image.php 417 B

123456789101112131415161718
  1. <?php
  2. session_start();
  3. if ($_SESSION["userContext"] != "admin") {
  4. exit();
  5. }
  6. $real_path = realpath($_SERVER["DOCUMENT_ROOT"] . $_SERVER["QUERY_STRING"]);
  7. if (empty($real_path)) {
  8. exit();
  9. }
  10. $dir_name = dirname($real_path);
  11. $dir_name = dirname($dir_name);
  12. if ($dir_name != $_SERVER["DOCUMENT_ROOT"] . "/rrd") {
  13. exit();
  14. }
  15. header("X-Accel-Redirect: " . $_SERVER["QUERY_STRING"]);
  16. header("Content-Type: image/png");
  17. ?>