| 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647 |
- <?php
- declare(strict_types=1);
- // GET api/v1/package.php?version=vX.Y.Z
- // Streams a release ZIP to an authenticated instance.
- require_once __DIR__ . "/../../includes/api.php";
- require_once __DIR__ . "/../../includes/releases.php";
- manageApiRequireMethod("GET");
- $instance = manageApiAuthenticate();
- $version = trim((string) ($_GET["version"] ?? ""));
- if (!manageIsVersion($version)) {
- manageApiFail(400, "Ungültige Version.");
- }
- try {
- $release = manageReleaseResolve($version);
- } catch (Throwable $exception) {
- manageApiFail(404, $exception->getMessage());
- }
- $path = $release["package_path"];
- $size = filesize($path);
- $handle = fopen($path, "rb");
- if ($size === false || $handle === false) {
- manageApiFail(500, "Release-Paket konnte nicht geöffnet werden.");
- }
- manageInstanceTouch($instance["id"], []);
- manageLogAccess("Package downloaded", [
- "instance" => $instance["id"],
- "version" => $version,
- ]);
- header("Content-Type: application/zip");
- header("Content-Disposition: attachment; filename=\"" . addcslashes(basename($path), "\"\\") . "\"");
- header("Content-Length: " . (string) $size);
- // Private: the response is tied to an authenticated instance, so no shared
- // cache may keep a copy.
- header("Cache-Control: private, no-store");
- header("X-Content-Type-Options: nosniff");
- fpassthru($handle);
- fclose($handle);
|