aboutsummaryrefslogtreecommitdiffstats
path: root/showattachment.cgi
blob: 70f5c6d6641d30b9c0ef67bed866777921941937 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
#!/usr/bonsaitools/bin/perl -wT
# -*- Mode: perl; indent-tabs-mode: nil -*-
#
# The contents of this file are subject to the Mozilla Public
# License Version 1.1 (the "License"); you may not use this file
# except in compliance with the License. You may obtain a copy of
# the License at http://www.mozilla.org/MPL/
#
# Software distributed under the License is distributed on an "AS
# IS" basis, WITHOUT WARRANTY OF ANY KIND, either express or
# implied. See the License for the specific language governing
# rights and limitations under the License.
#
# The Original Code is the Bugzilla Bug Tracking System.
#
# The Initial Developer of the Original Code is Netscape Communications
# Corporation. Portions created by Netscape are
# Copyright (C) 1998 Netscape Communications Corporation. All
# Rights Reserved.
#
# Contributor(s): Terry Weissman <terry@mozilla.org>
#                 Jacob Steenhagen <jake@acutex.net>

use diagnostics;
use strict;

use lib qw(.);

require "CGI.pl";

if (!defined $::FORM{'attach_id'}) {
    print "Content-type: text/html\n";
    print "\n";
    PutHeader("Search by attachment number");  
    print "<FORM METHOD=GET ACTION=\"showattachment.cgi\">\n";
    print "You may view a single attachment by entering its id here: \n";
    print "<INPUT NAME=attach_id>\n";   
    print "<INPUT TYPE=\"submit\" VALUE=\"Show Me This Attachment\">\n";
    print "</FORM>\n";
    PutFooter();
    exit;
}

ConnectToDatabase();

quietly_check_login();

if (!detaint_natural($::FORM{attach_id})) {
    DisplayError("Attachment ID should be numeric.");
    exit;
}

SendSQL("select bug_id, mimetype, thedata from attachments where attach_id = $::FORM{'attach_id'}");
my ($bug_id, $mimetype, $thedata) = FetchSQLData();

if (!$bug_id) {
    DisplayError("Attachment $::FORM{attach_id} does not exist.");
    exit;
}

# Make sure the user can see the bug to which this file is attached
ValidateBugID($bug_id);

print qq{Content-type: $mimetype\n\n$thedata};