diff --git a/mod/quiz/quizfile.php b/mod/quiz/quizfile.php deleted file mode 100644 index f168a7d0145..00000000000 --- a/mod/quiz/quizfile.php +++ /dev/null @@ -1,111 +0,0 @@ -libdir.'/filelib.php'); - require_once('locallib.php'); - - if (empty($CFG->filelifetime)) { - $lifetime = 86400; // Seconds for files to remain in caches - } else { - $lifetime = $CFG->filelifetime; - } - - // disable moodle specific debug messages - disable_debugging(); - - $relativepath = get_file_argument('quizfile.php'); - - if (!$relativepath) { - error('No valid arguments supplied or incorrect server configuration'); - } - - // extract relative path components - $args = explode('/', trim($relativepath, '/')); - if (count($args) < 3) { // always at least category, question and path - error('No valid arguments supplied'); - } - - $quizid = (int)array_shift($args); - $questionid = (int)array_shift($args); - $relativepath = implode ('/', $args); - - if (!($question = get_record('question', 'id', $questionid))) { - error('No valid arguments supplied'); - } - - if (!($questioncategory = get_record('question_categories', 'id', $question->category))) { - error('No valid arguments supplied'); - } - - ///////////////////////////////////// - // Check access - ///////////////////////////////////// - if ($quizid == 0) { // teacher doing preview during quiz creation - if ($questioncategory->publish) { - require_login(); - if (!isteacherinanycourse()) { - error('No valid arguments supplied'); - } - } else { - require_login($questioncategory->course); - $cm = get_coursemodule_from_instance('quiz', $quizid); - require_capability('mod/quiz:preview', get_context_instance(CONTEXT_MODULE, $cm->id)); - } - } else { - if (!($quiz = get_record('quiz', 'id', $quizid))) { - error('No valid arguments supplied'); - } - if (!($course = get_record('course', 'id', $quiz->course))) { - error('No valid arguments supplied'); - } - require_login($course->id); - - // For now, let's not worry about this. The following check causes - // problems sometimes when reviewing a quiz - //if (!isteacher($course->id) - // and !quiz_get_user_attempt_unfinished($quiz->id, $USER->id) - // and ! ($quiz->review && time() > $quiz->timeclose) - // || !quiz_get_user_attempts($quiz->id, $USER->id) ) - //{ - // error("Logged-in user is not allowed to view this quiz"); - //} - - /////////////////////////////////////////////////// - // The logged-in user has the right to view material on this quiz! - // Now verify the consistency between $quiz, $question, its category and $relativepathname - /////////////////////////////////////////////////// - - // For now, let's not worry about this. The following check doesn't - // work for randomly selected questions and it gets complicated - //if (!in_array($question->id, explode(',', $quiz->questions), FALSE)) { - // error("Specified question is not on the specified quiz"); - //} - } - - // Have the question check whether it uses this file or not - if (!$QTYPES[$question->qtype]->uses_quizfile($question, - $relativepath)) { - error("The specified file path is not on the specified question"); - } - - - /////////////////////////////////////////// - // All security stuff is now taken care of. - // Specified file can now be returned... - ////////////////////////////////////////// - - $pathname = "$CFG->dataroot/$questioncategory->course/$relativepath"; - $filename = $args[count($args)-1]; - - - if (file_exists($pathname)) { - send_file($pathname, $filename, $lifetime); - } else { - header('HTTP/1.0 404 not found'); - print_error('filenotfound', 'error'); //this is not displayed on IIS?? - } -?> diff --git a/question/type/datasetdependent/abstractqtype.php b/question/type/datasetdependent/abstractqtype.php index 54edd15fc0d..ae32d2b1074 100644 --- a/question/type/datasetdependent/abstractqtype.php +++ b/question/type/datasetdependent/abstractqtype.php @@ -88,26 +88,6 @@ class question_dataset_dependent_questiontype extends default_questiontype { return $str; } - function uses_quizfile($question, $relativefilepath) { - // Check whether the specified file is available by any - // dataset item on this question... - global $CFG; - if (get_record_sql(" SELECT * - FROM {$CFG->prefix}question_dataset_items i, - {$CFG->prefix}question_dataset_definitions d, - {$CFG->prefix}question_datasets q - WHERE i.value = '$relativefilepath' - AND d.id = i.definition AND d.type = 2 - AND d.id = q.datasetdefinition - AND q.question = $question->id ")) { - - return true; - } else { - // Make the check of the parent: - return parent::uses_quizfile($question, $relativefilepath); - } - } - function finished_edit_wizard(&$form) { return isset($form->backtoquiz); }