Files
website-typo3/web/typo3conf/ext/ep_theme/extimg.php
T
2018-04-18 17:24:00 +02:00

58 lines
1.6 KiB
PHP

<?php
/***************************************************************
*
* Copyright notice
*
* (c) 2016 Björn Fromme <[email protected]>, dreipunktnull
*
* All rights reserved
*
* This script is part of the TYPO3 project. The TYPO3 project is
* free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 3 of the License, or
* (at your option) any later version.
*
* The GNU General Public License can be found at
* http://www.gnu.org/copyleft/gpl.html.
*
* This script is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* This copyright notice MUST APPEAR in all copies of the script!
***************************************************************/
$url = urldecode($_GET['url']);
$token = $_GET['token'];
$typo3Config = require('../../LocalConfiguration.php');
$encryptionKey = $typo3Config['SYS']['encryptionKey'];
$hash = sha1($url . $encryptionKey);
if ($hash !== $token) {
die('Access denied');
}
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_TIMEOUT, 5);
curl_setopt($ch, CURLOPT_HEADER, 1);
curl_setopt($ch, CURLOPT_NOBODY, 1);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$headers = curl_exec($ch);
if ($headers === false) {
exit;
}
foreach (explode("\r\n", $headers) as $header) {
header($header);
}
readfile($url);
exit;