##// END OF EJS Templates
Fix in AttachmentsController#show....
Jean-Philippe Lang -
r2280:dacddd989720
parent child
Show More
@@ -1,74 +1,74
1 # Redmine - project management software
1 # Redmine - project management software
2 # Copyright (C) 2006-2008 Jean-Philippe Lang
2 # Copyright (C) 2006-2008 Jean-Philippe Lang
3 #
3 #
4 # This program is free software; you can redistribute it and/or
4 # This program is free software; you can redistribute it and/or
5 # modify it under the terms of the GNU General Public License
5 # modify it under the terms of the GNU General Public License
6 # as published by the Free Software Foundation; either version 2
6 # as published by the Free Software Foundation; either version 2
7 # of the License, or (at your option) any later version.
7 # of the License, or (at your option) any later version.
8 #
8 #
9 # This program is distributed in the hope that it will be useful,
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 # GNU General Public License for more details.
12 # GNU General Public License for more details.
13 #
13 #
14 # You should have received a copy of the GNU General Public License
14 # You should have received a copy of the GNU General Public License
15 # along with this program; if not, write to the Free Software
15 # along with this program; if not, write to the Free Software
16 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
16 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
17
17
18 class AttachmentsController < ApplicationController
18 class AttachmentsController < ApplicationController
19 before_filter :find_project
19 before_filter :find_project
20 before_filter :read_authorize, :except => :destroy
20 before_filter :read_authorize, :except => :destroy
21 before_filter :delete_authorize, :only => :destroy
21 before_filter :delete_authorize, :only => :destroy
22
22
23 verify :method => :post, :only => :destroy
23 verify :method => :post, :only => :destroy
24
24
25 def show
25 def show
26 if @attachment.is_diff?
26 if @attachment.is_diff?
27 @diff = File.new(@attachment.diskfile, "rb").read
27 @diff = File.new(@attachment.diskfile, "rb").read
28 render :action => 'diff'
28 render :action => 'diff'
29 elsif @attachment.is_text?
29 elsif @attachment.is_text?
30 @content = File.new(@attachment.diskfile, "rb").read
30 @content = File.new(@attachment.diskfile, "rb").read
31 render :action => 'file'
31 render :action => 'file'
32 elsif
32 else
33 download
33 download
34 end
34 end
35 end
35 end
36
36
37 def download
37 def download
38 if @attachment.container.is_a?(Version) || @attachment.container.is_a?(Project)
38 if @attachment.container.is_a?(Version) || @attachment.container.is_a?(Project)
39 @attachment.increment_download
39 @attachment.increment_download
40 end
40 end
41
41
42 # images are sent inline
42 # images are sent inline
43 send_file @attachment.diskfile, :filename => filename_for_content_disposition(@attachment.filename),
43 send_file @attachment.diskfile, :filename => filename_for_content_disposition(@attachment.filename),
44 :type => @attachment.content_type,
44 :type => @attachment.content_type,
45 :disposition => (@attachment.image? ? 'inline' : 'attachment')
45 :disposition => (@attachment.image? ? 'inline' : 'attachment')
46
46
47 end
47 end
48
48
49 def destroy
49 def destroy
50 # Make sure association callbacks are called
50 # Make sure association callbacks are called
51 @attachment.container.attachments.delete(@attachment)
51 @attachment.container.attachments.delete(@attachment)
52 redirect_to :back
52 redirect_to :back
53 rescue ::ActionController::RedirectBackError
53 rescue ::ActionController::RedirectBackError
54 redirect_to :controller => 'projects', :action => 'show', :id => @project
54 redirect_to :controller => 'projects', :action => 'show', :id => @project
55 end
55 end
56
56
57 private
57 private
58 def find_project
58 def find_project
59 @attachment = Attachment.find(params[:id])
59 @attachment = Attachment.find(params[:id])
60 # Show 404 if the filename in the url is wrong
60 # Show 404 if the filename in the url is wrong
61 raise ActiveRecord::RecordNotFound if params[:filename] && params[:filename] != @attachment.filename
61 raise ActiveRecord::RecordNotFound if params[:filename] && params[:filename] != @attachment.filename
62 @project = @attachment.project
62 @project = @attachment.project
63 rescue ActiveRecord::RecordNotFound
63 rescue ActiveRecord::RecordNotFound
64 render_404
64 render_404
65 end
65 end
66
66
67 def read_authorize
67 def read_authorize
68 @attachment.visible? ? true : deny_access
68 @attachment.visible? ? true : deny_access
69 end
69 end
70
70
71 def delete_authorize
71 def delete_authorize
72 @attachment.deletable? ? true : deny_access
72 @attachment.deletable? ? true : deny_access
73 end
73 end
74 end
74 end
General Comments 0
You need to be logged in to leave comments. Login now