class-studiou-wc-fpp-upload.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323
  1. <?php
  2. if (!defined('WPINC')) {
  3. die;
  4. }
  5. class Studiou_WC_FPP_Upload {
  6. /** @var Studiou_WC_FPP_DB */
  7. private $db;
  8. public function __construct($db) {
  9. $this->db = $db;
  10. add_action('wp_ajax_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  11. add_action('wp_ajax_nopriv_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  12. add_action('wp_ajax_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  13. add_action('wp_ajax_nopriv_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  14. }
  15. private function get_chunks_dir() {
  16. $upload_dir = wp_upload_dir();
  17. return $upload_dir['basedir'] . '/studiou-fpp-chunks';
  18. }
  19. private function get_allowed_mime_types() {
  20. return array(
  21. 'jpg|jpeg|jpe' => 'image/jpeg',
  22. 'png' => 'image/png',
  23. 'tiff|tif' => 'image/tiff',
  24. 'bmp' => 'image/bmp',
  25. 'psd' => 'image/vnd.adobe.photoshop',
  26. 'cr2' => 'image/x-canon-cr2',
  27. 'nef' => 'image/x-nikon-nef',
  28. 'arw' => 'image/x-sony-arw',
  29. 'dng' => 'image/x-adobe-dng',
  30. 'orf' => 'image/x-olympus-orf',
  31. 'rw2' => 'image/x-panasonic-rw2',
  32. 'raf' => 'image/x-fuji-raf',
  33. 'webp' => 'image/webp',
  34. );
  35. }
  36. public function handle_chunk_upload() {
  37. // Clean output buffers
  38. while (ob_get_level()) {
  39. ob_end_clean();
  40. }
  41. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  42. $product_id = isset($_POST['product_id']) ? absint($_POST['product_id']) : 0;
  43. $upload_id = isset($_POST['upload_id']) ? sanitize_text_field($_POST['upload_id']) : '';
  44. $chunk_index = isset($_POST['chunk_index']) ? absint($_POST['chunk_index']) : 0;
  45. $total_chunks = isset($_POST['total_chunks']) ? absint($_POST['total_chunks']) : 0;
  46. $file_name = isset($_POST['file_name']) ? sanitize_file_name($_POST['file_name']) : '';
  47. $file_size = isset($_POST['file_size']) ? absint($_POST['file_size']) : 0;
  48. // Validate product
  49. if (!$product_id || !Studiou_WC_FPP_Product::is_fpp_product($product_id)) {
  50. wp_send_json_error(array('message' => __('Invalid product.', 'studiou-wc-free-photo-product')));
  51. return;
  52. }
  53. // Validate file size
  54. $max_size = Studiou_WC_FPP_Product::get_product_max_file_size($product_id);
  55. if ($file_size > ($max_size * 1024 * 1024)) {
  56. wp_send_json_error(array('message' => sprintf(
  57. __('File is too large. Maximum size: %s MB', 'studiou-wc-free-photo-product'),
  58. $max_size
  59. )));
  60. return;
  61. }
  62. // Validate upload_id format (should be alphanumeric)
  63. if (!preg_match('/^[a-zA-Z0-9_-]+$/', $upload_id)) {
  64. wp_send_json_error(array('message' => __('Invalid upload ID.', 'studiou-wc-free-photo-product')));
  65. return;
  66. }
  67. // Validate chunk file exists
  68. if (!isset($_FILES['chunk']) || $_FILES['chunk']['error'] !== UPLOAD_ERR_OK) {
  69. wp_send_json_error(array('message' => __('Chunk upload failed.', 'studiou-wc-free-photo-product')));
  70. return;
  71. }
  72. $chunks_dir = $this->get_chunks_dir();
  73. if (!file_exists($chunks_dir)) {
  74. wp_mkdir_p($chunks_dir);
  75. }
  76. // Store the chunk
  77. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $chunk_index;
  78. if (!move_uploaded_file($_FILES['chunk']['tmp_name'], $chunk_file)) {
  79. wp_send_json_error(array('message' => __('Failed to store chunk.', 'studiou-wc-free-photo-product')));
  80. return;
  81. }
  82. // If this is the last chunk, assemble the file
  83. if ($chunk_index === $total_chunks - 1) {
  84. // Clean any output that may have been generated
  85. while (ob_get_level()) {
  86. ob_end_clean();
  87. }
  88. $result = $this->assemble_chunks($upload_id, $total_chunks, $file_name, $product_id);
  89. // Clean again before sending JSON
  90. while (ob_get_level()) {
  91. ob_end_clean();
  92. }
  93. if (is_wp_error($result)) {
  94. wp_send_json_error(array('message' => $result->get_error_message()));
  95. return;
  96. }
  97. wp_send_json_success(array(
  98. 'complete' => true,
  99. 'attachment_id' => $result['attachment_id'],
  100. 'file_record_id' => $result['file_record_id'],
  101. 'thumbnail_url' => $result['thumbnail_url'],
  102. 'preview_url' => $result['preview_url'],
  103. 'file_name' => $result['file_name'],
  104. ));
  105. return;
  106. }
  107. wp_send_json_success(array(
  108. 'complete' => false,
  109. 'chunk_index' => $chunk_index,
  110. ));
  111. }
  112. private function assemble_chunks($upload_id, $total_chunks, $file_name, $product_id) {
  113. $chunks_dir = $this->get_chunks_dir();
  114. $upload_dir = wp_upload_dir();
  115. // Create a subdirectory for free photo uploads
  116. $fpp_dir = $upload_dir['path'] . '/free-photo';
  117. if (!file_exists($fpp_dir)) {
  118. wp_mkdir_p($fpp_dir);
  119. }
  120. // Generate unique filename
  121. $ext = pathinfo($file_name, PATHINFO_EXTENSION);
  122. $base = sanitize_file_name(pathinfo($file_name, PATHINFO_FILENAME));
  123. $unique_name = $base . '_' . uniqid() . '.' . $ext;
  124. $assembled_path = $fpp_dir . '/' . $unique_name;
  125. // Assemble chunks
  126. $output = fopen($assembled_path, 'wb');
  127. if (!$output) {
  128. $this->cleanup_chunks($upload_id, $total_chunks);
  129. return new WP_Error('assemble_failed', __('Failed to create output file.', 'studiou-wc-free-photo-product'));
  130. }
  131. for ($i = 0; $i < $total_chunks; $i++) {
  132. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  133. if (!file_exists($chunk_file)) {
  134. fclose($output);
  135. unlink($assembled_path);
  136. $this->cleanup_chunks($upload_id, $total_chunks);
  137. return new WP_Error('chunk_missing', sprintf(
  138. __('Missing chunk %d.', 'studiou-wc-free-photo-product'),
  139. $i
  140. ));
  141. }
  142. $chunk_data = file_get_contents($chunk_file);
  143. fwrite($output, $chunk_data);
  144. }
  145. fclose($output);
  146. // Clean up chunk files
  147. $this->cleanup_chunks($upload_id, $total_chunks);
  148. // Validate file extension
  149. $allowed = $this->get_allowed_mime_types();
  150. $ext_lower = strtolower($ext);
  151. $valid = false;
  152. foreach ($allowed as $exts => $mime) {
  153. $ext_list = explode('|', $exts);
  154. if (in_array($ext_lower, $ext_list)) {
  155. $valid = true;
  156. break;
  157. }
  158. }
  159. if (!$valid) {
  160. unlink($assembled_path);
  161. return new WP_Error('invalid_type', __('File type not allowed.', 'studiou-wc-free-photo-product'));
  162. }
  163. // Create WP attachment
  164. $relative_path = str_replace($upload_dir['basedir'] . '/', '', $assembled_path);
  165. $filetype = wp_check_filetype($unique_name, $allowed);
  166. $attachment_data = array(
  167. 'post_mime_type' => $filetype['type'] ?: 'application/octet-stream',
  168. 'post_title' => sanitize_file_name($file_name),
  169. 'post_content' => '',
  170. 'post_status' => 'inherit',
  171. 'post_parent' => $product_id,
  172. );
  173. $attachment_id = wp_insert_attachment($attachment_data, $assembled_path, $product_id);
  174. if (is_wp_error($attachment_id)) {
  175. unlink($assembled_path);
  176. return $attachment_id;
  177. }
  178. // Generate metadata (wrapped in output buffer to prevent stray output corrupting JSON)
  179. require_once(ABSPATH . 'wp-admin/includes/image.php');
  180. ob_start();
  181. try {
  182. @set_time_limit(120);
  183. $metadata = @wp_generate_attachment_metadata($attachment_id, $assembled_path);
  184. if (!empty($metadata)) {
  185. wp_update_attachment_metadata($attachment_id, $metadata);
  186. }
  187. } catch (\Throwable $e) {
  188. if (defined('WP_DEBUG') && WP_DEBUG) {
  189. error_log('STUDIOU FPP: metadata generation failed - ' . $e->getMessage());
  190. }
  191. }
  192. ob_end_clean();
  193. // Assign media category
  194. $media_cat_id = Studiou_WC_FPP_Product::get_product_media_category($product_id);
  195. if ($media_cat_id) {
  196. wp_set_object_terms($attachment_id, array((int) $media_cat_id), 'studiou_media_category');
  197. }
  198. // Get thumbnail URL (small - for upload preview)
  199. $thumbnail_url = '';
  200. $image_src = wp_get_attachment_image_src($attachment_id, 'thumbnail');
  201. if ($image_src) {
  202. $thumbnail_url = $image_src[0];
  203. } else {
  204. $thumbnail_url = wp_mime_type_icon($attachment_id);
  205. }
  206. // Get preview URL (larger - for product gallery replacement)
  207. $preview_url = '';
  208. $preview_src = wp_get_attachment_image_src($attachment_id, 'woocommerce_single');
  209. if ($preview_src) {
  210. $preview_url = $preview_src[0];
  211. } elseif ($image_src) {
  212. $preview_url = $image_src[0];
  213. }
  214. // Get session key for guests
  215. $session_key = '';
  216. if (!is_user_logged_in()) {
  217. if (WC()->session) {
  218. $session_key = WC()->session->get_customer_id();
  219. }
  220. }
  221. // Insert file record
  222. $file_record_id = $this->db->insert_file_record(array(
  223. 'product_id' => $product_id,
  224. 'attachment_id' => $attachment_id,
  225. 'customer_id' => get_current_user_id(),
  226. 'session_key' => $session_key,
  227. 'file_name' => $file_name,
  228. ));
  229. if (!$file_record_id) {
  230. wp_delete_attachment($attachment_id, true);
  231. return new WP_Error('record_failed', __('Failed to create file record.', 'studiou-wc-free-photo-product'));
  232. }
  233. return array(
  234. 'attachment_id' => $attachment_id,
  235. 'file_record_id' => $file_record_id,
  236. 'thumbnail_url' => $thumbnail_url,
  237. 'preview_url' => $preview_url,
  238. 'file_name' => $file_name,
  239. );
  240. }
  241. private function cleanup_chunks($upload_id, $total_chunks) {
  242. $chunks_dir = $this->get_chunks_dir();
  243. for ($i = 0; $i < $total_chunks; $i++) {
  244. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  245. if (file_exists($chunk_file)) {
  246. unlink($chunk_file);
  247. }
  248. }
  249. }
  250. public function handle_remove_upload() {
  251. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  252. $file_record_id = isset($_POST['file_record_id']) ? absint($_POST['file_record_id']) : 0;
  253. if (!$file_record_id) {
  254. wp_send_json_error(array('message' => __('Invalid file.', 'studiou-wc-free-photo-product')));
  255. return;
  256. }
  257. $record = $this->db->get_file_record($file_record_id);
  258. if (!$record) {
  259. wp_send_json_error(array('message' => __('File not found.', 'studiou-wc-free-photo-product')));
  260. return;
  261. }
  262. // Only allow removal if not yet linked to an order
  263. if ($record->order_id > 0) {
  264. wp_send_json_error(array('message' => __('Cannot remove a file linked to an order.', 'studiou-wc-free-photo-product')));
  265. return;
  266. }
  267. // Verify ownership
  268. $current_user_id = get_current_user_id();
  269. if ($current_user_id > 0 && (int) $record->customer_id !== $current_user_id) {
  270. wp_send_json_error(array('message' => __('Permission denied.', 'studiou-wc-free-photo-product')));
  271. return;
  272. }
  273. $this->db->delete_file_record($file_record_id);
  274. wp_send_json_success(array('message' => __('File removed.', 'studiou-wc-free-photo-product')));
  275. }
  276. }