We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10357
    • 573 Posts
    there is a typo, change fp to fd wherever it appears. e.g [+fp.class+] to [+fd.class+]
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      Where is the patched version?
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 15987
        • 786 Posts
        Here is a quick and dirty fix. unzip and upload the attached file to the assets/snippets/fileDownload folder.

        I am working on a more robust fix, but this will work for now.

        This fix is for version 2.0
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          None of my archive utilities can unzip this.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 15987
            • 786 Posts
            ok, copy and paste the following into you download.php file:

            <?php
            /**********************************
            FileDownload (v2.0beta)
            Created By: Kyle Jaebker
            Last Modified: 10/15/2006
            download.php - used to download file and track number of downloads
            **********************************/
            
            $incomingParams = base64_decode($_GET['dwn']);
            
            if (!$incomingParams) {
            	echo 'Invalid parameters';
            	return;
            }
            
            list($dwnParams['file'],$dwnParams['incFileSize'],$dwnParams['size'],$dwnParams['dwnCount'],$dwnParams['useDb']) = explode('||',$incomingParams);
            
            if (substr_count($dwnParams['file'], '..') > 0 or substr($dwnParams['file'], 0, 1) == '/') {
            	echo 'Invalid Filename';
            	return;
            }
            
            $dwnParams['countfile'] = $dwnParams['file'];
            $dwnParams['file'] = '../../../' . $dwnParams['file'];
            
            if (strstr($dwnParams['file'], 'manager') || strstr($dwnParams['file'], 'config.inc.php')) die();
            
            $fileName = substr($dwnParams['file'],strrpos($dwnParams['file'],'/')+1);
            
            if ( !file_exists($dwnParams['file']) ) {
            	echo 'File not found: ' . $fileName;
            	return;
            }
            
            $ext = explode('.', $fileName);
            if ( sizeof($ext) < 2 ) {
            	echo 'Invalid filename: should have extension';
            	return;
            }
            
            $countPath = 'filecount.txt';
            
            if ($dwnParams['dwnCount']) {
            	if ($dwnParams['useDb']) {
            		include_once '../../../manager/includes/config.inc.php';
            		include_once 'data.db.class.inc.php';
            		$fdData = new FdDataDb($database_server,$dbase,$database_user,$database_password,$table_prefix);
            		
            		$fdData->connect();
            		$fdData->updateCount($dwnParams['countfile']);
            		$fdData->disconnect();
            	} else {
            		if(!$handle = fopen($countPath,'r+')) {
            		    return 'file open failed: '.$countPath;
            		} else {
            		    $i = 0;
            		    // Get the files already counted
            		    while ((list($fname,$count) = fgetcsv($handle, 1000)) !== FALSE) {
            		            $files[$i]['name'] = $fname;
            		            $files[$i]['count']  = $count;
            		            $i++;
            		    }
            
            		    $fileInTxt = 0;
            		    // Check if current file has been counted
            		    foreach ( array_keys($files) as $key ) {
            		        $myFile =& $files[$key];
            		        if ($myFile['name'] == $dwnParams['countfile']) {
            		            $myFile['count']++;
            		            $fileInTxt = 1;
            		            break;
            		        }
            		    }
            		    fclose($handle);
            		    // If file has not been counted add it to the array
            		    if (!$fileInTxt) {
            		        $i++;
            		        $files[$i]['name'] = $dwnParams['countfile'];
            		        $files[$i]['count'] = 1;
            		    }
            		    // ReOutput the count file
            		    $handle = fopen($countPath,'w');
            		    foreach ( $files as $file ) {
            		        $str = $file['name'] . ',' . $file['count'] . '\r\n';
            		        fwrite($handle, $str);
            		    }
            		    fclose($handle);
            		}	
            	}
            }
            
            if (preg_match('#Opera(/| )([0-9].[0-9]{1,2})#', getenv('HTTP_USER_AGENT')) or
            	preg_match('#MSIE ([0-9].[0-9]{1,2})#', getenv('HTTP_USER_AGENT'))) {
                $exeType = 'application/octetstream';
            } else {
                $exeType = 'application/octet-stream';
            }
            
            $extension = substr($fileName,strrpos($fileName,'.')+1);
            
            switch($extension) {
            	case 'asf':     $type = 'video/x-ms-asf';               break;
            	case 'avi':     $type = 'video/x-msvideo';              break;
            	case 'bin':     $type = 'application/octet-stream';     break;
            	case 'bmp':     $type = 'image/bmp';                    break;
            	case 'cgi':     $type = 'magnus-internal/cgi';          break;
            	case 'css':     $type = 'text/css';                     break;
            	case 'dcr':     $type = 'application/x-director';       break;
            	case 'dxr':     $type = 'application/x-director';       break;
            	case 'dll':     $type = 'application/octet-stream';     break;
            	case 'doc':     $type = 'application/msword';           break;
            	case 'exe':     $type = $exeType;      					break;
            	case 'gif':     $type = 'image/gif';                    break;
            	case 'gtar':    $type = 'application/x-gtar';           break;
            	case 'gz':      $type = 'application/gzip';             break;
            	case 'htm':     $type = 'text/html';                    break;
            	case 'html':    $type = 'text/html';                    break;
            	case 'iso':     $type = 'application/octet-stream';     break;
            	case 'jar':     $type = 'application/java-archive';     break;
            	case 'java':    $type = 'text/x-java-source';           break;
            	case 'jnlp':    $type = 'application/x-java-jnlp-file'; break;
            	case 'js':      $type = 'application/x-javascript';     break;
            	case 'jpg':     $type = 'image/jpg';                    break;
            	case 'jpe':     $type = 'image/jpg';                    break;
            	case 'jpeg':    $type = 'image/jpg';                    break;
            	case 'lzh':     $type = 'application/octet-stream';     break;
            	case 'mdb':     $type = 'application/mdb';              break;
            	case 'mid':     $type = 'audio/x-midi';                 break;
            	case 'midi':    $type = 'audio/x-midi';                 break;
            	case 'mov':     $type = 'video/quicktime';              break;
            	case 'mp2':     $type = 'audio/x-mpeg';                 break;
            	case 'mp3':     $type = 'audio/mpeg';                   break;
            	case 'mpg':     $type = 'video/mpeg';                   break;
            	case 'mpe':     $type = 'video/mpeg';                   break;
            	case 'mpeg':    $type = 'video/mpeg';                   break;
            	case 'pdf':     $type = 'application/pdf';              break;
            	case 'php':     $type = 'application/x-httpd-php';      break;
            	case 'php3':    $type = 'application/x-httpd-php3';     break;
            	case 'php4':    $type = 'application/x-httpd-php';      break;
            	case 'png':     $type = 'image/png';                    break;
            	case 'ppt':     $type = 'application/mspowerpoint';     break;
            	case 'qt':      $type = 'video/quicktime';              break;
            	case 'qti':     $type = 'image/x-quicktime';            break;
            	case 'rar':     $type = 'encoding/x-compress';          break;
            	case 'ra':      $type = 'audio/x-pn-realaudio';         break;
            	case 'rm':      $type = 'audio/x-pn-realaudio';         break;
            	case 'ram':     $type = 'audio/x-pn-realaudio';         break;
            	case 'rtf':     $type = 'application/rtf';              break;
            	case 'swa':     $type = 'application/x-director';       break;
            	case 'swf':     $type = 'application/x-shockwave-flash';break;
            	case 'tar':     $type = 'application/x-tar';            break;
            	case 'tgz':     $type = 'application/gzip';             break;
            	case 'tif':     $type = 'image/tiff';                   break;
            	case 'tiff':    $type = 'image/tiff';                   break;
            	case 'torrent': $type = 'application/x-bittorrent';     break;
            	case 'txt':     $type = 'text/plain';                   break;
            	case 'wav':     $type = 'audio/wav';                    break;
            	case 'wma':     $type = 'audio/x-ms-wma';               break;
            	case 'wmv':     $type = 'video/x-ms-wmv';               break;
            	case 'xls':     $type = 'application/xls';              break;
            	case 'xml':     $type = 'application/xml';              break;
            	case '7z':      $type = 'application/x-compress';       break;
            	case 'zip':     $type = 'application/x-zip-compressed'; break;
            	default:        $type = 'application/force-download';   break;
            }
            
            $fp = fopen($dwnParams['file'],'r');
            $filedata = fread($fp,filesize($dwnParams['file']));
            fclose($fp);
            
            //Send the user their download
            header('Pragma: private');
            header('Expires: 0');
            header('Cache-Control: private, must-revalidate, post-check=0, pre-check=0');
            header('Content-Type: ' . $type);
            header('Content-Disposition: attachment; filename="'.$fileName.'";');
            header('Accept-Ranges: bytes');
            header('Content-Transfer-Encoding: binary');
            if ($dwnParams['incFileSize']) {
            	header('Content-Length: ' . $dwnParams['size']);
            }
            print $filedata;
            ?>
            
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              Just the one line added ( 26 ) ?
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 25663 MODX Staff
                • 12,272 Posts
                Yep ... keeps folks out of the manager folder and config.inc.php file in particular.
                  Ryan Thrash, MODX Co-Founder
                  Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
                  • 28042 ☆ A M B ☆
                  • 24,524 Posts
                  Ok, thanks... a lot easier to just go add that line to all the installations I’ve got.
                    Studying MODX in the desert - http://sottwell.com
                    Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                    Join the Slack Community - http://modx.org
                    • 4095
                    • 372 Posts
                    Ok, I figured it out, I’m an idiot rolleyes

                    I copied the download.php from the filedownload folder into the snippet instead of the download2.0.php from the root...... doh shocked

                    [s]I’ve just upgraded from version 1.7 to 2.0 and now having problems.

                    I get the error: Invalid parameters

                    I striped my Snippet call to the most basic and yet still having the issue.
                    [!FileDownload? &getFolder=`assets/files/resources`!]


                    I noticed the following lines in the Snippet
                    $incomingParams = base64_decode($_GET['dwn']);
                     
                     if (!$incomingParams) {
                     	echo 'Invalid parameters';
                     	return;
                     }
                    }


                    If I remove them I then get the error: Invalid filename: should have extension

                    They do have extensions and the same files used to work fine in v1.7. I’m using UTF-8, would that have anything to do with it?

                    Any suggestions?

                    [EDIT: I have also tried the patched version below with no luck]
                      [img]http://www.emanz.ac.nz/assets/images/logo/emanz-icon_16x16.gif[/img] Emergency Management Academy of New Zealand [br] http://www.emanz.ac.nz[br][br]MODx Sandbox Login: sandbox Password: castle [br]
                      Admin Sandbox Login: sandbox Password: castle
                      • 4095
                      • 372 Posts
                      Awesome Snippet, got it working and almost solved a request I had from the Chief Executive.

                      Hopefully the next version intergrates some of OnO’s work (with the reported issues fixed). Currently I have a download sections for members only, but once the URL is known anyone can download it. There seems to be no way to have a directory under /assests/files protected sad

                      [EDIT: also for the wish list is to have [+fd.path+] able to use the description rather than filename. You can set the folder to use the description [+fd.description+], yet the path still shows the actual folder name which is confussing to some user as the don’t match]

                      Thanks for you work on this getting it to where it is now..... Damn I love MODx and the Community smiley

                      OnO’s hack: http://modxcms.com/forums/index.php/topic,9276.0.html
                        [img]http://www.emanz.ac.nz/assets/images/logo/emanz-icon_16x16.gif[/img] Emergency Management Academy of New Zealand [br] http://www.emanz.ac.nz[br][br]MODx Sandbox Login: sandbox Password: castle [br]
                        Admin Sandbox Login: sandbox Password: castle