class-studiou-wc-fpp-upload.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313
  1. <?php
  2. if (!defined('WPINC')) {
  3. die;
  4. }
  5. class Studiou_WC_FPP_Upload {
  6. /** @var Studiou_WC_FPP_DB */
  7. private $db;
  8. public function __construct($db) {
  9. $this->db = $db;
  10. add_action('wp_ajax_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  11. add_action('wp_ajax_nopriv_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  12. add_action('wp_ajax_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  13. add_action('wp_ajax_nopriv_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  14. }
  15. private function get_chunks_dir() {
  16. $upload_dir = wp_upload_dir();
  17. return $upload_dir['basedir'] . '/studiou-fpp-chunks';
  18. }
  19. private function get_allowed_mime_types() {
  20. return array(
  21. 'jpg|jpeg|jpe' => 'image/jpeg',
  22. 'png' => 'image/png',
  23. 'tiff|tif' => 'image/tiff',
  24. 'bmp' => 'image/bmp',
  25. 'psd' => 'image/vnd.adobe.photoshop',
  26. 'cr2' => 'image/x-canon-cr2',
  27. 'nef' => 'image/x-nikon-nef',
  28. 'arw' => 'image/x-sony-arw',
  29. 'dng' => 'image/x-adobe-dng',
  30. 'orf' => 'image/x-olympus-orf',
  31. 'rw2' => 'image/x-panasonic-rw2',
  32. 'raf' => 'image/x-fuji-raf',
  33. 'webp' => 'image/webp',
  34. );
  35. }
  36. public function handle_chunk_upload() {
  37. // Clean output buffers
  38. while (ob_get_level()) {
  39. ob_end_clean();
  40. }
  41. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  42. $product_id = isset($_POST['product_id']) ? absint($_POST['product_id']) : 0;
  43. $upload_id = isset($_POST['upload_id']) ? sanitize_text_field($_POST['upload_id']) : '';
  44. $chunk_index = isset($_POST['chunk_index']) ? absint($_POST['chunk_index']) : 0;
  45. $total_chunks = isset($_POST['total_chunks']) ? absint($_POST['total_chunks']) : 0;
  46. $file_name = isset($_POST['file_name']) ? sanitize_file_name($_POST['file_name']) : '';
  47. $file_size = isset($_POST['file_size']) ? absint($_POST['file_size']) : 0;
  48. // Validate product
  49. if (!$product_id || !Studiou_WC_FPP_Product::is_fpp_product($product_id)) {
  50. wp_send_json_error(array('message' => __('Invalid product.', 'studiou-wc-free-photo-product')));
  51. return;
  52. }
  53. // Validate file size
  54. $max_size = Studiou_WC_FPP_Product::get_product_max_file_size($product_id);
  55. if ($file_size > ($max_size * 1024 * 1024)) {
  56. wp_send_json_error(array('message' => sprintf(
  57. __('File is too large. Maximum size: %s MB', 'studiou-wc-free-photo-product'),
  58. $max_size
  59. )));
  60. return;
  61. }
  62. // Validate upload_id format (should be alphanumeric)
  63. if (!preg_match('/^[a-zA-Z0-9_-]+$/', $upload_id)) {
  64. wp_send_json_error(array('message' => __('Invalid upload ID.', 'studiou-wc-free-photo-product')));
  65. return;
  66. }
  67. // Validate chunk file exists
  68. if (!isset($_FILES['chunk']) || $_FILES['chunk']['error'] !== UPLOAD_ERR_OK) {
  69. wp_send_json_error(array('message' => __('Chunk upload failed.', 'studiou-wc-free-photo-product')));
  70. return;
  71. }
  72. $chunks_dir = $this->get_chunks_dir();
  73. if (!file_exists($chunks_dir)) {
  74. wp_mkdir_p($chunks_dir);
  75. }
  76. // Store the chunk
  77. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $chunk_index;
  78. if (!move_uploaded_file($_FILES['chunk']['tmp_name'], $chunk_file)) {
  79. wp_send_json_error(array('message' => __('Failed to store chunk.', 'studiou-wc-free-photo-product')));
  80. return;
  81. }
  82. // If this is the last chunk, assemble the file
  83. if ($chunk_index === $total_chunks - 1) {
  84. // Clean any output that may have been generated
  85. while (ob_get_level()) {
  86. ob_end_clean();
  87. }
  88. $result = $this->assemble_chunks($upload_id, $total_chunks, $file_name, $product_id);
  89. // Clean again before sending JSON
  90. while (ob_get_level()) {
  91. ob_end_clean();
  92. }
  93. if (is_wp_error($result)) {
  94. wp_send_json_error(array('message' => $result->get_error_message()));
  95. return;
  96. }
  97. wp_send_json_success(array(
  98. 'complete' => true,
  99. 'attachment_id' => $result['attachment_id'],
  100. 'file_record_id' => $result['file_record_id'],
  101. 'thumbnail_url' => $result['thumbnail_url'],
  102. 'file_name' => $result['file_name'],
  103. ));
  104. return;
  105. }
  106. wp_send_json_success(array(
  107. 'complete' => false,
  108. 'chunk_index' => $chunk_index,
  109. ));
  110. }
  111. private function assemble_chunks($upload_id, $total_chunks, $file_name, $product_id) {
  112. $chunks_dir = $this->get_chunks_dir();
  113. $upload_dir = wp_upload_dir();
  114. // Create a subdirectory for free photo uploads
  115. $fpp_dir = $upload_dir['path'] . '/free-photo';
  116. if (!file_exists($fpp_dir)) {
  117. wp_mkdir_p($fpp_dir);
  118. }
  119. // Generate unique filename
  120. $ext = pathinfo($file_name, PATHINFO_EXTENSION);
  121. $base = sanitize_file_name(pathinfo($file_name, PATHINFO_FILENAME));
  122. $unique_name = $base . '_' . uniqid() . '.' . $ext;
  123. $assembled_path = $fpp_dir . '/' . $unique_name;
  124. // Assemble chunks
  125. $output = fopen($assembled_path, 'wb');
  126. if (!$output) {
  127. $this->cleanup_chunks($upload_id, $total_chunks);
  128. return new WP_Error('assemble_failed', __('Failed to create output file.', 'studiou-wc-free-photo-product'));
  129. }
  130. for ($i = 0; $i < $total_chunks; $i++) {
  131. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  132. if (!file_exists($chunk_file)) {
  133. fclose($output);
  134. unlink($assembled_path);
  135. $this->cleanup_chunks($upload_id, $total_chunks);
  136. return new WP_Error('chunk_missing', sprintf(
  137. __('Missing chunk %d.', 'studiou-wc-free-photo-product'),
  138. $i
  139. ));
  140. }
  141. $chunk_data = file_get_contents($chunk_file);
  142. fwrite($output, $chunk_data);
  143. }
  144. fclose($output);
  145. // Clean up chunk files
  146. $this->cleanup_chunks($upload_id, $total_chunks);
  147. // Validate file extension
  148. $allowed = $this->get_allowed_mime_types();
  149. $ext_lower = strtolower($ext);
  150. $valid = false;
  151. foreach ($allowed as $exts => $mime) {
  152. $ext_list = explode('|', $exts);
  153. if (in_array($ext_lower, $ext_list)) {
  154. $valid = true;
  155. break;
  156. }
  157. }
  158. if (!$valid) {
  159. unlink($assembled_path);
  160. return new WP_Error('invalid_type', __('File type not allowed.', 'studiou-wc-free-photo-product'));
  161. }
  162. // Create WP attachment
  163. $relative_path = str_replace($upload_dir['basedir'] . '/', '', $assembled_path);
  164. $filetype = wp_check_filetype($unique_name, $allowed);
  165. $attachment_data = array(
  166. 'post_mime_type' => $filetype['type'] ?: 'application/octet-stream',
  167. 'post_title' => sanitize_file_name($file_name),
  168. 'post_content' => '',
  169. 'post_status' => 'inherit',
  170. 'post_parent' => $product_id,
  171. );
  172. $attachment_id = wp_insert_attachment($attachment_data, $assembled_path, $product_id);
  173. if (is_wp_error($attachment_id)) {
  174. unlink($assembled_path);
  175. return $attachment_id;
  176. }
  177. // Generate metadata (wrapped in output buffer to prevent stray output corrupting JSON)
  178. require_once(ABSPATH . 'wp-admin/includes/image.php');
  179. ob_start();
  180. try {
  181. @set_time_limit(120);
  182. $metadata = @wp_generate_attachment_metadata($attachment_id, $assembled_path);
  183. if (!empty($metadata)) {
  184. wp_update_attachment_metadata($attachment_id, $metadata);
  185. }
  186. } catch (\Throwable $e) {
  187. if (defined('WP_DEBUG') && WP_DEBUG) {
  188. error_log('STUDIOU FPP: metadata generation failed - ' . $e->getMessage());
  189. }
  190. }
  191. ob_end_clean();
  192. // Assign media category
  193. $media_cat_id = Studiou_WC_FPP_Product::get_product_media_category($product_id);
  194. if ($media_cat_id) {
  195. wp_set_object_terms($attachment_id, array((int) $media_cat_id), 'studiou_media_category');
  196. }
  197. // Get thumbnail URL
  198. $thumbnail_url = '';
  199. $image_src = wp_get_attachment_image_src($attachment_id, 'thumbnail');
  200. if ($image_src) {
  201. $thumbnail_url = $image_src[0];
  202. } else {
  203. // Fallback for non-image files (RAW formats)
  204. $thumbnail_url = wp_mime_type_icon($attachment_id);
  205. }
  206. // Get session key for guests
  207. $session_key = '';
  208. if (!is_user_logged_in()) {
  209. if (WC()->session) {
  210. $session_key = WC()->session->get_customer_id();
  211. }
  212. }
  213. // Insert file record
  214. $file_record_id = $this->db->insert_file_record(array(
  215. 'product_id' => $product_id,
  216. 'attachment_id' => $attachment_id,
  217. 'customer_id' => get_current_user_id(),
  218. 'session_key' => $session_key,
  219. 'file_name' => $file_name,
  220. ));
  221. if (!$file_record_id) {
  222. wp_delete_attachment($attachment_id, true);
  223. return new WP_Error('record_failed', __('Failed to create file record.', 'studiou-wc-free-photo-product'));
  224. }
  225. return array(
  226. 'attachment_id' => $attachment_id,
  227. 'file_record_id' => $file_record_id,
  228. 'thumbnail_url' => $thumbnail_url,
  229. 'file_name' => $file_name,
  230. );
  231. }
  232. private function cleanup_chunks($upload_id, $total_chunks) {
  233. $chunks_dir = $this->get_chunks_dir();
  234. for ($i = 0; $i < $total_chunks; $i++) {
  235. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  236. if (file_exists($chunk_file)) {
  237. unlink($chunk_file);
  238. }
  239. }
  240. }
  241. public function handle_remove_upload() {
  242. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  243. $file_record_id = isset($_POST['file_record_id']) ? absint($_POST['file_record_id']) : 0;
  244. if (!$file_record_id) {
  245. wp_send_json_error(array('message' => __('Invalid file.', 'studiou-wc-free-photo-product')));
  246. return;
  247. }
  248. $record = $this->db->get_file_record($file_record_id);
  249. if (!$record) {
  250. wp_send_json_error(array('message' => __('File not found.', 'studiou-wc-free-photo-product')));
  251. return;
  252. }
  253. // Only allow removal if not yet linked to an order
  254. if ($record->order_id > 0) {
  255. wp_send_json_error(array('message' => __('Cannot remove a file linked to an order.', 'studiou-wc-free-photo-product')));
  256. return;
  257. }
  258. // Verify ownership
  259. $current_user_id = get_current_user_id();
  260. if ($current_user_id > 0 && (int) $record->customer_id !== $current_user_id) {
  261. wp_send_json_error(array('message' => __('Permission denied.', 'studiou-wc-free-photo-product')));
  262. return;
  263. }
  264. $this->db->delete_file_record($file_record_id);
  265. wp_send_json_success(array('message' => __('File removed.', 'studiou-wc-free-photo-product')));
  266. }
  267. }