diff --git a/file.php b/file.php index 3efd77d18f7..21c6a19ad86 100644 --- a/file.php +++ b/file.php @@ -144,7 +144,7 @@ // ======================================== session_write_close(); // unlock session during fileserving $filename = $args[count($args)-1]; - send_file($pathname, $filename, $lifetime, !empty($CFG->filteruploadedfiles), false, $forcedownload); + send_file($pathname, $filename, $lifetime, $CFG->filteruploadedfiles, false, $forcedownload); function not_found($courseid) { global $CFG; diff --git a/lib/filelib.php b/lib/filelib.php index d4800b685a6..6c471099039 100644 --- a/lib/filelib.php +++ b/lib/filelib.php @@ -140,7 +140,11 @@ function mimeinfo($element, $filename) { } } -function send_file($path, $filename, $lifetime=86400 , $filter=false, $pathisstring=false, $forcedownload=false) { + +/** + * @PARAM $filter int 0=no filtering, 1=all files, 2=html files only + */ +function send_file($path, $filename, $lifetime=86400 , $filter=0, $pathisstring=false, $forcedownload=false) { global $CFG; $mimetype = $forcedownload ? 'application/x-forcedownload' : mimeinfo('type', $filename); @@ -223,7 +227,7 @@ function send_file($path, $filename, $lifetime=86400 , $filter=false, $pathisstr @header('Accept-Ranges: none'); // Do not allow byteserving when caching disabled } - if (!$filter) { + if (empty($filter)) { if ($mimetype == 'text/html' && !empty($CFG->usesid) && empty($_COOKIE['MoodleSession'.$CFG->sessioncookie])) { //cookieless mode - rewrite links @header('Content-Type: text/html'); @@ -263,7 +267,8 @@ function send_file($path, $filename, $lifetime=86400 , $filter=false, $pathisstr @header('Content-Type: text/html'); while (@ob_end_flush()); //flush the buffers - save memory and disable sid rewrite echo $output; - } else if (($mimetype == 'text/plain') and ($CFG->filteruploadedfiles==1)) { + // only filter text if filter all files is selected + } else if (($mimetype == 'text/plain') and ($filter == 1)) { $options->newlines = false; $options->noclean = true; $text = htmlentities($pathisstring ? $path : implode('', file($path)));