class-studiou-wc-fpp-upload.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391
  1. <?php
  2. if (!defined('WPINC')) {
  3. die;
  4. }
  5. class Studiou_WC_FPP_Upload {
  6. /** @var Studiou_WC_FPP_DB */
  7. private $db;
  8. public function __construct($db) {
  9. $this->db = $db;
  10. add_action('wp_ajax_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  11. add_action('wp_ajax_nopriv_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  12. add_action('wp_ajax_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  13. add_action('wp_ajax_nopriv_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  14. }
  15. private function get_chunks_dir() {
  16. $upload_dir = wp_upload_dir();
  17. return $upload_dir['basedir'] . '/studiou-fpp-chunks';
  18. }
  19. private function get_allowed_mime_types() {
  20. return array(
  21. 'jpg|jpeg|jpe' => 'image/jpeg',
  22. 'png' => 'image/png',
  23. 'tiff|tif' => 'image/tiff',
  24. 'bmp' => 'image/bmp',
  25. 'psd' => 'image/vnd.adobe.photoshop',
  26. 'cr2' => 'image/x-canon-cr2',
  27. 'nef' => 'image/x-nikon-nef',
  28. 'arw' => 'image/x-sony-arw',
  29. 'dng' => 'image/x-adobe-dng',
  30. 'orf' => 'image/x-olympus-orf',
  31. 'rw2' => 'image/x-panasonic-rw2',
  32. 'raf' => 'image/x-fuji-raf',
  33. 'webp' => 'image/webp',
  34. );
  35. }
  36. public function handle_chunk_upload() {
  37. // Clean output buffers
  38. while (ob_get_level()) {
  39. ob_end_clean();
  40. }
  41. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  42. $product_id = isset($_POST['product_id']) ? absint($_POST['product_id']) : 0;
  43. $upload_id = isset($_POST['upload_id']) ? sanitize_text_field($_POST['upload_id']) : '';
  44. $chunk_index = isset($_POST['chunk_index']) ? absint($_POST['chunk_index']) : 0;
  45. $total_chunks = isset($_POST['total_chunks']) ? absint($_POST['total_chunks']) : 0;
  46. $file_name = isset($_POST['file_name']) ? sanitize_file_name($_POST['file_name']) : '';
  47. $file_size = isset($_POST['file_size']) ? absint($_POST['file_size']) : 0;
  48. // Validate product
  49. if (!$product_id || !Studiou_WC_FPP_Product::is_fpp_product($product_id)) {
  50. wp_send_json_error(array('message' => __('Invalid product.', 'studiou-wc-free-photo-product')));
  51. return;
  52. }
  53. // Validate file size
  54. $max_size = Studiou_WC_FPP_Product::get_product_max_file_size($product_id);
  55. if ($file_size > ($max_size * 1024 * 1024)) {
  56. wp_send_json_error(array('message' => sprintf(
  57. __('File is too large. Maximum size: %s MB', 'studiou-wc-free-photo-product'),
  58. $max_size
  59. )));
  60. return;
  61. }
  62. // Validate upload_id format (should be alphanumeric)
  63. if (!preg_match('/^[a-zA-Z0-9_-]+$/', $upload_id)) {
  64. wp_send_json_error(array('message' => __('Invalid upload ID.', 'studiou-wc-free-photo-product')));
  65. return;
  66. }
  67. // Validate chunk file exists
  68. if (!isset($_FILES['chunk']) || $_FILES['chunk']['error'] !== UPLOAD_ERR_OK) {
  69. wp_send_json_error(array('message' => __('Chunk upload failed.', 'studiou-wc-free-photo-product')));
  70. return;
  71. }
  72. $chunks_dir = $this->get_chunks_dir();
  73. if (!file_exists($chunks_dir)) {
  74. wp_mkdir_p($chunks_dir);
  75. }
  76. // Store the chunk
  77. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $chunk_index;
  78. if (!move_uploaded_file($_FILES['chunk']['tmp_name'], $chunk_file)) {
  79. wp_send_json_error(array('message' => __('Failed to store chunk.', 'studiou-wc-free-photo-product')));
  80. return;
  81. }
  82. // If this is the last chunk, assemble the file
  83. if ($chunk_index === $total_chunks - 1) {
  84. // Clean any output that may have been generated
  85. while (ob_get_level()) {
  86. ob_end_clean();
  87. }
  88. $result = $this->assemble_chunks($upload_id, $total_chunks, $file_name, $product_id);
  89. // Clean again before sending JSON
  90. while (ob_get_level()) {
  91. ob_end_clean();
  92. }
  93. if (is_wp_error($result)) {
  94. wp_send_json_error(array('message' => $result->get_error_message()));
  95. return;
  96. }
  97. wp_send_json_success(array(
  98. 'complete' => true,
  99. 'attachment_id' => $result['attachment_id'],
  100. 'file_record_id' => $result['file_record_id'],
  101. 'thumbnail_url' => $result['thumbnail_url'],
  102. 'preview_url' => $result['preview_url'],
  103. 'file_name' => $result['file_name'],
  104. ));
  105. return;
  106. }
  107. wp_send_json_success(array(
  108. 'complete' => false,
  109. 'chunk_index' => $chunk_index,
  110. ));
  111. }
  112. private function assemble_chunks($upload_id, $total_chunks, $file_name, $product_id) {
  113. $chunks_dir = $this->get_chunks_dir();
  114. $upload_dir = wp_upload_dir();
  115. // Create a subdirectory for free photo uploads
  116. $fpp_dir = $upload_dir['path'] . '/free-photo';
  117. if (!file_exists($fpp_dir)) {
  118. wp_mkdir_p($fpp_dir);
  119. }
  120. // Generate unique filename
  121. $ext = pathinfo($file_name, PATHINFO_EXTENSION);
  122. $base = sanitize_file_name(pathinfo($file_name, PATHINFO_FILENAME));
  123. $unique_name = $base . '_' . uniqid() . '.' . $ext;
  124. $assembled_path = $fpp_dir . '/' . $unique_name;
  125. // Assemble chunks
  126. $output = fopen($assembled_path, 'wb');
  127. if (!$output) {
  128. $this->cleanup_chunks($upload_id, $total_chunks);
  129. return new WP_Error('assemble_failed', __('Failed to create output file.', 'studiou-wc-free-photo-product'));
  130. }
  131. for ($i = 0; $i < $total_chunks; $i++) {
  132. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  133. if (!file_exists($chunk_file)) {
  134. fclose($output);
  135. unlink($assembled_path);
  136. $this->cleanup_chunks($upload_id, $total_chunks);
  137. return new WP_Error('chunk_missing', sprintf(
  138. __('Missing chunk %d.', 'studiou-wc-free-photo-product'),
  139. $i
  140. ));
  141. }
  142. $chunk_data = file_get_contents($chunk_file);
  143. fwrite($output, $chunk_data);
  144. }
  145. fclose($output);
  146. // Clean up chunk files
  147. $this->cleanup_chunks($upload_id, $total_chunks);
  148. // Validate file extension
  149. $allowed = $this->get_allowed_mime_types();
  150. $ext_lower = strtolower($ext);
  151. $valid = false;
  152. foreach ($allowed as $exts => $mime) {
  153. $ext_list = explode('|', $exts);
  154. if (in_array($ext_lower, $ext_list)) {
  155. $valid = true;
  156. break;
  157. }
  158. }
  159. if (!$valid) {
  160. unlink($assembled_path);
  161. return new WP_Error('invalid_type', __('File type not allowed.', 'studiou-wc-free-photo-product'));
  162. }
  163. // Validate image resolution (if limits are set)
  164. $res_error = $this->validate_image_resolution($assembled_path, $product_id);
  165. if (is_wp_error($res_error)) {
  166. unlink($assembled_path);
  167. return $res_error;
  168. }
  169. // Create WP attachment
  170. $relative_path = str_replace($upload_dir['basedir'] . '/', '', $assembled_path);
  171. $filetype = wp_check_filetype($unique_name, $allowed);
  172. $attachment_data = array(
  173. 'post_mime_type' => $filetype['type'] ?: 'application/octet-stream',
  174. 'post_title' => sanitize_file_name($file_name),
  175. 'post_content' => '',
  176. 'post_status' => 'inherit',
  177. 'post_parent' => $product_id,
  178. );
  179. $attachment_id = wp_insert_attachment($attachment_data, $assembled_path, $product_id);
  180. if (is_wp_error($attachment_id)) {
  181. unlink($assembled_path);
  182. return $attachment_id;
  183. }
  184. // Generate metadata (wrapped in output buffer to prevent stray output corrupting JSON)
  185. require_once(ABSPATH . 'wp-admin/includes/image.php');
  186. ob_start();
  187. try {
  188. @set_time_limit(120);
  189. $metadata = @wp_generate_attachment_metadata($attachment_id, $assembled_path);
  190. if (!empty($metadata)) {
  191. wp_update_attachment_metadata($attachment_id, $metadata);
  192. }
  193. } catch (\Throwable $e) {
  194. if (defined('WP_DEBUG') && WP_DEBUG) {
  195. error_log('STUDIOU FPP: metadata generation failed - ' . $e->getMessage());
  196. }
  197. }
  198. ob_end_clean();
  199. // Assign media category
  200. $media_cat_id = Studiou_WC_FPP_Product::get_product_media_category($product_id);
  201. if ($media_cat_id) {
  202. wp_set_object_terms($attachment_id, array((int) $media_cat_id), 'studiou_media_category');
  203. }
  204. // Get thumbnail URL (small - for upload preview)
  205. $thumbnail_url = '';
  206. $image_src = wp_get_attachment_image_src($attachment_id, 'thumbnail');
  207. if ($image_src) {
  208. $thumbnail_url = $image_src[0];
  209. } else {
  210. $thumbnail_url = wp_mime_type_icon($attachment_id);
  211. }
  212. // Get preview URL (larger - for product gallery replacement)
  213. $preview_url = '';
  214. $preview_src = wp_get_attachment_image_src($attachment_id, 'woocommerce_single');
  215. if ($preview_src) {
  216. $preview_url = $preview_src[0];
  217. } elseif ($image_src) {
  218. $preview_url = $image_src[0];
  219. }
  220. // Get session key for guests
  221. $session_key = '';
  222. if (!is_user_logged_in()) {
  223. if (WC()->session) {
  224. $session_key = WC()->session->get_customer_id();
  225. }
  226. }
  227. // Insert file record
  228. $file_record_id = $this->db->insert_file_record(array(
  229. 'product_id' => $product_id,
  230. 'attachment_id' => $attachment_id,
  231. 'customer_id' => get_current_user_id(),
  232. 'session_key' => $session_key,
  233. 'file_name' => $file_name,
  234. ));
  235. if (!$file_record_id) {
  236. wp_delete_attachment($attachment_id, true);
  237. return new WP_Error('record_failed', __('Failed to create file record.', 'studiou-wc-free-photo-product'));
  238. }
  239. return array(
  240. 'attachment_id' => $attachment_id,
  241. 'file_record_id' => $file_record_id,
  242. 'thumbnail_url' => $thumbnail_url,
  243. 'preview_url' => $preview_url,
  244. 'file_name' => $file_name,
  245. );
  246. }
  247. /**
  248. * Validate image resolution against product limits.
  249. * Width/height are commutable — a 3000x2000 image matches both 3000x2000 and 2000x3000 limits.
  250. */
  251. private function validate_image_resolution($file_path, $product_id) {
  252. $limits = Studiou_WC_FPP_Product::get_product_resolution_limits($product_id);
  253. // Skip if no limits set
  254. $has_min = ($limits['min_width'] > 0 || $limits['min_height'] > 0);
  255. $has_max = ($limits['max_width'] > 0 || $limits['max_height'] > 0);
  256. if (!$has_min && !$has_max) {
  257. return true;
  258. }
  259. // Get image dimensions
  260. $size = @getimagesize($file_path);
  261. if (!$size || !isset($size[0], $size[1])) {
  262. // Cannot determine dimensions (e.g. RAW files) — skip validation
  263. return true;
  264. }
  265. $img_w = $size[0];
  266. $img_h = $size[1];
  267. // Normalize: always compare min(w,h) vs min(limit_w,limit_h) and max(w,h) vs max(limit_w,limit_h)
  268. // This makes portrait/landscape interchangeable
  269. $img_short = min($img_w, $img_h);
  270. $img_long = max($img_w, $img_h);
  271. // Minimum resolution check
  272. if ($has_min) {
  273. $min_short = min($limits['min_width'] ?: 0, $limits['min_height'] ?: 0);
  274. $min_long = max($limits['min_width'] ?: 0, $limits['min_height'] ?: 0);
  275. // If only one dimension is set, use it for both
  276. if ($min_short === 0) $min_short = $min_long;
  277. if ($img_short < $min_short || $img_long < $min_long) {
  278. return new WP_Error('resolution_too_small', sprintf(
  279. __('Image resolution %1$dx%2$d px is too small. Minimum required: %3$dx%4$d px.', 'studiou-wc-free-photo-product'),
  280. $img_w, $img_h, $limits['min_width'] ?: $limits['min_height'], $limits['min_height'] ?: $limits['min_width']
  281. ));
  282. }
  283. }
  284. // Maximum resolution check
  285. if ($has_max) {
  286. $max_short = min($limits['max_width'] ?: PHP_INT_MAX, $limits['max_height'] ?: PHP_INT_MAX);
  287. $max_long = max($limits['max_width'] ?: PHP_INT_MAX, $limits['max_height'] ?: PHP_INT_MAX);
  288. if ($max_short === PHP_INT_MAX) $max_short = $max_long;
  289. if ($img_short > $max_short || $img_long > $max_long) {
  290. return new WP_Error('resolution_too_large', sprintf(
  291. __('Image resolution %1$dx%2$d px is too large. Maximum allowed: %3$dx%4$d px.', 'studiou-wc-free-photo-product'),
  292. $img_w, $img_h, $limits['max_width'] ?: $limits['max_height'], $limits['max_height'] ?: $limits['max_width']
  293. ));
  294. }
  295. }
  296. return true;
  297. }
  298. private function cleanup_chunks($upload_id, $total_chunks) {
  299. $chunks_dir = $this->get_chunks_dir();
  300. for ($i = 0; $i < $total_chunks; $i++) {
  301. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  302. if (file_exists($chunk_file)) {
  303. unlink($chunk_file);
  304. }
  305. }
  306. }
  307. public function handle_remove_upload() {
  308. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  309. $file_record_id = isset($_POST['file_record_id']) ? absint($_POST['file_record_id']) : 0;
  310. if (!$file_record_id) {
  311. wp_send_json_error(array('message' => __('Invalid file.', 'studiou-wc-free-photo-product')));
  312. return;
  313. }
  314. $record = $this->db->get_file_record($file_record_id);
  315. if (!$record) {
  316. wp_send_json_error(array('message' => __('File not found.', 'studiou-wc-free-photo-product')));
  317. return;
  318. }
  319. // Only allow removal if not yet linked to an order
  320. if ($record->order_id > 0) {
  321. wp_send_json_error(array('message' => __('Cannot remove a file linked to an order.', 'studiou-wc-free-photo-product')));
  322. return;
  323. }
  324. // Verify ownership
  325. $current_user_id = get_current_user_id();
  326. if ($current_user_id > 0 && (int) $record->customer_id !== $current_user_id) {
  327. wp_send_json_error(array('message' => __('Permission denied.', 'studiou-wc-free-photo-product')));
  328. return;
  329. }
  330. $this->db->delete_file_record($file_record_id);
  331. wp_send_json_success(array('message' => __('File removed.', 'studiou-wc-free-photo-product')));
  332. }
  333. }