Commit Graph
16 Commits
Author SHA1 Message Date
Isaac ConnorandClaude Opus 5 dc8e22d42a fix: quote the download filename so Chrome doesn't save the export as index.php
The merged mp4 export is named '<Monitor> <start> to <end>.mp4', so it contains
spaces and colons, and download.php emitted it as a bare unquoted filename=
parameter. That is not a valid RFC 6266 token, so browsers that parse
Content-Disposition strictly find no filename and fall back to naming the
download after the last path segment of the URL - index.php. Firefox is lenient
and accepted it, which is why the report was Chrome-on-Windows only.

Add contentDispositionAttachment(), which emits a quoted ASCII filename with the
Windows-illegal characters folded to '_', plus the untouched name as RFC 5987
filename* whenever that folding changed anything, so unicode monitor names still
arrive intact.

Also in that path:
- urlencode the file and export_root query parameters; a monitor name containing
  '&' or '+' would otherwise split or mis-decode the download URL. Read them back
  in export.js with URLSearchParams so the link text shows the decoded name.
- drop the stray ';' from Content-Length, which made the value unparseable.
- silence the shutdown unlink()s, whose warnings would be appended to the body
  of a download that had already started.
- log $this->filenamePath, not an undefined local, on the unreadable-file path.

Tests: tests/php/test_download_content_disposition.php, 12 assertions, all pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nr76CednxtDt2nPuq6WrbL
2026-09-03 20:17:16 -04:00
IgorA100 ee655c2e64 Set $maxTime to the current time only if $endSecs is missing in the incomplete event or if $maxTime is empty after looping through all events. (download_functions.php) 2026-05-13 11:52:34 +03:00
IgorA100 f7b21d3923 Return false instead of return "" (download_functions.php) 2026-05-13 10:29:50 +03:00
IgorA100 bbcd07634d For now, we'll only search for "mp4" files (download_functions.php)
In the future, we'll need to add analysis of all files for merging and use that to decide on the output file format.
2026-05-11 00:46:20 +03:00
IgorA100 5a8a88faab Gjntdownload_functions.php 2026-05-11 00:04:13 +03:00
IgorA100 1d59afd1d2 Added checks (download_functions.php) 2026-05-10 15:48:25 +03:00
IgorA100andCopilot Autofix powered by AI 3719f83c03 Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-05-10 11:37:09 +03:00
IgorA100 27b744e941 Code optimization (download_functions.php) 2026-05-09 16:18:12 +03:00
IgorA100 7f7d760030 Fix: Correct end timestamp of events when exporting MP4 for multiple events (download_functions.php)
Closed: #4767
Also, an error when downloading an incomplete event has been fixed. This error occurred when $Event->DefaultVideo() started storing the value 'index.m3u8' instead of the incomplete event filename.
2026-05-09 15:37:23 +03:00
copilot-swe-agent[bot]andconnortechnology b5605e01c1 fix: add -- end-of-options marker before filename operands in tar/zip/gzip commands
Co-authored-by: connortechnology <925519+connortechnology@users.noreply.github.com>
2026-03-09 16:55:56 +00:00
Isaac ConnorandClaude Opus 4.6 b3a7c05f07 fix: close SQL injection, command injection, and shell escaping gaps
FilterTerm.php:
- Use intval() on AlarmedZoneId value in SQL subquery to prevent
  injection via crafted filter val

report_event_audit.php, montagereview.php:
- Cast $selected_monitor_ids through array_map('intval') before
  interpolating into SQL IN clause (values come from $_REQUEST)

download_functions.php:
- Replace manual single-quoting with escapeshellarg() for merged
  file name in ffmpeg, tar, and zip commands (monitor names can
  contain shell metacharacters including single quotes)
- Same fix for export list file path

export_functions.php:
- Use escapeshellarg() on source and destination paths in cp -as
  commands during event export

functions.php:
- Validate column keys in getFormChanges() against /^[a-zA-Z0-9_]+$/
  to prevent SQL injection via crafted array keys from $_REQUEST
- Use dbEscape() and intval() for image/document MIME type and size
  fields instead of raw string interpolation
- Replace escapeshellcmd() with escapeshellarg() in deletePath()
  rm -rf command

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 10:48:23 -04:00
IgorA100 da63055802 Now you can download without archiving, and archiving is performed in stages as new MP4 files are generated (download_functions.php)
This allows you to save significant disk space.
2026-01-09 16:26:33 +03:00
Isaac Connor 8a496f5d17 Remove extra comma that now breaks php 2024-06-04 09:39:22 -04:00
IgorA100 a204a973f1 Code optimization 2024-02-09 18:09:51 +03:00
IgorA100 d0dc4bcbe1 Sorting an array of events when merging into a file
When merging events into a file, they must first be sorted by time and start date of the event.
2024-02-09 17:34:06 +03:00
Isaac Connor 44c5c3c70c Introduce new download mode that concats event videos into 1 file per monitor 2023-10-04 12:04:11 -04:00