetError(PHOTOSTATION_SHARED_ALBUM_CREATE_FAIL);
  213. goto End;
  214. }
  215. foreach($itemIds as $itemId) {
  216. $id_arr = explode('_', $itemId);
  217. if (3 !== count($id_arr) || ($id_arr[0] !== 'photo' && $id_arr[0] !== 'video')) {
  218. continue;
  219. }
  220. $type = $id_arr[0];
  221. $albumName = @pack('H*', $id_arr[1]);
  222. $fileName = @pack('H*', $id_arr[2]);
  223. if (!csSYNOPhotoMisc::CheckAlbumAccessible($albumName)) {
  224. return false;
  225. }
  226. if ('/' === $albumName) {
  227. $filePath = $fileName;
  228. } else {
  229. $filePath = $albumName.'/'.$fileName;
  230. }
  231. $dbId = csSYNOPhotoMisc::GetPhotoVideoDBId($filePath, $type);
  232. if (FALSE === $dbId) {
  233. continue;
  234. }
  235. $this->AddItemQuery($type, $sharedAlbumId, $dbId);
  236. }
  237. $result['id'] = 'sharedalbum_'.$sharedAlbumId;
  238. $this->SetResponse($result);
  239. $ret = true;
  240. End:
  241. return $ret;
  242. }
  243. private function Edit()
  244. {
  245. $ret = false;
  246. if (!isset($_REQUEST['id']) || !isset($_REQUEST['name'])) {
  247. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  248. goto End;
  249. }
  250. $id_arr = explode("_", $_REQUEST['id']);
  251. if (2 !== count($id_arr) || 'sharedalbum' != $id_arr[0]) {
  252. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  253. goto End;
  254. }
  255. $sharedAlbumId = $id_arr[1];
  256. $name = $_REQUEST['name'];
  257. if (FALSE === $this->CheckExistenceById($sharedAlbumId)) {
  258. $this->SetError(PHOTOSTATION_SHARED_ALBUM_NOT_EXISTS);
  259. goto End;
  260. }
  261. if (FALSE !== $this->CheckExistenceByName($name, $sharedAlbumId)) {
  262. $this->SetError(PHOTOSTATION_SHARED_ALBUM_HAS_EXISTED);
  263. goto End;
  264. }
  265. $sqlParams = array($name, $sharedAlbumId);
  266. $query = "UPDATE " . $this->TableName . " SET name = ? WHERE id = ? AND ";
  267. $this->appendUserIDCond($query, $sqlParams);
  268. $db_result = PHOTO_DB_Query($query, $sqlParams);
  269. $ret = true;
  270. End:
  271. return $ret;
  272. }
  273. private function Delete()
  274. {
  275. $ret = false;
  276. if (!isset($_REQUEST['id'])) {
  277. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  278. goto End;
  279. }
  280. $ids = explode(",", $_REQUEST['id']);
  281. $success_count = 0;
  282. foreach ($ids as $id) {
  283. $id_arr = explode("_", $id);
  284. if (2 !== count($id_arr) || 'sharedalbum' != $id_arr[0]) {
  285. continue;
  286. }
  287. $sharedAlbumId = $id_arr[1];
  288. if (FALSE === $this->CheckExistenceById($sharedAlbumId)) {
  289. continue;
  290. }
  291. $sqlParams = array($sharedAlbumId);
  292. $query = "DELETE FROM " . $this->TableName . " WHERE id = ? AND ";
  293. $this->appendUserIDCond($query, $sqlParams);
  294. $db_result = PHOTO_DB_Query($query, $sqlParams);
  295. $success_count ++;
  296. }
  297. if ($success_count === 0) {
  298. $this->SetError(PHOTOSTATION_SHARED_ALBUM_DELETE_FAIL);
  299. goto End;
  300. }
  301. $ret = true;
  302. End:
  303. return $ret;
  304. }
  305. private function AddItems()
  306. {
  307. $ret = false;
  308. if (!isset($_REQUEST['id']) || !isset($_REQUEST['item_id'])) {
  309. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  310. goto End;
  311. }
  312. $id_arr = explode("_", $_REQUEST['id']);
  313. if (2 !== count($id_arr) || 'sharedalbum' != $id_arr[0]) {
  314. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  315. goto End;
  316. }
  317. $sharedAlbumId = $id_arr[1];
  318. $itemIds = explode(",", $_REQUEST['item_id']);
  319. if (FALSE === $this->CheckExistenceById($sharedAlbumId)) {
  320. $this->SetError(PHOTOSTATION_SHARED_ALBUM_NOT_EXISTS);
  321. goto End;
  322. }
  323. foreach($itemIds as $itemId) {
  324. $id_arr = explode('_', $itemId);
  325. if (3 !== count($id_arr) || ($id_arr[0] !== 'photo' && $id_arr[0] !== 'video')) {
  326. continue;
  327. }
  328. $type = $id_arr[0];
  329. $albumName = @pack('H*', $id_arr[1]);
  330. $fileName = @pack('H*', $id_arr[2]);
  331. if (!csSYNOPhotoMisc::CheckAlbumAccessible($albumName)) {
  332. return false;
  333. }
  334. if ('/' === $albumName) {
  335. $filePath = $fileName;
  336. } else {
  337. $filePath = $albumName.'/'.$fileName;
  338. }
  339. $dbId = csSYNOPhotoMisc::GetPhotoVideoDBId($filePath, $type);
  340. if (FALSE === $dbId) {
  341. continue;
  342. }
  343. $this->AddItemQuery($type, $sharedAlbumId, $dbId);
  344. }
  345. $ret = true;
  346. End:
  347. return $ret;
  348. }
  349. private function RemoveItems()
  350. {
  351. $ret = false;
  352. if (!isset($_REQUEST['id']) || !isset($_REQUEST['item_id'])) {
  353. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  354. goto End;
  355. }
  356. $id_arr = explode("_", $_REQUEST['id']);
  357. if (2 !== count($id_arr) || 'sharedalbum' != $id_arr[0]) {
  358. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  359. goto End;
  360. }
  361. if ($id_arr[1] === 'single') {
  362. $sharedAlbum = SharedAlbum::GetHiddenAlbumInfo();
  363. $id_arr[1] = explode("_", $sharedAlbum['id'])[1];
  364. }
  365. $sharedAlbumId = $id_arr[1];
  366. $itemIds = explode(",", $_REQUEST['item_id']);
  367. if (FALSE === $this->CheckExistenceById($sharedAlbumId)) {
  368. $this->SetError(PHOTOSTATION_SHARED_ALBUM_NOT_EXISTS);
  369. goto End;
  370. }
  371. foreach($itemIds as $itemId) {
  372. $id_arr = explode('_', $itemId);
  373. if (3 !== count($id_arr) || ($id_arr[0] !== 'photo' && $id_arr[0] !== 'video')) {
  374. continue;
  375. }
  376. $type = $id_arr[0];
  377. $albumName = @pack('H*', $id_arr[1]);
  378. $fileName = @pack('H*', $id_arr[2]);
  379. if (!csSYNOPhotoMisc::CheckAlbumAccessible($albumName)) {
  380. return false;
  381. }
  382. if ('/' === $albumName) {
  383. $filePath = $fileName;
  384. } else {
  385. $filePath = $albumName.'/'.$fileName;
  386. }
  387. $dbId = csSYNOPhotoMisc::GetPhotoVideoDBId($filePath, $type);
  388. if (FALSE === $dbId) {
  389. continue;
  390. }
  391. $this->DeleteItemQuery($type, $sharedAlbumId, $dbId);
  392. }
  393. $ret = true;
  394. End:
  395. return $ret;
  396. }
  397. private function GetInfoPublic()
  398. {
  399. $ret = false;
  400. if (!isset($_REQUEST['public_share_id'])) {
  401. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  402. goto End;
  403. }
  404. $sharedAlbum = SharedAlbum::GetInfoByPublicShare($_REQUEST['public_share_id']);
  405. if (NULL === $sharedAlbum) {
  406. $this->SetError(PHOTOSTATION_SHARED_ALBUM_GET_INFO_ERROR);
  407. goto End;
  408. }
  409. if ('valid' !== $sharedAlbum['share_status']) {
  410. $this->SetError(PHOTOSTATION_SHARED_ALBUM_ACCESS_DENY);
  411. goto End;
  412. }
  413. $result['shared_album'] = $sharedAlbum;
  414. $this->SetResponse($result);
  415. $ret = true;
  416. End:
  417. return $ret;
  418. }
  419. private function validateDate($date) {
  420. $d = DateTime::createFromFormat('Y-m-d', $date);
  421. return $d && $d->format('Y-m-d') == $date;
  422. }
  423. private function EditPublicShare()
  424. {
  425. $ret = false;
  426. if (!SharedAlbum::CheckPublicSharePermission()) {
  427. $this->SetError(PHOTOSTATION_SHARED_ALBUM_ACCESS_DENY);
  428. goto End;
  429. }
  430. if (!isset($_REQUEST['id']) || !isset($_REQUEST['is_shared'])) {
  431. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  432. goto End;
  433. }
  434. $id_arr = explode("_", $_REQUEST['id']);
  435. if (2 !== count($id_arr) || 'sharedalbum' != $id_arr[0]) {
  436. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  437. goto End;
  438. }
  439. $sharedAlbumId = $id_arr[1];
  440. $isShared = $_REQUEST['is_shared'] === 'true';
  441. if (FALSE === $this->CheckExistenceById($sharedAlbumId)) {
  442. $this->SetError(PHOTOSTATION_SHARED_ALBUM_NOT_EXISTS);
  443. goto End;
  444. }
  445. $start_time = NULL;
  446. $end_time = NULL;
  447. if (isset($_REQUEST['start_time']) && isset($_REQUEST['end_time']) && $this->validateDate($_REQUEST['start_time']) && $this->validateDate($_REQUEST['end_time'])) {
  448. $start_time = $_REQUEST['start_time'];
  449. $end_time = $_REQUEST['end_time'];
  450. $startDate = new DateTime($start_time);
  451. $endDate = new DateTime($end_time);
  452. if ($startDate > $endDate) {
  453. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  454. goto End;
  455. }
  456. }
  457. if (NULL === ($shareLink = $this->GetShareLinkById($sharedAlbumId)) && $isShared) {
  458. do {
  459. $shareLink = SharedAlbum::GetRandomString();
  460. } while (SharedAlbum::CheckExistenceBySharelink($shareLink));
  461. }
  462. $sqlParams = array(
  463. $isShared ? 't' : 'f',
  464. $shareLink,
  465. $start_time,
  466. $end_time,
  467. $sharedAlbumId
  468. );
  469. $query = "UPDATE " . $this->TableName . " SET is_shared = ?, sharelink = ?, start_time = ?, end_time = ? WHERE id = ? AND ";
  470. $this->appendUserIDCond($query, $sqlParams);
  471. $db_result = PHOTO_DB_Query($query, $sqlParams);
  472. $info = $this->GetInfoById($sharedAlbumId, array('public_share'));
  473. if ($info === NULL) {
  474. $this->SetError(PHOTOSTATION_SHARED_ALBUM_GET_INFO_ERROR);
  475. goto End;
  476. }
  477. $this->SetResponse($info['additional']['public_share']);
  478. $ret = true;
  479. End:
  480. return $ret;
  481. }
  482. private function GetSingleItem()
  483. {
  484. $ret = false;
  485. if (!SharedAlbum::CheckPublicSharePermission()) {
  486. $this->SetError(PHOTOSTATION_SHARED_ALBUM_ACCESS_DENY);
  487. goto End;
  488. }
  489. if (!isset($_REQUEST['item_id'])) {
  490. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  491. goto End;
  492. }
  493. $id_arr = explode("_", $_REQUEST['item_id']);
  494. if (3 !== count($id_arr) || ('photo' !== $id_arr[0] && 'video' !== $id_arr[0])) {
  495. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  496. goto End;
  497. }
  498. $type = $id_arr[0];
  499. $albumName = @pack('H*', $id_arr[1]);
  500. $fileName = @pack('H*', $id_arr[2]);
  501. if (!csSYNOPhotoMisc::CheckAlbumAccessible($albumName)) {
  502. $this->SetError(PHOTOSTATION_SHARED_ALBUM_ACCESS_DENY);
  503. goto End;
  504. }
  505. $hiddenAlbum = SharedAlbum::GetHiddenAlbumInfo();
  506. if ($hiddenAlbum === NULL) {
  507. $result['is_shared'] = false;
  508. } else {
  509. $collectionid = explode("_", $hiddenAlbum['id'])[1];
  510. $table = ('photo' === $type) ? $this->PhotoTableName : $this->VideoTableName;
  511. if ('/' === $albumName) {
  512. $filePath = $fileName;
  513. } else {
  514. $filePath = $albumName.'/'.$fileName;
  515. }
  516. $dbId = csSYNOPhotoMisc::GetPhotoVideoDBId($filePath, $type);
  517. if (FALSE === $dbId) {
  518. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  519. goto End;
  520. }
  521. $query = "SELECT COUNT(*) FROM " . $table . " WHERE collectionid = ? AND {$type}id = ?";
  522. $sqlParams = array($collectionid, $dbId);
  523. $db_result = PHOTO_DB_Query($query, $sqlParams);
  524. $row = PHOTO_DB_FetchRow($db_result);
  525. if (1 !== (int)$row[0]) {
  526. $result['is_shared'] = false;
  527. } else {
  528. $result['is_shared'] = true;
  529. $result['public_share_url'] = csSYNOPhotoMisc::GetServerHost(true) . SYNOPHOTO_URL_PREFIX . '/photo/share/' . $hiddenAlbum['additional']['public_share']['shareid'] . '/' . $_REQUEST['item_id'];
  530. }
  531. }
  532. $this->SetResponse($result);
  533. $ret = true;
  534. End:
  535. return $ret;
  536. }
  537. private function SetSingleItem()
  538. {
  539. $ret = false;
  540. if (!SharedAlbum::CheckPublicSharePermission()) {
  541. $this->SetError(PHOTOSTATION_SHARED_ALBUM_ACCESS_DENY);
  542. goto End;
  543. }
  544. if (!isset($_REQUEST['item_id']) || !isset($_REQUEST['enable'])) {
  545. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  546. goto End;
  547. }
  548. $id_arr = explode("_", $_REQUEST['item_id']);
  549. if (3 !== count($id_arr) || ('photo' !== $id_arr[0] && 'video' !== $id_arr[0])) {
  550. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  551. goto End;
  552. }
  553. $type = $id_arr[0];
  554. $albumName = @pack('H*', $id_arr[1]);
  555. $fileName = @pack('H*', $id_arr[2]);
  556. if (!csSYNOPhotoMisc::CheckAlbumAccessible($albumName)) {
  557. $this->SetError(PHOTOSTATION_SHARED_ALBUM_ACCESS_DENY);
  558. goto End;
  559. }
  560. $hiddenAlbum = SharedAlbum::GetHiddenAlbumInfo();
  561. if ($hiddenAlbum === NULL) {
  562. $this->SetError(PHOTOSTATION_SHARED_ALBUM_GET_INFO_ERROR);
  563. goto End;
  564. }
  565. if ('/' === $albumName) {
  566. $filePath = $fileName;
  567. } else {
  568. $filePath = $albumName.'/'.$fileName;
  569. }
  570. $dbId = csSYNOPhotoMisc::GetPhotoVideoDBId($filePath, $type);
  571. if (FALSE === $dbId) {
  572. $this->SetError(PHOTOSTATION_SHARED_ALBUM_BAD_PARAMS);
  573. goto End;
  574. }
  575. $collectionid = explode("_", $hiddenAlbum['id'])[1];
  576. $sqlParams = array($collectionid, $dbId);
  577. if ($_REQUEST['enable'] === "true") {
  578. $this->AddItemQuery($type, $collectionid, $dbId);
  579. $result['is_shared'] = true;
  580. $result['public_share_url'] = csSYNOPhotoMisc::GetServerHost(true) . SYNOPHOTO_URL_PREFIX . '/photo/share/' . $hiddenAlbum['additional']['public_share']['shareid'] . '/' . $_REQUEST['item_id'];
  581. } else {
  582. $this->DeleteItemQuery($type, $collectionid, $dbId);
  583. $result['is_shared'] = false;
  584. }
  585. $this->SetResponse($result);
  586. $ret = true;
  587. End:
  588. return $ret;
  589. }
  590. /**
  591. * @return id if exist, FALSE otherwise
  592. */
  593. private function CheckExistenceByName($name, $filter_id = -1)
  594. {
  595. $sqlParams = array($name, $filter_id);
  596. $query = "SELECT COUNT(*) FROM " . $this->TableName . " WHERE name = ? AND id <> ? AND hidden = 'f' AND ";
  597. $this->appendUserIDCond($query, $sqlParams);
  598. $db_result = PHOTO_DB_Query($query, $sqlParams);
  599. $row = PHOTO_DB_FetchRow($db_result);
  600. if (1 !== (int)$row[0]) {
  601. return FALSE;
  602. }
  603. $sqlParams = array($name);
  604. $query = "SELECT id FROM " . $this->TableName . " WHERE name = ? AND hidden = 'f' AND ";
  605. $this->appendUserIDCond($query, $sqlParams);
  606. $db_result = PHOTO_DB_Query($query, $sqlParams);
  607. $row = PHOTO_DB_FetchRow($db_result);
  608. return $row[0];
  609. }
  610. private function CheckExistenceById($id)
  611. {
  612. $sqlParams = array($id);
  613. $query = "SELECT COUNT(*) FROM " . $this->TableName . " WHERE id = ? AND ";
  614. $this->appendUserIDCond($query, $sqlParams);
  615. $db_result = PHOTO_DB_Query($query, $sqlParams);
  616. $row = PHOTO_DB_FetchRow($db_result);
  617. if (1 === (int)$row[0]) {
  618. return TRUE;
  619. }
  620. return FALSE;
  621. }
  622. private function GetInfoById($sharedAlbumId, $additional = array()) {
  623. $sharedAlbum = SharedAlbum::GetInfoById($sharedAlbumId, $additional);
  624. if ($sharedAlbum === NULL) {
  625. return NULL;
  626. }
  627. $thumbSize['preview']['resolutionx'] = 0;
  628. $thumbSize['preview']['resolutiony'] = 0;
  629. $thumbSize['small']['resolutionx'] = 0;
  630. $thumbSize['small']['resolutiony'] = 0;
  631. $thumbSize['large']['resolutionx'] = 0;
  632. $thumbSize['large']['resolutiony'] = 0;
  633. $thubmSize['sig'] = "";
  634. $cover = SharedAlbum::GetSharedAlbumCover($sharedAlbumId);
  635. $getRealPath = ('root' === SYNOPHOTO_ADMIN_USER) ? false : true;
  636. if ($cover === NULL) {
  637. $sharedAlbum['thumbnail_status'] = 'default';
  638. } else if (false !== ($item = PhotoAPIUtil::getItemByPath($cover['path'], array('thumb_size'), $cover['type'], $getRealPath))) {
  639. $sharedAlbum['thumbnail_status'] = $item['thumbnail_status'];
  640. $thumbSize = $item['additional']['thumb_size'];
  641. }
  642. if (in_array("thumb_size", $additional)) {
  643. $sharedAlbum['additional']['thumb_size'] = $thumbSize;
  644. }
  645. return $sharedAlbum;
  646. }
  647. private function AddItemQuery($type, $sharedAlbumId, $itemDBId)
  648. {
  649. $query = "INSERT INTO " . ($type === 'photo' ? $this->PhotoTableName : $this->VideoTableName) . " VALUES (?, ?)";
  650. $db_result = PHOTO_DB_Query($query, array($sharedAlbumId, $itemDBId));
  651. }
  652. private function DeleteItemQuery($type, $sharedAlbumId, $itemDBId)
  653. {
  654. $query = "DELETE FROM " . ($type === 'photo' ? $this->PhotoTableName : $this->VideoTableName) . " WHERE collectionid = ? AND {$type}id = ?";
  655. $db_result = PHOTO_DB_Query($query, array($sharedAlbumId, $itemDBId));
  656. }
  657. private function GetShareLinkById($sharedAlbumId)
  658. {
  659. $sqlParams = array($sharedAlbumId);
  660. $query = "SELECT sharelink FROM " . $this->TableName . " WHERE id = ? AND";
  661. $this->appendUserIDCond($query, $sqlParams);
  662. $db_result = PHOTO_DB_Query($query, $sqlParams);
  663. $row = PHOTO_DB_FetchRow($db_result);
  664. if (!$row) {
  665. return NULL;
  666. }
  667. return $row[0];
  668. }
  669. private function appendUserIDCond(&$sql, &$sqlParams)
  670. {
  671. $useridCond = " 1=1 ";
  672. if ($this->UserID !== 0) {
  673. $useridCond = " userid = ? ";
  674. $sqlParams[] = $this->UserID;
  675. }
  676. $sql = $sql . $useridCond;
  677. }
  678. }
  679. $api = new SharedAlbumAPI();
  680. $api->Run();
  681. ?>