class-studiou-wc-fpp-upload.php 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401
  1. <?php
  2. if (!defined('WPINC')) {
  3. die;
  4. }
  5. class Studiou_WC_FPP_Upload {
  6. /** @var Studiou_WC_FPP_DB */
  7. private $db;
  8. public function __construct($db) {
  9. $this->db = $db;
  10. add_action('wp_ajax_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  11. add_action('wp_ajax_nopriv_studiou_wcfpp_upload_chunk', array($this, 'handle_chunk_upload'));
  12. add_action('wp_ajax_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  13. add_action('wp_ajax_nopriv_studiou_wcfpp_remove_upload', array($this, 'handle_remove_upload'));
  14. }
  15. private function get_chunks_dir() {
  16. $upload_dir = wp_upload_dir();
  17. return $upload_dir['basedir'] . '/studiou-fpp-chunks';
  18. }
  19. private function get_allowed_mime_types() {
  20. return array(
  21. 'jpg|jpeg|jpe' => 'image/jpeg',
  22. 'png' => 'image/png',
  23. 'tiff|tif' => 'image/tiff',
  24. 'bmp' => 'image/bmp',
  25. 'psd' => 'image/vnd.adobe.photoshop',
  26. 'cr2' => 'image/x-canon-cr2',
  27. 'nef' => 'image/x-nikon-nef',
  28. 'arw' => 'image/x-sony-arw',
  29. 'dng' => 'image/x-adobe-dng',
  30. 'orf' => 'image/x-olympus-orf',
  31. 'rw2' => 'image/x-panasonic-rw2',
  32. 'raf' => 'image/x-fuji-raf',
  33. 'webp' => 'image/webp',
  34. );
  35. }
  36. public function handle_chunk_upload() {
  37. // Clean output buffers
  38. while (ob_get_level()) {
  39. ob_end_clean();
  40. }
  41. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  42. $product_id = isset($_POST['product_id']) ? absint($_POST['product_id']) : 0;
  43. $upload_id = isset($_POST['upload_id']) ? sanitize_text_field($_POST['upload_id']) : '';
  44. $chunk_index = isset($_POST['chunk_index']) ? absint($_POST['chunk_index']) : 0;
  45. $total_chunks = isset($_POST['total_chunks']) ? absint($_POST['total_chunks']) : 0;
  46. $file_name = isset($_POST['file_name']) ? sanitize_file_name($_POST['file_name']) : '';
  47. $file_size = isset($_POST['file_size']) ? absint($_POST['file_size']) : 0;
  48. // Validate product
  49. if (!$product_id || !Studiou_WC_FPP_Product::is_fpp_product($product_id)) {
  50. wp_send_json_error(array('message' => __('Invalid product.', 'studiou-wc-free-photo-product')));
  51. return;
  52. }
  53. // Validate file size
  54. $max_size = Studiou_WC_FPP_Product::get_product_max_file_size($product_id);
  55. if ($file_size > ($max_size * 1024 * 1024)) {
  56. wp_send_json_error(array('message' => sprintf(
  57. __('File is too large. Maximum size: %s MB', 'studiou-wc-free-photo-product'),
  58. $max_size
  59. )));
  60. return;
  61. }
  62. // Validate upload_id format (should be alphanumeric)
  63. if (!preg_match('/^[a-zA-Z0-9_-]+$/', $upload_id)) {
  64. wp_send_json_error(array('message' => __('Invalid upload ID.', 'studiou-wc-free-photo-product')));
  65. return;
  66. }
  67. // Validate chunk file exists
  68. if (!isset($_FILES['chunk']) || $_FILES['chunk']['error'] !== UPLOAD_ERR_OK) {
  69. wp_send_json_error(array('message' => __('Chunk upload failed.', 'studiou-wc-free-photo-product')));
  70. return;
  71. }
  72. $chunks_dir = $this->get_chunks_dir();
  73. if (!file_exists($chunks_dir)) {
  74. wp_mkdir_p($chunks_dir);
  75. }
  76. // Store the chunk
  77. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $chunk_index;
  78. if (!move_uploaded_file($_FILES['chunk']['tmp_name'], $chunk_file)) {
  79. wp_send_json_error(array('message' => __('Failed to store chunk.', 'studiou-wc-free-photo-product')));
  80. return;
  81. }
  82. // If this is the last chunk, assemble the file
  83. if ($chunk_index === $total_chunks - 1) {
  84. // Clean any output that may have been generated
  85. while (ob_get_level()) {
  86. ob_end_clean();
  87. }
  88. $result = $this->assemble_chunks($upload_id, $total_chunks, $file_name, $product_id);
  89. // Clean again before sending JSON
  90. while (ob_get_level()) {
  91. ob_end_clean();
  92. }
  93. if (is_wp_error($result)) {
  94. wp_send_json_error(array('message' => $result->get_error_message()));
  95. return;
  96. }
  97. // Store the upload reference in the WC session immediately, in the same request.
  98. // This avoids a race with a follow-up "set_upload_session" AJAX call that could
  99. // still be in flight when the user clicks Add to Cart.
  100. if (function_exists('WC') && WC()->session) {
  101. WC()->session->set('studiou_fpp_attachment_id', $result['attachment_id']);
  102. WC()->session->set('studiou_fpp_file_record_id', $result['file_record_id']);
  103. WC()->session->set('studiou_fpp_file_name', $result['file_name']);
  104. WC()->session->set('studiou_fpp_thumb_url', $result['thumbnail_url']);
  105. }
  106. wp_send_json_success(array(
  107. 'complete' => true,
  108. 'attachment_id' => $result['attachment_id'],
  109. 'file_record_id' => $result['file_record_id'],
  110. 'thumbnail_url' => $result['thumbnail_url'],
  111. 'preview_url' => $result['preview_url'],
  112. 'file_name' => $result['file_name'],
  113. ));
  114. return;
  115. }
  116. wp_send_json_success(array(
  117. 'complete' => false,
  118. 'chunk_index' => $chunk_index,
  119. ));
  120. }
  121. private function assemble_chunks($upload_id, $total_chunks, $file_name, $product_id) {
  122. $chunks_dir = $this->get_chunks_dir();
  123. $upload_dir = wp_upload_dir();
  124. // Create a subdirectory for free photo uploads
  125. $fpp_dir = $upload_dir['path'] . '/free-photo';
  126. if (!file_exists($fpp_dir)) {
  127. wp_mkdir_p($fpp_dir);
  128. }
  129. // Generate unique filename
  130. $ext = pathinfo($file_name, PATHINFO_EXTENSION);
  131. $base = sanitize_file_name(pathinfo($file_name, PATHINFO_FILENAME));
  132. $unique_name = $base . '_' . uniqid() . '.' . $ext;
  133. $assembled_path = $fpp_dir . '/' . $unique_name;
  134. // Assemble chunks
  135. $output = fopen($assembled_path, 'wb');
  136. if (!$output) {
  137. $this->cleanup_chunks($upload_id, $total_chunks);
  138. return new WP_Error('assemble_failed', __('Failed to create output file.', 'studiou-wc-free-photo-product'));
  139. }
  140. for ($i = 0; $i < $total_chunks; $i++) {
  141. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  142. if (!file_exists($chunk_file)) {
  143. fclose($output);
  144. unlink($assembled_path);
  145. $this->cleanup_chunks($upload_id, $total_chunks);
  146. return new WP_Error('chunk_missing', sprintf(
  147. __('Missing chunk %d.', 'studiou-wc-free-photo-product'),
  148. $i
  149. ));
  150. }
  151. $chunk_data = file_get_contents($chunk_file);
  152. fwrite($output, $chunk_data);
  153. }
  154. fclose($output);
  155. // Clean up chunk files
  156. $this->cleanup_chunks($upload_id, $total_chunks);
  157. // Validate file extension
  158. $allowed = $this->get_allowed_mime_types();
  159. $ext_lower = strtolower($ext);
  160. $valid = false;
  161. foreach ($allowed as $exts => $mime) {
  162. $ext_list = explode('|', $exts);
  163. if (in_array($ext_lower, $ext_list)) {
  164. $valid = true;
  165. break;
  166. }
  167. }
  168. if (!$valid) {
  169. unlink($assembled_path);
  170. return new WP_Error('invalid_type', __('File type not allowed.', 'studiou-wc-free-photo-product'));
  171. }
  172. // Validate image resolution (if limits are set)
  173. $res_error = $this->validate_image_resolution($assembled_path, $product_id);
  174. if (is_wp_error($res_error)) {
  175. unlink($assembled_path);
  176. return $res_error;
  177. }
  178. // Create WP attachment
  179. $relative_path = str_replace($upload_dir['basedir'] . '/', '', $assembled_path);
  180. $filetype = wp_check_filetype($unique_name, $allowed);
  181. $attachment_data = array(
  182. 'post_mime_type' => $filetype['type'] ?: 'application/octet-stream',
  183. 'post_title' => sanitize_file_name($file_name),
  184. 'post_content' => '',
  185. 'post_status' => 'inherit',
  186. 'post_parent' => $product_id,
  187. );
  188. $attachment_id = wp_insert_attachment($attachment_data, $assembled_path, $product_id);
  189. if (is_wp_error($attachment_id)) {
  190. unlink($assembled_path);
  191. return $attachment_id;
  192. }
  193. // Generate metadata (wrapped in output buffer to prevent stray output corrupting JSON)
  194. require_once(ABSPATH . 'wp-admin/includes/image.php');
  195. ob_start();
  196. try {
  197. @set_time_limit(120);
  198. $metadata = @wp_generate_attachment_metadata($attachment_id, $assembled_path);
  199. if (!empty($metadata)) {
  200. wp_update_attachment_metadata($attachment_id, $metadata);
  201. }
  202. } catch (\Throwable $e) {
  203. if (defined('WP_DEBUG') && WP_DEBUG) {
  204. error_log('STUDIOU FPP: metadata generation failed - ' . $e->getMessage());
  205. }
  206. }
  207. ob_end_clean();
  208. // Assign media category
  209. $media_cat_id = Studiou_WC_FPP_Product::get_product_media_category($product_id);
  210. if ($media_cat_id) {
  211. wp_set_object_terms($attachment_id, array((int) $media_cat_id), 'studiou_media_category');
  212. }
  213. // Get thumbnail URL (small - for upload preview)
  214. $thumbnail_url = '';
  215. $image_src = wp_get_attachment_image_src($attachment_id, 'thumbnail');
  216. if ($image_src) {
  217. $thumbnail_url = $image_src[0];
  218. } else {
  219. $thumbnail_url = wp_mime_type_icon($attachment_id);
  220. }
  221. // Get preview URL (larger - for product gallery replacement)
  222. $preview_url = '';
  223. $preview_src = wp_get_attachment_image_src($attachment_id, 'woocommerce_single');
  224. if ($preview_src) {
  225. $preview_url = $preview_src[0];
  226. } elseif ($image_src) {
  227. $preview_url = $image_src[0];
  228. }
  229. // Get session key for guests
  230. $session_key = '';
  231. if (!is_user_logged_in()) {
  232. if (WC()->session) {
  233. $session_key = WC()->session->get_customer_id();
  234. }
  235. }
  236. // Insert file record
  237. $file_record_id = $this->db->insert_file_record(array(
  238. 'product_id' => $product_id,
  239. 'attachment_id' => $attachment_id,
  240. 'customer_id' => get_current_user_id(),
  241. 'session_key' => $session_key,
  242. 'file_name' => $file_name,
  243. ));
  244. if (!$file_record_id) {
  245. wp_delete_attachment($attachment_id, true);
  246. return new WP_Error('record_failed', __('Failed to create file record.', 'studiou-wc-free-photo-product'));
  247. }
  248. return array(
  249. 'attachment_id' => $attachment_id,
  250. 'file_record_id' => $file_record_id,
  251. 'thumbnail_url' => $thumbnail_url,
  252. 'preview_url' => $preview_url,
  253. 'file_name' => $file_name,
  254. );
  255. }
  256. /**
  257. * Validate image resolution against product limits.
  258. * Width/height are commutable — a 3000x2000 image matches both 3000x2000 and 2000x3000 limits.
  259. */
  260. private function validate_image_resolution($file_path, $product_id) {
  261. $limits = Studiou_WC_FPP_Product::get_product_resolution_limits($product_id);
  262. // Skip if no limits set
  263. $has_min = ($limits['min_width'] > 0 || $limits['min_height'] > 0);
  264. $has_max = ($limits['max_width'] > 0 || $limits['max_height'] > 0);
  265. if (!$has_min && !$has_max) {
  266. return true;
  267. }
  268. // Get image dimensions
  269. $size = @getimagesize($file_path);
  270. if (!$size || !isset($size[0], $size[1])) {
  271. // Cannot determine dimensions (e.g. RAW files) — skip validation
  272. return true;
  273. }
  274. $img_w = $size[0];
  275. $img_h = $size[1];
  276. // Normalize: always compare min(w,h) vs min(limit_w,limit_h) and max(w,h) vs max(limit_w,limit_h)
  277. // This makes portrait/landscape interchangeable
  278. $img_short = min($img_w, $img_h);
  279. $img_long = max($img_w, $img_h);
  280. // Minimum resolution check
  281. if ($has_min) {
  282. $min_short = min($limits['min_width'] ?: 0, $limits['min_height'] ?: 0);
  283. $min_long = max($limits['min_width'] ?: 0, $limits['min_height'] ?: 0);
  284. // If only one dimension is set, use it for both
  285. if ($min_short === 0) $min_short = $min_long;
  286. if ($img_short < $min_short || $img_long < $min_long) {
  287. return new WP_Error('resolution_too_small', sprintf(
  288. __('Image resolution %1$dx%2$d px is too small. Minimum required: %3$dx%4$d px.', 'studiou-wc-free-photo-product'),
  289. $img_w, $img_h, $limits['min_width'] ?: $limits['min_height'], $limits['min_height'] ?: $limits['min_width']
  290. ));
  291. }
  292. }
  293. // Maximum resolution check
  294. if ($has_max) {
  295. $max_short = min($limits['max_width'] ?: PHP_INT_MAX, $limits['max_height'] ?: PHP_INT_MAX);
  296. $max_long = max($limits['max_width'] ?: PHP_INT_MAX, $limits['max_height'] ?: PHP_INT_MAX);
  297. if ($max_short === PHP_INT_MAX) $max_short = $max_long;
  298. if ($img_short > $max_short || $img_long > $max_long) {
  299. return new WP_Error('resolution_too_large', sprintf(
  300. __('Image resolution %1$dx%2$d px is too large. Maximum allowed: %3$dx%4$d px.', 'studiou-wc-free-photo-product'),
  301. $img_w, $img_h, $limits['max_width'] ?: $limits['max_height'], $limits['max_height'] ?: $limits['max_width']
  302. ));
  303. }
  304. }
  305. return true;
  306. }
  307. private function cleanup_chunks($upload_id, $total_chunks) {
  308. $chunks_dir = $this->get_chunks_dir();
  309. for ($i = 0; $i < $total_chunks; $i++) {
  310. $chunk_file = $chunks_dir . '/' . $upload_id . '_chunk_' . $i;
  311. if (file_exists($chunk_file)) {
  312. unlink($chunk_file);
  313. }
  314. }
  315. }
  316. public function handle_remove_upload() {
  317. check_ajax_referer('studiou-wcfpp-front-nonce', 'nonce');
  318. $file_record_id = isset($_POST['file_record_id']) ? absint($_POST['file_record_id']) : 0;
  319. if (!$file_record_id) {
  320. wp_send_json_error(array('message' => __('Invalid file.', 'studiou-wc-free-photo-product')));
  321. return;
  322. }
  323. $record = $this->db->get_file_record($file_record_id);
  324. if (!$record) {
  325. wp_send_json_error(array('message' => __('File not found.', 'studiou-wc-free-photo-product')));
  326. return;
  327. }
  328. // Only allow removal if not yet linked to an order
  329. if ($record->order_id > 0) {
  330. wp_send_json_error(array('message' => __('Cannot remove a file linked to an order.', 'studiou-wc-free-photo-product')));
  331. return;
  332. }
  333. // Verify ownership
  334. $current_user_id = get_current_user_id();
  335. if ($current_user_id > 0 && (int) $record->customer_id !== $current_user_id) {
  336. wp_send_json_error(array('message' => __('Permission denied.', 'studiou-wc-free-photo-product')));
  337. return;
  338. }
  339. $this->db->delete_file_record($file_record_id);
  340. wp_send_json_success(array('message' => __('File removed.', 'studiou-wc-free-photo-product')));
  341. }
  342. }