permission($cmd_info["modulo_riferimento"],$_POST["codice"],$id_modulo) || (!empty($_POST["valutazione"])) ) && !empty($_POST["codice_round"]) && !empty($_POST["partecipante"]) && !empty($_POST["codice_lotto"]) && !empty($_POST["richiesta"]) && tokenVerify()) { $valutazione = (empty($_POST["valutazione"])) ? NULL : "commissione"; $codice_round = $_POST["codice_round"]; $concorso = concorso::init($_POST["codice"],$codice_round,$valutazione); if (!empty($concorso) && $concorso->setLotto($_POST["codice_lotto"])) { $record = $concorso->info; $round = $concorso->round; if ($concorso->checkOpeningPermission($_POST["partecipante"],$_POST["richiesta"])) { $aggiuntive = false; $busta = $concorso->getBusta($_POST["partecipante"],$_POST["richiesta"],$aggiuntive,true); if (!empty($busta)) { if ($busta["open"] == "S") { $file_content = $busta["content"]; if (P7Manager::bustaEstensioneSoloP7M($busta["nomeFile"])) { $ext = getTypeAndExtension($file_content,true); $busta["nomeFile"] = str_replace(".p7m", "{$ext["ext"]}", $busta["nomeFile"]); $error = false; } if ($_POST["openP7M"] == "S") { $path = $config["chunk_folder"] . "/" . $_SESSION["utente"]->codice; if (!is_dir($path)) { mkdir($path); } $path .= "/" . $busta["nomeFile"]; file_put_contents($path, $file_content); $file_content = ""; if (file_exists($path)) { $p7m = new P7Manager($path); if ($p7m != false) { $file_content = $p7m->extract(true); $file_info = new finfo(FILEINFO_MIME_TYPE); $mime_type = $file_info->buffer($file_content); $ext = P7manager::extFromMime($mime_type); $busta["mime"] = $mime_type; $busta["nomeFile"] = str_replace(".p7m", ".{$ext}", $busta["nomeFile"]); } } } if (!empty($file_content)) { $richiesta = $pdo->go("SELECT * FROM b_concorsi_richieste WHERE codice = :richiesta",[":richiesta"=>$busta["codice_richiesta"]])->fetch(PDO::FETCH_ASSOC); $partecipante = $concorso->getPartecipante($_POST["partecipante"]); $concorso->addToLog("DOWNLOAD",$richiesta["titolo"] . " - " . $partecipante["id"]); header('Content-Description: File Transfer'); header('Content-Disposition: attachment; filename=' . str_replace("-",".",$busta["nomeFile"])); header('Content-Type: ' . $busta["mime"]); header('Content-Transfer-Encoding: binary'); header('Connection: Keep-Alive'); header('Expires: 0'); header('Cache-Control: must-revalidate, post-check=0, pre-check=0'); header('Pragma: public'); echo $file_content; $error = false; } } else { if (!empty($_POST["private"])) { $key = openssl_pkey_get_private($_POST["private"]); if (@openssl_private_decrypt($busta["salt"],$salt,$key)) { $imported = explode(".",$busta["nomeFile"]); $addSalt = $config["simple_encrypt"]["offer"]; if (is_array($imported)) { $imported = end($imported); if ($imported == "imported-offer") { $imported = true; } } else { $imported = false; } $busta["content"] = openssl_decrypt($busta["content"],"AES128",$salt,OPENSSL_RAW_DATA,$addSalt); if ($busta["content"] !== false && !empty($busta["password"])) { if ($imported === true) { $fileInfo = getTypeAndExtension($busta["content"],true); $busta["mime"] = $fileInfo["type"]; $busta["nomeFile"] = str_replace(".imported-offer","",$busta["nomeFile"]) . $fileInfo["ext"]; } $content = simple_encrypt($busta["content"],$busta["password"]); if (!empty($content) && file_put_contents($busta["path"],$content)) { unset($busta["content"]); $busta["open"] = "S"; $busta["utente_decrypt"] = $_SESSION["utente"]->codice; $busta["timestamp_decrypt"] = date('Y-m-d H:i:s'); $salva = new salva(); $salva->debug = false; $salva->nome_tabella = "b_concorsi_buste"; $salva->operazione = "UPDATE"; $salva->oggetto = $busta; $salva->expect = array("codice","nomeFile","mime","content","open","utente_decrypt","timestamp_decrypt"); $esito = $salva->save(); if ($esito > 0) { $richiesta = $pdo->go("SELECT * FROM b_concorsi_richieste WHERE codice = :richiesta",[":richiesta"=>$busta["codice_richiesta"]])->fetch(PDO::FETCH_ASSOC); if ($richiesta["locked"] == "S") { $sql = "SELECT codice FROM b_offerte_concorsi WHERE codice_partecipante = :codice_partecipante and tipo = :busta "; $ris = $pdo->go($sql,array(":codice_partecipante"=>$_POST["partecipante"],":busta"=>$richiesta["busta"])); if ($ris->rowCount() === 1) { $offerta = $ris->fetch(PDO::FETCH_ASSOC); $sql = "SELECT * FROM b_offerte_concorsi WHERE codice = :codice "; $ris = $pdo->go($sql,array(":codice"=>$offerta["codice"])); $offerta = $ris->fetch(PDO::FETCH_ASSOC); if (@openssl_private_decrypt($offerta["salt"],$salt_offerta,$key)) { $offerta["content"] = openssl_decrypt($offerta["cryptedContent"],"AES128",$salt_offerta,OPENSSL_RAW_DATA,$config["simple_encrypt"]["offer"]); if ($offerta["content"] !== false) { $offerta["content"] = base64_encode($offerta["content"]); $salva = new salva(); $salva->debug = false; $salva->nome_tabella = "b_offerte_concorsi"; $salva->operazione = "UPDATE"; $salva->oggetto = $offerta; $salva->expect = array("codice","content","utente_decrypt","timestamp_decrypt"); $esito = $salva->save(); if ($esito > 0) { $sql = "SELECT * FROM b_dettaglio_offerte_concorsi WHERE codice_offerta = :codice_offerta AND codice_partecipante = :codice_partecipante "; $ris = $pdo->go($sql,array(":codice_offerta"=>$offerta["codice"],":codice_partecipante"=>$_POST["partecipante"])); if ($ris->rowCount() > 0) { while ($dettaglio = $ris->fetch(PDO::FETCH_ASSOC)) { $dettaglio["offerta"] = openssl_decrypt($dettaglio["cryptedOffer"],"AES128",$salt_offerta,OPENSSL_RAW_DATA,$config["simple_encrypt"]["offer"]); $salva = new salva(); $salva->debug = false; $salva->nome_tabella = "b_dettaglio_offerte_concorsi"; $salva->operazione = "UPDATE"; $salva->oggetto = $dettaglio; $salva->expect = array("codice","offerta"); $salva->save(); } } $sql = "SELECT * FROM b_concorsi_form_data WHERE codice_offerta = :codice_offerta "; $ris = $pdo->go($sql,array(":codice_offerta"=>$offerta["codice"])); if ($ris->rowCount() > 0) { while ($dettaglio = $ris->fetch(PDO::FETCH_ASSOC)) { $dettaglio["content"] = openssl_decrypt($dettaglio["cryptedContent"],"AES128",$salt_offerta,OPENSSL_RAW_DATA,$config["simple_encrypt"]["offer"]); $salva = new salva(); $salva->debug = false; $salva->nome_tabella = "b_concorsi_form_data"; $salva->operazione = "UPDATE"; $salva->oggetto = $dettaglio; $salva->expect = array("codice","content"); $salva->save(); } } } } } } } $error = false; $partecipante = $concorso->getPartecipante($_POST["partecipante"]); $concorso->addToLog("OPEN",$richiesta["titolo"] . " - " . $partecipante["id"]); ?> $("#btn--").removeClass("btn-danger").addClass("btn-success").html(" "); $("#form--").attr("target","_blank"); $("#p7m-operation--").addClass('d-flex').slideDown(); tabofferte.draw(); refreshModalHelper(); swal({title:js_dict.error,html:"",type:"error"});