diff --git a/lib/moodlelib.php b/lib/moodlelib.php index a53a8de8fb8..fd1f8167293 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -2817,6 +2817,11 @@ function get_login_url() { function require_login($courseorid = NULL, $autologinguest = true, $cm = NULL, $setwantsurltome = true, $preventredirect = false) { global $CFG, $SESSION, $USER, $PAGE, $SITE, $DB, $OUTPUT; + // Must not redirect when byteserving already started. + if (!empty($_SERVER['HTTP_RANGE'])) { + $preventredirect = true; + } + // setup global $COURSE, themes, language and locale if (!empty($courseorid)) { if (is_object($courseorid)) { diff --git a/lib/outputrenderers.php b/lib/outputrenderers.php index 019f01982ea..1c014595e39 100644 --- a/lib/outputrenderers.php +++ b/lib/outputrenderers.php @@ -2317,12 +2317,16 @@ EOD; } error_reporting($CFG->debug); - // Header not yet printed - if (isset($_SERVER['SERVER_PROTOCOL'])) { - // server protocol should be always present, because this render - // can not be used from command line or when outputting custom XML - @header($_SERVER['SERVER_PROTOCOL'] . ' 404 Not Found'); + // Output not yet started. + $protocol = (isset($_SERVER['SERVER_PROTOCOL']) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0'); + if (empty($_SERVER['HTTP_RANGE'])) { + @header($protocol . ' 404 Not Found'); + } else { + // Must stop byteserving attempts somehow, + // this is weird but Chrome PDF viewer can be stopped only with 407! + @header($protocol . ' 407 Proxy Authentication Required'); } + $this->page->set_context(null); // ugly hack - make sure page context is set to something, we do not want bogus warnings here $this->page->set_url('/'); // no url //$this->page->set_pagelayout('base'); //TODO: MDL-20676 blocks on error pages are weird, unfortunately it somehow detect the pagelayout from URL :-( diff --git a/lib/setuplib.php b/lib/setuplib.php index 129147a9b1d..e8258447f81 100644 --- a/lib/setuplib.php +++ b/lib/setuplib.php @@ -1547,12 +1547,9 @@ width: 80%; -moz-border-radius: 20px; padding: 15px"> } // In the name of protocol correctness, monitoring and performance - // profiling, set the appropriate error headers for machine consumption - if (isset($_SERVER['SERVER_PROTOCOL'])) { - // Avoid it with cron.php. Note that we assume it's HTTP/1.x - // The 503 ode here means our Moodle does not work at all, the error happened too early - @header($_SERVER['SERVER_PROTOCOL'] . ' 503 Service Unavailable'); - } + // profiling, set the appropriate error headers for machine consumption. + $protocol = (isset($_SERVER['SERVER_PROTOCOL']) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0'); + @header($protocol . ' 503 Service Unavailable'); // better disable any caching @header('Content-Type: text/html; charset=utf-8');