3 require_once('admin.php');
5 header('Content-Type: text/html; charset=' . get_option('blog_charset'));
7 if (!current_user_can('upload_files'))
8 die(__('You do not have permission to upload files.'));
10 $wpvarstoreset = array('action', 'post', 'all', 'last', 'link', 'sort', 'start', 'imgtitle', 'descr', 'attachment');
12 for ($i=0; $i<count($wpvarstoreset); $i += 1) {
13 $wpvar = $wpvarstoreset[$i];
14 if (!isset($$wpvar)) {
15 if (empty($_POST["$wpvar"])) {
16 if (empty($_GET["$wpvar"])) {
19 $$wpvar = $_GET["$wpvar"];
22 $$wpvar = $_POST["$wpvar"];
37 if ( !current_user_can('edit_post', (int) $attachment) )
38 die(__('You are not allowed to delete this attachment.').' <a href="'.basename(__FILE__)."?post=$post&all=$all&action=upload\">".__('Go back').'</a>');
40 wp_delete_attachment($attachment);
42 header("Location: ".basename(__FILE__)."?post=$post&all=$all&action=view&start=$start");
47 $overrides = array('action'=>'save');
49 $file = wp_handle_upload($_FILES['image'], $overrides);
51 if ( isset($file['error']) )
52 die($file['error'] . '<br /><a href="' . basename(__FILE__) . '?action=upload&post=' . $post . '">'.__('Back to Image Uploading').'</a>');
55 $type = $file['type'];
56 $file = $file['file'];
57 $filename = basename($file);
59 // Construct the attachment array
61 'post_title' => $imgtitle ? $imgtitle : $filename,
62 'post_content' => $descr,
63 'post_status' => 'attachment',
64 'post_parent' => $post,
65 'post_mime_type' => $type,
70 $id = wp_insert_attachment($attachment, $file, $post);
72 if ( preg_match('!^image/!', $attachment['post_mime_type']) ) {
73 // Generate the attachment's postmeta.
74 $imagesize = getimagesize($file);
75 $imagedata['width'] = $imagesize['0'];
76 $imagedata['height'] = $imagesize['1'];
77 list($uwidth, $uheight) = get_udims($imagedata['width'], $imagedata['height']);
78 $imagedata['hwstring_small'] = "height='$uheight' width='$uwidth'";
79 $imagedata['file'] = $file;
81 add_post_meta($id, '_wp_attachment_metadata', $imagedata);
83 if ( $imagedata['width'] * $imagedata['height'] < 3 * 1024 * 1024 ) {
84 if ( $imagedata['width'] > 128 && $imagedata['width'] >= $imagedata['height'] * 4 / 3 )
85 $thumb = wp_create_thumbnail($file, 128);
86 elseif ( $imagedata['height'] > 96 )
87 $thumb = wp_create_thumbnail($file, 96);
89 if ( @file_exists($thumb) ) {
90 $newdata = $imagedata;
91 $newdata['thumb'] = basename($thumb);
92 update_post_meta($id, '_wp_attachment_metadata', $newdata, $imagedata);
98 add_post_meta($id, '_wp_attachment_metadata', array());
101 header("Location: ".basename(__FILE__)."?post=$post&all=$all&action=view&start=0");
106 $current_1 = ' class="current"';
107 $back = $next = false;
112 // How many images do we show? How many do we query?
116 if ( $post && (empty($all) || $all == 'false') ) {
117 $and_post = "AND post_parent = '$post'";
118 $current_2 = ' class="current"';
120 $current_3 = ' class="current"';
123 if (! current_user_can('edit_others_posts') )
124 $and_user = "AND post_author = " . $user_ID;
127 $start = $wpdb->get_var("SELECT count(ID) FROM $wpdb->posts WHERE post_status = 'attachment' $and_user $and_post") - $num;
129 $start = (int) $start;
135 $sort = "post_date_gmt DESC";
137 $attachments = $wpdb->get_results("SELECT ID, post_date, post_title, post_mime_type, guid FROM $wpdb->posts WHERE post_status = 'attachment' $and_type $and_post $and_user ORDER BY $sort LIMIT $start, $double", ARRAY_A);
139 if ( count($attachments) == 0 ) {
140 header("Location: ".basename(__FILE__)."?post=$post&action=upload");
142 } elseif ( count($attachments) > $num ) {
143 $next = $start + count($attachments) - $num;
149 $back = $start - $num;
161 if ( count($attachments) > 0 ) {
162 $attachments = array_slice( $attachments, 0, $num );
163 $__delete = __('Delete');
164 $__not_linked = __('Not Linked');
165 $__linked_to_page = __('Linked to Page');
166 $__linked_to_image = __('Linked to Image');
167 $__linked_to_file = __('Linked to File');
168 $__using_thumbnail = __('Using Thumbnail');
169 $__using_original = __('Using Original');
170 $__using_title = __('Using Title');
171 $__using_filename = __('Using Filename');
172 $__using_icon = __('Using Icon');
173 $__no_thumbnail = '<del>'.__('No Thumbnail').'</del>';
174 $__send_to_editor = __('Send to editor');
175 $__close = __('Close Options');
176 $__confirmdelete = __('Delete this file from the server?');
177 $__nothumb = __('There is no thumbnail associated with this photo.');
178 $script .= "notlinked = '$__not_linked';
179 linkedtoimage = '$__linked_to_image';
180 linkedtopage = '$__linked_to_page';
181 linkedtofile = '$__linked_to_file';
182 usingthumbnail = '$__using_thumbnail';
183 usingoriginal = '$__using_original';
184 usingtitle = '$__using_title';
185 usingfilename = '$__using_filename';
186 usingicon = '$__using_icon';
187 var aa = new Array();
188 var ab = new Array();
189 var imga = new Array();
190 var imgb = new Array();
191 var srca = new Array();
192 var srcb = new Array();
193 var title = new Array();
194 var filename = new Array();
195 var icon = new Array();
197 foreach ( $attachments as $key => $attachment ) {
198 $ID = $attachment['ID'];
199 $href = get_attachment_link($ID);
200 $meta = get_post_meta($ID, '_wp_attachment_metadata', true);
201 if (!is_array($meta)) {
202 $meta = get_post_meta($ID, 'imagedata', true); // Try 1.6 Alpha meta key
203 if (!is_array($meta)) {
206 add_post_meta($ID, '_wp_attachment_metadata', $meta);
208 $attachment = array_merge($attachment, $meta);
209 $noscript = "<noscript>
210 <div class='caption'><a href=\"".basename(__FILE__)."?action=links&attachment={$ID}&post={$post}&all={$all}&start={$start}\">Choose Links</a></div>
213 $send_delete_cancel = "<a onclick=\"sendToEditor({$ID});return false;\" href=\"javascript:void()\">$__send_to_editor</a>
214 <a onclick=\"return confirm('$__confirmdelete')\" href=\"".basename(__FILE__)."?action=delete&attachment={$ID}&all=$all&start=$start&post=$post\">$__delete</a>
215 <a onclick=\"popup.style.display='none';return false;\" href=\"javascript:void()\">$__close</a>
218 if ( preg_match('!^image/!', $attachment['post_mime_type'] ) ) {
219 $image = & $attachment;
220 if ( ($image['width'] > 128 || $image['height'] > 96) && !empty($image['thumb']) && file_exists(dirname($image['file']).'/'.$image['thumb']) ) {
221 $src = str_replace(basename($image['guid']), $image['thumb'], $image['guid']);
222 $script .= "srca[{$ID}] = '$src';
223 srcb[{$ID}] = '{$image['guid']}';
226 $thumbtext = $__using_thumbnail;
228 $src = $image['guid'];
230 $thumbtext = $__no_thumbnail;
232 list($image['uwidth'], $image['uheight']) = get_udims($image['width'], $image['height']);
233 $height_width = 'height="'.$image['uheight'].'" width="'.$image['uwidth'].'"';
234 $xpadding = (128 - $image['uwidth']) / 2;
235 $ypadding = (96 - $image['uheight']) / 2;
236 $style .= "#target{$ID} img { padding: {$ypadding}px {$xpadding}px; }\n";
237 $title = htmlentities($image['post_title'], ENT_QUOTES);
238 $script .= "aa[{$ID}] = '<a id=\"p{$ID}\" rel=\"attachment\" class=\"imagelink\" href=\"$href\" onclick=\"doPopup({$ID});return false;\" title=\"{$title}\">';
239 ab[{$ID}] = '<a class=\"imagelink\" href=\"{$image['guid']}\" onclick=\"doPopup({$ID});return false;\" title=\"{$title}\">';
240 imga[{$ID}] = '<img id=\"image{$ID}\" src=\"$src\" alt=\"{$title}\" $height_width />';
241 imgb[{$ID}] = '<img id=\"image{$ID}\" src=\"{$image['guid']}\" alt=\"{$title}\" $height_width />';
243 $html .= "<div id='target{$ID}' class='attwrap left'>
244 <div id='div{$ID}' class='imagewrap' onclick=\"doPopup({$ID});\">
245 <img id=\"image{$ID}\" src=\"$src\" alt=\"{$title}\" $height_width />
250 $popups .= "<div id='popup{$ID}' class='popup'>
251 <a id=\"I{$ID}\" onclick=\"if($thumb)toggleImage({$ID});else alert('$__nothumb');return false;\" href=\"javascript:void()\">$thumbtext</a>
252 <a id=\"L{$ID}\" onclick=\"toggleLink({$ID});return false;\" href=\"javascript:void()\">$__not_linked</a>
253 {$send_delete_cancel}
257 $title = htmlentities($attachment['post_title'], ENT_QUOTES);
258 $filename = basename($attachment['guid']);
259 $icon = get_attachment_icon($ID);
260 $toggle_icon = "<a id=\"I{$ID}\" onclick=\"toggleOtherIcon({$ID});return false;\" href=\"javascript:void()\">$__using_title</a>";
261 $script .= "aa[{$ID}] = '<a id=\"p{$ID}\" rel=\"attachment\" href=\"$href\" onclick=\"doPopup({$ID});return false;\" title=\"{$title}\">';
262 ab[{$ID}] = '<a id=\"p{$ID}\" href=\"{$filename}\" onclick=\"doPopup({$ID});return false;\" title=\"{$title}\">';
263 title[{$ID}] = '{$title}';
264 filename[{$ID}] = '{$filename}';
265 icon[{$ID}] = '{$icon}';
267 $html .= "<div id='target{$ID}' class='attwrap left'>
268 <div id='div{$ID}' class='otherwrap usingtext' onmousedown=\"selectLink({$ID})\" onclick=\"doPopup({$ID});return false;\">
269 <a id=\"p{$ID}\" href=\"{$attachment['guid']}\" onmousedown=\"selectLink({$ID});\" onclick=\"return false;\">{$title}</a>
274 $popups .= "<div id='popup{$ID}' class='popup'>
275 <div class='filetype'>".__('File Type:').' '.str_replace('/',"/\n",$attachment['post_mime_type'])."</div>
276 <a id=\"L{$ID}\" onclick=\"toggleOtherLink({$ID});return false;\" href=\"javascript:void()\">$__linked_to_file</a>
278 {$send_delete_cancel}
285 $images_width = $uwidth_sum + ( count($images) * 6 ) + 35;
290 die(__('This script was not meant to be called directly.'));
294 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
295 <html xmlns="http://www.w3.org/1999/xhtml">
297 <meta http-equiv="Content-Type" content="<?php bloginfo('html_type'); ?>; charset=<?php echo get_settings('blog_charset'); ?>" />
298 <meta http-equiv="imagetoolbar" content="no" />
299 <script type="text/javascript">
300 /* Define any variables we'll need, such as alternate URLs. */
301 <?php echo $script; ?>
302 function htmldecode(st) {
303 o = document.getElementById('htmldecode');
305 o = document.createElement("A");
312 function cancelUpload() {
313 o = document.getElementById('uploadForm');
315 o.action.value = 'view';
318 function doPopup(i) {
320 popup.style.display = 'none';
321 target = document.getElementById('target'+i);
322 popup = document.getElementById('popup'+i);
323 popup.style.left = (target.offsetLeft) + 'px';
324 popup.style.top = (target.offsetTop) + 'px';
325 popup.style.display = 'block';
328 function selectLink(n) {
329 o=document.getElementById('div'+n);
330 if ( typeof document.body.createTextRange == 'undefined' || typeof win.tinyMCE == 'undefined' || win.tinyMCE.configs.length < 1 )
332 r = document.body.createTextRange();
333 if ( typeof r != 'undefined' ) {
334 r.moveToElementText(o);
338 function toggleLink(n) {
339 ol=document.getElementById('L'+n);
340 if ( ol.innerHTML == htmldecode(notlinked) ) {
341 ol.innerHTML = linkedtoimage;
342 } else if ( ol.innerHTML == htmldecode(linkedtoimage) ) {
343 ol.innerHTML = linkedtopage;
345 ol.innerHTML = notlinked;
349 function toggleOtherLink(n) {
350 ol=document.getElementById('L'+n);
351 if ( ol.innerHTML == htmldecode(linkedtofile) ) {
352 ol.innerHTML = linkedtopage;
354 ol.innerHTML = linkedtofile;
358 function toggleImage(n) {
359 oi = document.getElementById('I'+n);
360 if ( oi.innerHTML == htmldecode(usingthumbnail) ) {
361 oi.innerHTML = usingoriginal;
363 oi.innerHTML = usingthumbnail;
367 function toggleOtherIcon(n) {
368 od = document.getElementById('div'+n);
369 oi = document.getElementById('I'+n);
370 if ( oi.innerHTML == htmldecode(usingtitle) ) {
371 oi.innerHTML = usingfilename;
372 od.className = 'otherwrap usingtext';
373 } else if ( oi.innerHTML == htmldecode(usingfilename) && icon[n] != '' ) {
374 oi.innerHTML = usingicon;
375 od.className = 'otherwrap usingicon';
377 oi.innerHTML = usingtitle;
378 od.className = 'otherwrap usingtext';
382 function updateImage(n) {
383 od=document.getElementById('div'+n);
384 ol=document.getElementById('L'+n);
385 oi=document.getElementById('I'+n);
386 if ( oi.innerHTML == htmldecode(usingthumbnail) ) {
391 if ( ol.innerHTML == htmldecode(linkedtoimage) ) {
392 od.innerHTML = ab[n]+img+'</a>';
393 } else if ( ol.innerHTML == htmldecode(linkedtopage) ) {
394 od.innerHTML = aa[n]+img+'</a>';
399 function updateOtherIcon(n) {
400 od=document.getElementById('div'+n);
401 ol=document.getElementById('L'+n);
402 oi=document.getElementById('I'+n);
403 if ( oi.innerHTML == htmldecode(usingfilename) ) {
405 } else if ( oi.innerHTML == htmldecode(usingicon) ) {
410 if ( ol.innerHTML == htmldecode(linkedtofile) ) {
411 od.innerHTML = ab[n]+txt+'</a>';
412 } else if ( ol.innerHTML == htmldecode(linkedtopage) ) {
413 od.innerHTML = aa[n]+txt+'</a>';
419 var win = window.opener ? window.opener : window.dialogArguments;
421 tinyMCE = win.tinyMCE;
422 richedit = ( typeof tinyMCE == 'object' && tinyMCE.configs.length > 0 );
423 function sendToEditor(n) {
424 o = document.getElementById('div'+n);
425 h = o.innerHTML.replace(new RegExp('^\\s*(.*?)\\s*$', ''), '$1'); // Trim
426 h = h.replace(new RegExp(' (class|title|width|height|id|onclick|onmousedown)=([^\'"][^ ]*)( |/|>)', 'g'), ' $1="$2"$3'); // Enclose attribs in quotes
427 h = h.replace(new RegExp(' (width|height)=".*?"', 'g'), ''); // Drop size constraints
428 h = h.replace(new RegExp(' on(click|mousedown)="[^"]*"', 'g'), ''); // Drop menu events
429 h = h.replace(new RegExp('<(/?)A', 'g'), '<$1a'); // Lowercase tagnames
430 h = h.replace(new RegExp('<IMG', 'g'), '<img'); // Lowercase again
431 h = h.replace(new RegExp('(<img .+?")>', 'g'), '$1 />'); // XHTML
433 win.tinyMCE.execCommand('mceInsertContent', false, h);
435 win.edInsertContent(win.edCanvas, h);
438 <style type="text/css">
439 <?php if ( $action == 'links' ) : ?>
440 * html { overflow-x: hidden; }
442 * html { overflow-y: hidden; }
445 font: 13px "Lucida Grande", "Lucida Sans Unicode", Tahoma, Verdana;
452 margin: 3px 2px 0px 6px;
464 width: <?php echo $images_width; ?>px;
467 background-color: rgb(209, 226, 239);
469 <?php echo $style; ?>
470 .attwrap, .attwrap * {
483 background-color: #f9fcfe;
488 .otherwrap a, .otherwrap a:hover, .otherwrap a:active, .otherwrap a:visited {
505 border-bottom: 3px double #89a
507 .imagewrap, .imagewrap img, .imagewrap a, .imagewrap a img, .imagewrap a:hover img, .imagewrap a:visited img, .imagewrap a:active img {
508 text-decoration: none;
516 border-bottom: 1px solid #448abd;
526 text-decoration: none;
528 border-top: 3px solid #fff;
530 #upload-menu .current a {
532 border-right: 2px solid #448abd;
534 #upload-menu a:hover {
539 color: rgb(68, 138, 189);
555 #upload-menu li.spacer {
578 background-color: rgb(240, 240, 238);
579 border-top: 2px solid #fff;
580 border-right: 2px solid #ddd;
581 border-bottom: 2px solid #ddd;
582 border-left: 2px solid #fff;
587 filter:alpha(opacity=90);
592 .popup a, .popup a:visited, .popup a:active {
593 background-color: transparent;
596 text-decoration: none;
600 background-color: #fff;
610 #submit input, #submit input:focus {
611 background: url( images/fade-butt.png );
612 border: 3px double #999;
613 border-left-color: #ccc;
614 border-top-color: #ccc;
618 #submit input:active {
620 border: 3px double #ccc;
621 border-left-color: #999;
622 border-top-color: #999;
641 <ul id="upload-menu">
642 <li<?php echo $current_1; ?>><a href="<?php echo basename(__FILE__); ?>?action=upload&post=<?php echo $post; ?>&all=<?php echo $all; ?>&start=<?php echo $start; ?>"><?php _e('Upload'); ?></a></li>
643 <?php if ( $attachments = $wpdb->get_results("SELECT ID FROM $wpdb->posts WHERE post_parent = '$post'") ) { ?>
644 <li<?php echo $current_2; ?>><a href="<?php echo basename(__FILE__); ?>?action=view&post=<?php echo $post; ?>&all=false"><?php _e('Browse'); ?></a></li>
646 <?php if ($wpdb->get_var("SELECT count(ID) FROM $wpdb->posts WHERE post_status = 'attachment'")) { ?>
647 <li<?php echo $current_3; ?>><a href="<?php echo basename(__FILE__); ?>?action=view&post=<?php echo $post; ?>&all=true"><?php _e('Browse All'); ?></a></li>
650 <?php if ( $action == 'view' ) { ?>
651 <?php if ( false !== $back ) : ?>
652 <li class="spacer"><a href="<?php echo basename(__FILE__); ?>?action=<?php echo $action; ?>&post=<?php echo $post; ?>&all=<?php echo $all; ?>&start=0" title="<?php _e('First'); ?>">|«</a></li>
653 <li><a href="<?php echo basename(__FILE__); ?>?action=<?php echo $action; ?>&post=<?php echo $post; ?>&all=<?php echo $all; ?>&start=<?php echo $back; ?>"">« <?php _e('Back'); ?></a></li>
655 <li class="inactive spacer">|«</li>
656 <li class="inactive">« <?php _e('Back'); ?></li>
658 <?php if ( false !== $next ) : ?>
659 <li><a href="<?php echo basename(__FILE__); ?>?action=<?php echo $action; ?>&post=<?php echo $post; ?>&all=<?php echo $all; ?>&start=<?php echo $next; ?>"><?php _e('Next'); ?> »</a></li>
660 <li><a href="<?php echo basename(__FILE__); ?>?action=<?php echo $action; ?>&post=<?php echo $post; ?>&all=<?php echo $all; ?>&last=true" title="<?php _e('Last'); ?>">»|</a></li>
662 <li class="inactive"><?php _e('Next'); ?> »</li>
663 <li class="inactive">»|</li>
665 <?php } // endif not upload?>
667 <?php if ( $action == 'view' ) : ?>
669 <!--<div class="tip"><?php _e('You can drag and drop these items into your post. Click on one for more options.'); ?></div>-->
672 <?php echo $popups; ?>
675 <?php elseif ( $action == 'upload' ) : ?>
676 <div class="tip"></div>
677 <form enctype="multipart/form-data" id="uploadForm" method="POST" action="<?php echo basename(__FILE__); ?>">
678 <table style="width:99%;">
680 <th scope="row" align="right"><label for="upload"><?php _e('File:'); ?></label></th>
681 <td><input type="file" id="upload" name="image" /></td>
684 <th scope="row" align="right"><label for="title"><?php _e('Title:'); ?></label></th>
685 <td><input type="text" id="title" name="imgtitle" /></td>
688 <th scope="row" align="right"><label for="descr"><?php _e('Description:'); ?></label></th>
689 <td><input type="textarea" name="descr" id="descr" value="" /></td>
694 <input type="hidden" name="action" value="save" />
695 <input type="hidden" name="post" value="<?php echo $post; ?>" />
696 <input type="hidden" name="all" value="<?php echo $all; ?>" />
697 <input type="hidden" name="start" value="<?php echo $start; ?>" />
699 <input type="submit" value="<?php _e('Upload'); ?>" />
700 <?php if ( !empty($all) ) : ?>
701 <input type="button" value="<?php _e('Cancel'); ?>" onclick="cancelUpload()" />
709 <?php elseif ( $action == 'links' ) : ?>
711 <?php the_attachment_links($attachment); ?>