X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;f=admin%2Fbackups.php;h=2193486ba9210d22bf8f5dc0add07e2e5874fa1b;hb=9fed7316c2f3226f8a7c18481e174d81cfe2d7fc;hp=a70a2846e55c96a7a8fcae67221f648d0da7b5fa;hpb=9dab04be9d81766f1878d3688ee73d0bcf29f5d2;p=fa-stable.git diff --git a/admin/backups.php b/admin/backups.php index a70a2846..2193486b 100644 --- a/admin/backups.php +++ b/admin/backups.php @@ -17,20 +17,23 @@ include_once($path_to_root . "/includes/ui.inc"); include_once($path_to_root . "/admin/db/maintenance_db.inc"); if (get_post('view')) { - $filename = BACKUP_PATH . get_post('backups'); - if (in_ajax()) - $Ajax->popup( $filename ); - else { - header('Content-type: application/octet-stream'); - header('Content-Length: '.filesize($filename)); - header("Content-Disposition: inline; filename=$filename"); - readfile($filename); - exit(); + if (!get_post('backups')) { + display_error(_('Select backup file first.')); + } else { + $filename = BACKUP_PATH . clean_file_name(get_post('backups')); + if (in_ajax()) + $Ajax->popup( $filename ); + else { + header('Content-type: text/plain'); + header('Content-Length: '.filesize($filename)); + header("Content-Disposition: inline"); + readfile($filename); + exit(); + } } }; - if (get_post('download')) { - download_file(BACKUP_PATH . get_post('backups')); + download_file(BACKUP_PATH . clean_file_name(get_post('backups'))); exit; } @@ -96,7 +99,7 @@ function compress_list_row($label, $name, $value=null) if (function_exists("gzopen")) $ar_comps['gzip'] = "gzip"; - echo "$label"; + echo "$label"; echo array_selector('comp', $value, $ar_comps); echo ""; } @@ -105,6 +108,7 @@ function download_file($filename) { if (empty($filename) || !file_exists($filename)) { + display_error(_('Select backup file first.')); return false; } $saveasname = basename($filename); @@ -118,6 +122,8 @@ function download_file($filename) $db_name = $_SESSION["wa_current_user"]->company; $conn = $db_connections[$db_name]; +$backup_name = clean_file_name(get_post('backups')); +$backup_path = BACKUP_PATH . $backup_name; if (get_post('creat')) { generate_backup($conn, get_post('comp'), get_post('comments')); @@ -125,26 +131,27 @@ if (get_post('creat')) { }; if (get_post('restore')) { - if (db_import(BACKUP_PATH . get_post('backups'), $conn)) + if (db_import($backup_path, $conn)) display_notification(_("Restore backup completed.")); + refresh_sys_prefs(); // re-read system setup } if (get_post('deldump')) { - if (unlink(BACKUP_PATH . get_post('backups'))) { + if (unlink($backup_path)) { display_notification(_("File successfully deleted.")." " - . _("Filename") . ": " . get_post('backups')); + . _("Filename") . ": " . $backup_name); $Ajax->activate('backups'); } else display_error(_("Can't delete backup file.")); -}; +} if (get_post('upload')) { $tmpname = $_FILES['uploadfile']['tmp_name']; - $fname = $_FILES['uploadfile']['name']; + $fname = trim(basename($_FILES['uploadfile']['name'])); - if (!preg_match("/.sql(.zip|.gz)?$/", $fname)) + if (!preg_match("/\.sql(\.zip|\.gz)?$/", $fname)) display_error(_("You can only upload *.sql backup files")); elseif (is_uploaded_file($tmpname)) { rename($tmpname, BACKUP_PATH . $fname); @@ -155,7 +162,7 @@ if (get_post('upload')) } //------------------------------------------------------------------------------- start_form(true, true); -start_outer_table($table_style2); +start_outer_table(TABLESTYLE2); table_section(1); table_section_title(_("Create backup")); textarea_row(_("Comments:"), 'comments', null, 30, 8); @@ -169,7 +176,7 @@ table_section_title(_("Backup scripts maintenance")); echo "".get_backup_file_combo().""; echo ""; start_table(); - submit_row('view',_("View Backup"), false, '', '', true); + submit_row('view',_("View Backup"), false, '', '', false); submit_row('download',_("Download Backup"), false, '', '', false); submit_row('restore',_("Restore Backup"), false, '','', 'process'); submit_js_confirm('restore',_("You are about to restore database from backup file.\nDo you want to continue?"));