99 lines
3.0 KiB
PHP
99 lines
3.0 KiB
PHP
<?php
|
|
/**
|
|
* Asset-server voor productie: serveert statische bestanden uit themes/,
|
|
* admin/theme/ en plugins/.
|
|
*
|
|
* Dit bestand wordt op productie gebruikt wanneer de PHP-dev-router niet
|
|
* beschikbaar is. public/.htaccess herschrijft /themes/, /admin/assets/ en
|
|
* /plugins/ URLs naar dit bestand. Paden worden via realpath() + prefix-
|
|
* check afgedwongen binnen de juiste asset-map om path traversal te voorkomen.
|
|
*
|
|
* @since 2.6.4
|
|
* @package CodePress
|
|
*/
|
|
/**
|
|
* Asset server - serves static files from themes/, admin/theme/, and plugins/
|
|
* This file is used on production servers where the PHP router is not available.
|
|
* The .htaccess rewrites /themes/, /admin/assets/, and /plugins/ URLs to this file.
|
|
*/
|
|
|
|
$basePath = dirname(__DIR__);
|
|
$requestUri = $_SERVER['REQUEST_URI'] ?? '/';
|
|
$path = parse_url($requestUri, PHP_URL_PATH) ?? '/';
|
|
|
|
$mimeTypes = [
|
|
'css' => 'text/css',
|
|
'js' => 'application/javascript',
|
|
'svg' => 'image/svg+xml',
|
|
'png' => 'image/png',
|
|
'jpg' => 'image/jpeg',
|
|
'ico' => 'image/x-icon',
|
|
'woff' => 'font/woff',
|
|
'woff2' => 'font/woff2',
|
|
'json' => 'application/json',
|
|
'map' => 'application/json',
|
|
];
|
|
|
|
// Determine which asset directory to serve from
|
|
$assetFile = null;
|
|
|
|
/**
|
|
* /themes/<naam>/assets/...: theme-asset matchen en pad oplossen.
|
|
*
|
|
* @since 2.6.4
|
|
*/
|
|
// /themes/<name>/assets/...
|
|
if (preg_match('#^/themes/([^/]+)/assets/(.+)$#', $path, $m)) {
|
|
$themeName = $m[1];
|
|
$assetRel = $m[2];
|
|
$assetFile = $basePath . '/themes/' . $themeName . '/assets/' . $assetRel;
|
|
$realBase = realpath($basePath . '/themes/' . $themeName . '/assets');
|
|
}
|
|
/**
|
|
* /admin/assets/...: admin-theme-asset matchen (default admin theme).
|
|
*
|
|
* @since 2.6.4
|
|
*/
|
|
// /admin/assets/...
|
|
elseif (preg_match('#^/admin/assets/(.+)$#', $path, $m)) {
|
|
$assetRel = $m[1];
|
|
$assetFile = $basePath . '/admin/theme/default/assets/' . $assetRel;
|
|
$realBase = realpath($basePath . '/admin/theme/default/assets');
|
|
}
|
|
/**
|
|
* /plugins/<naam>/assets/...: plugin-asset matchen en pad oplossen.
|
|
*
|
|
* @since 2.6.4
|
|
*/
|
|
// /plugins/<name>/assets/...
|
|
elseif (preg_match('#^/plugins/([^/]+)/assets/(.+)$#', $path, $m)) {
|
|
$pluginName = $m[1];
|
|
$assetRel = $m[2];
|
|
$assetFile = $basePath . '/plugins/' . $pluginName . '/assets/' . $assetRel;
|
|
$realBase = realpath($basePath . '/plugins/' . $pluginName . '/assets');
|
|
}
|
|
|
|
/**
|
|
* Matchende asset uitleveren met juiste MIME en cache-headers.
|
|
*
|
|
* Controleert dat het opgeloste pad binnen de asset-map blijft en een
|
|
* regulier bestand is; anders volgt een 404.
|
|
*
|
|
* @since 2.6.4
|
|
*/
|
|
if ($assetFile && $realBase) {
|
|
$realFile = realpath($assetFile);
|
|
if ($realFile && strpos($realFile, $realBase) === 0 && is_file($realFile)) {
|
|
$ext = strtolower(pathinfo($realFile, PATHINFO_EXTENSION));
|
|
if (isset($mimeTypes[$ext])) {
|
|
header('Content-Type: ' . $mimeTypes[$ext]);
|
|
}
|
|
header('Cache-Control: public, max-age=86400');
|
|
readfile($realFile);
|
|
exit;
|
|
}
|
|
}
|
|
|
|
http_response_code(404);
|
|
header('Content-Type: text/plain');
|
|
echo '404 Not Found'; |