v2.0.0.1
Publisium
- <?php
-
- declare(strict_types=1);
-
- require_once __DIR__ . '/includes/config.php';
- require_once __DIR__ . '/includes/database.php';
- require_once __DIR__ . '/includes/auth.php';
- require_once __DIR__ . '/includes/csrf.php';
- require_once __DIR__ . '/includes/read-aloud.php';
-
- Auth::boot();
- Auth::requireLogin();
-
- header('Content-Type: application/json');
-
- function audioUploadFail(int $status, string $message): never
- {
- http_response_code($status);
- echo json_encode(['success' => false, 'error' => $message]);
- exit;
- }
-
- if ($_SERVER['REQUEST_METHOD'] !== 'POST' || !Csrf::verify($_POST['csrf_token'] ?? null)) {
- audioUploadFail(403, 'Something went wrong. Reload the page and try again.');
- }
-
- $kind = (string) ($_POST['kind'] ?? 'article');
-
- if (in_array($kind, ['intro', 'outro'], true)) {
- if (!Auth::hasRoleAtLeast(Auth::ROLE_EDITOR_IN_CHIEF)) {
- audioUploadFail(403, 'Only editors in chief can change the intro and outro.');
- }
- $maxBytes = ReadAloud::MAX_FRAME_AUDIO_BYTES;
- } elseif ($kind === 'article') {
- if (!ReadAloud::isEnabled()) {
- audioUploadFail(403, 'Read aloud is switched off in Settings.');
- }
- if (!Auth::hasRoleAtLeast(Auth::ROLE_WRITER)) {
- audioUploadFail(403, 'You can’t upload audio for this article.');
- }
- $maxBytes = ReadAloud::MAX_ARTICLE_AUDIO_BYTES;
- } else {
- audioUploadFail(400, 'Something went wrong. Reload the page and try again.');
- }
-
- if (!isset($_FILES['file']) || !is_array($_FILES['file'])) {
- audioUploadFail(400, 'The upload didn’t work. Please try again.');
- }
-
- [$stored, $result] = ReadAloud::storeUpload($_FILES['file'], $maxBytes);
-
- if (!$stored) {
- audioUploadFail(400, $result);
- }
-
- echo json_encode(['success' => true, 'path' => $result, 'url' => ReadAloud::publicUrl($result)]);
-