image.php 384 B

12345678910111213
  1. <?php
  2. session_start();
  3. if ($_SESSION['user'] != 'admin') exit;
  4. $real_path = realpath($_SERVER["DOCUMENT_ROOT"].$_SERVER['QUERY_STRING']);
  5. if (empty($real_path)) exit;
  6. $dir_name = dirname($real_path);
  7. $dir_name = dirname($dir_name);
  8. if ($dir_name != $_SERVER["DOCUMENT_ROOT"].'/rrd') exit;
  9. header("X-Accel-Redirect: ".$_SERVER['QUERY_STRING']);
  10. header("Content-Type: image/png");
  11. ?>