X-Git-Url: http://git.freeside.biz/gitweb/?p=freeside.git;a=blobdiff_plain;f=httemplate%2Fview%2Fattachment.html;h=4c4ca56388728541e80a91b62aff56086a0e6819;hp=5fc053967f9e3d3d4b06c697f4941bbd6a8cd0c0;hb=3f2a7b01b59902faed5767d81e2959e131bdbdfd;hpb=624b2d44625f69d71175c3348cae635d580c890b diff --git a/httemplate/view/attachment.html b/httemplate/view/attachment.html index 5fc053967..4c4ca5638 100644 --- a/httemplate/view/attachment.html +++ b/httemplate/view/attachment.html @@ -1,16 +1,26 @@ -<% $attach->body %> <%init> +$FS::CurrentUser::CurrentUser->access_right('Download attachment') + or die 'access denied'; + my ($query) = $cgi->keywords; $query =~ /^(\d+)$/; my $attachnum = $1 or die 'Invalid attachment number'; -$FS::CurrentUser::CurrentUser->access_right('Download attachment') or die 'access denied'; - -my $attach = qsearchs('cust_attachment', { attachnum => $attachnum }) or die "Attachment not found: $attachnum"; +my $attach = qsearchs('cust_attachment', { attachnum => $attachnum }) + or die "Attachment not found: $attachnum"; die 'access denied' if $attach->disabled; +$r->subprocess_env('no-gzip' => 1); # disable mod_deflate + $m->clear_buffer; + $r->content_type($attach->mime_type || 'text/plain'); -$r->headers_out->add('Content-Disposition' => 'attachment;filename=' . $attach->filename); +my $filename = $attach->filename; +$filename =~ s/"/'/g; #no idea how to encode " ... \" ? "" ? can't? +$r->headers_out->add( + 'Content-Disposition' => qq(attachment;filename="$filename") +); + +$m->print($attach->body);