BlogController.go 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652
  1. package controllers
  2. import (
  3. "strings"
  4. "github.com/lifei6671/mindoc/models"
  5. "time"
  6. "github.com/astaxie/beego"
  7. "github.com/lifei6671/mindoc/conf"
  8. "github.com/lifei6671/mindoc/utils/pagination"
  9. "strconv"
  10. "fmt"
  11. "os"
  12. "net/http"
  13. "path/filepath"
  14. "github.com/astaxie/beego/orm"
  15. "html/template"
  16. "encoding/json"
  17. "github.com/lifei6671/mindoc/utils"
  18. "net/url"
  19. )
  20. type BlogController struct {
  21. BaseController
  22. }
  23. func (c *BlogController) Prepare() {
  24. c.BaseController.Prepare()
  25. if !c.EnableAnonymous && c.Member == nil {
  26. c.Redirect(conf.URLFor("AccountController.Login")+"?url="+url.PathEscape(conf.BaseUrl+c.Ctx.Request.URL.RequestURI()), 302)
  27. }
  28. }
  29. //文章阅读
  30. func (c *BlogController) Index() {
  31. c.Prepare()
  32. c.TplName = "blog/index.tpl"
  33. blogId, _ := strconv.Atoi(c.Ctx.Input.Param(":id"))
  34. if blogId <= 0 {
  35. c.ShowErrorPage(404, "页面不存在")
  36. }
  37. blogReadSession := fmt.Sprintf("blog:read:%d", blogId)
  38. blog, err := models.NewBlog().FindFromCache(blogId)
  39. if err != nil {
  40. c.ShowErrorPage(404, "文章不存在")
  41. }
  42. if c.Ctx.Input.IsPost() {
  43. password := c.GetString("password");
  44. if blog.BlogStatus == "password" && password != blog.Password {
  45. c.JsonResult(6001, "文章密码不正确")
  46. } else if blog.BlogStatus == "password" && password == blog.Password {
  47. //如果密码输入正确,则存入session中
  48. c.CruSession.Set(blogReadSession, blogId)
  49. c.JsonResult(0, "OK")
  50. }
  51. c.JsonResult(0, "OK")
  52. } else if blog.BlogStatus == "password" && (c.CruSession.Get(blogReadSession) == nil || (c.Member != nil && blog.MemberId != c.Member.MemberId && !c.Member.IsAdministrator())) {
  53. //如果不存在已输入密码的标记
  54. c.TplName = "blog/index_password.tpl"
  55. }
  56. //加载文章附件
  57. blog.LinkAttach();
  58. c.Data["Model"] = blog
  59. c.Data["Content"] = template.HTML(blog.BlogRelease)
  60. if blog.BlogExcerpt == "" {
  61. c.Data["Description"] = utils.AutoSummary(blog.BlogRelease, 120)
  62. } else {
  63. c.Data["Description"] = blog.BlogExcerpt
  64. }
  65. if nextBlog, err := models.NewBlog().QueryNext(blogId); err == nil {
  66. c.Data["Next"] = nextBlog
  67. }
  68. if preBlog, err := models.NewBlog().QueryPrevious(blogId); err == nil {
  69. c.Data["Previous"] = preBlog
  70. }
  71. }
  72. //文章列表
  73. func (c *BlogController) List() {
  74. c.Prepare()
  75. c.TplName = "blog/list.tpl"
  76. pageIndex, _ := c.GetInt("page", 1)
  77. var blogList []*models.Blog
  78. var totalCount int
  79. var err error
  80. blogList, totalCount, err = models.NewBlog().FindToPager(pageIndex, conf.PageSize, 0, "")
  81. if err != nil && err != orm.ErrNoRows {
  82. c.ShowErrorPage(500, err.Error())
  83. }
  84. if totalCount > 0 {
  85. pager := pagination.NewPagination(c.Ctx.Request, totalCount, conf.PageSize, c.BaseUrl())
  86. c.Data["PageHtml"] = pager.HtmlPages()
  87. for _, blog := range blogList {
  88. //如果没有添加文章摘要,则自动提取
  89. if blog.BlogExcerpt == "" {
  90. blog.BlogExcerpt = utils.AutoSummary(blog.BlogRelease, 120)
  91. }
  92. blog.Link()
  93. }
  94. } else {
  95. c.Data["PageHtml"] = ""
  96. }
  97. c.Data["Lists"] = blogList
  98. }
  99. //管理后台文章列表
  100. func (c *BlogController) ManageList() {
  101. c.Prepare()
  102. c.TplName = "blog/manage_list.tpl"
  103. pageIndex, _ := c.GetInt("page", 1)
  104. blogList, totalCount, err := models.NewBlog().FindToPager(pageIndex, conf.PageSize, c.Member.MemberId, "")
  105. if err != nil {
  106. c.ShowErrorPage(500, err.Error())
  107. }
  108. if totalCount > 0 {
  109. pager := pagination.NewPagination(c.Ctx.Request, totalCount, conf.PageSize, c.BaseUrl())
  110. c.Data["PageHtml"] = pager.HtmlPages()
  111. } else {
  112. c.Data["PageHtml"] = ""
  113. }
  114. c.Data["ModelList"] = blogList
  115. }
  116. //文章设置
  117. func (c *BlogController) ManageSetting() {
  118. c.Prepare()
  119. c.TplName = "blog/manage_setting.tpl"
  120. //如果是post请求
  121. if c.Ctx.Input.IsPost() {
  122. blogId, _ := c.GetInt("id", 0)
  123. blogTitle := c.GetString("title")
  124. blogIdentify := c.GetString("identify")
  125. orderIndex, _ := c.GetInt("order_index", 0)
  126. blogType, _ := c.GetInt("blog_type", 0)
  127. blogExcerpt := c.GetString("excerpt", "")
  128. blogStatus := c.GetString("status", "publish")
  129. blogPassword := c.GetString("password", "")
  130. documentIdentify := strings.TrimSpace(c.GetString("documentIdentify"))
  131. bookIdentify := strings.TrimSpace(c.GetString("bookIdentify"))
  132. documentId := 0
  133. if blogTitle == "" {
  134. c.JsonResult(6001, "文章标题不能为空")
  135. }
  136. if strings.Count(blogExcerpt, "") > 500 {
  137. c.JsonResult(6008, "文章摘要必须小于500字符")
  138. }
  139. if blogStatus != "public" && blogStatus != "password" && blogStatus != "draft" {
  140. blogStatus = "public"
  141. }
  142. if blogStatus == "password" && blogPassword == "" {
  143. c.JsonResult(6010, "加密文章请设置密码")
  144. }
  145. if blogType != 0 && blogType != 1 {
  146. c.JsonResult(6005, "未知的文章类型")
  147. }
  148. if strings.Count(blogTitle, "") > 200 {
  149. c.JsonResult(6002, "文章标题不能大于200个字符")
  150. }
  151. //如果是关联文章,需要同步关联的文档
  152. if blogType == 1 {
  153. book, err := models.NewBook().FindByIdentify(bookIdentify)
  154. if err != nil {
  155. c.JsonResult(6011, "关联文档的项目不存在")
  156. }
  157. doc, err := models.NewDocument().FindByIdentityFirst(documentIdentify, book.BookId)
  158. if err != nil {
  159. c.JsonResult(6003, "查询关联项目文档时出错")
  160. }
  161. documentId = doc.DocumentId
  162. // 如果不是超级管理员,则校验权限
  163. if !c.Member.IsAdministrator() {
  164. bookResult, err := models.NewBookResult().FindByIdentify(book.Identify, c.Member.MemberId)
  165. if err != nil || bookResult.RoleId == conf.BookObserver {
  166. c.JsonResult(6002, "关联文档不存在或权限不足")
  167. }
  168. }
  169. }
  170. var blog *models.Blog
  171. var err error
  172. //如果文章ID存在,则从数据库中查询文章
  173. if blogId > 0 {
  174. if c.Member.IsAdministrator() {
  175. blog, err = models.NewBlog().Find(blogId)
  176. } else {
  177. blog, err = models.NewBlog().FindByIdAndMemberId(blogId, c.Member.MemberId)
  178. }
  179. if err != nil {
  180. c.JsonResult(6003, "文章不存在")
  181. }
  182. //如果设置了文章标识
  183. if blogIdentify != "" {
  184. //如果查询到的文章标识存在并且不是当前文章的id
  185. if b, err := models.NewBlog().FindByIdentify(blogIdentify); err == nil && b.BlogId != blogId {
  186. c.JsonResult(6004, "文章标识已存在")
  187. }
  188. }
  189. blog.Modified = time.Now()
  190. blog.ModifyAt = c.Member.MemberId
  191. } else {
  192. //如果设置了文章标识
  193. if blogIdentify != "" {
  194. if models.NewBlog().IsExist(blogIdentify) {
  195. c.JsonResult(6004, "文章标识已存在")
  196. }
  197. }
  198. blog = models.NewBlog()
  199. blog.MemberId = c.Member.MemberId
  200. blog.Created = time.Now()
  201. }
  202. if blogIdentify == "" {
  203. blog.BlogIdentify = fmt.Sprintf("%s-%d", "post", time.Now().UnixNano())
  204. } else {
  205. blog.BlogIdentify = blogIdentify
  206. }
  207. blog.BlogTitle = blogTitle
  208. blog.OrderIndex = orderIndex
  209. blog.BlogType = blogType
  210. if blogType == 1 {
  211. blog.DocumentId = documentId
  212. }
  213. blog.BlogExcerpt = blogExcerpt
  214. blog.BlogStatus = blogStatus
  215. blog.Password = blogPassword
  216. if err := blog.Save(); err != nil {
  217. beego.Error("保存文章失败 -> ", err)
  218. c.JsonResult(6011, "保存文章失败")
  219. } else {
  220. c.JsonResult(0, "ok", blog)
  221. }
  222. }
  223. if c.Ctx.Input.Referer() == "" {
  224. c.Data["Referer"] = "javascript:history.back();"
  225. } else {
  226. c.Data["Referer"] = c.Ctx.Input.Referer()
  227. }
  228. blogId, err := strconv.Atoi(c.Ctx.Input.Param(":id"))
  229. c.Data["DocumentIdentify"] = "";
  230. if err == nil {
  231. blog, err := models.NewBlog().FindByIdAndMemberId(blogId, c.Member.MemberId)
  232. if err != nil {
  233. c.ShowErrorPage(500, err.Error())
  234. }
  235. c.Data["Model"] = blog
  236. } else {
  237. c.Data["Model"] = models.NewBlog()
  238. }
  239. }
  240. //文章创建或编辑
  241. func (c *BlogController) ManageEdit() {
  242. c.Prepare()
  243. c.TplName = "blog/manage_edit.tpl"
  244. if c.Ctx.Input.IsPost() {
  245. blogId, _ := c.GetInt("blogId", 0)
  246. if blogId <= 0 {
  247. c.JsonResult(6001, "文章参数错误")
  248. }
  249. blogContent := c.GetString("content", "")
  250. blogHtml := c.GetString("htmlContent", "")
  251. version, _ := c.GetInt64("version", 0)
  252. cover := c.GetString("cover")
  253. var blog *models.Blog
  254. var err error
  255. if c.Member.IsAdministrator() {
  256. blog, err = models.NewBlog().Find(blogId)
  257. } else {
  258. blog, err = models.NewBlog().FindByIdAndMemberId(blogId, c.Member.MemberId)
  259. }
  260. if err != nil {
  261. beego.Error("查询文章失败 ->", err)
  262. c.JsonResult(6002, "查询文章失败")
  263. }
  264. if version > 0 && blog.Version != version && cover != "yes" {
  265. c.JsonResult(6005, "文章已被修改")
  266. }
  267. //如果是关联文章,需要同步关联的文档
  268. if blog.BlogType == 1 {
  269. doc, err := models.NewDocument().Find(blog.DocumentId)
  270. if err != nil {
  271. beego.Error("查询关联项目文档时出错 ->", err)
  272. c.JsonResult(6003, "查询关联项目文档时出错")
  273. }
  274. book, err := models.NewBook().Find(doc.BookId)
  275. if err != nil {
  276. c.JsonResult(6002, "项目不存在或权限不足")
  277. }
  278. // 如果不是超级管理员,则校验权限
  279. if !c.Member.IsAdministrator() {
  280. bookResult, err := models.NewBookResult().FindByIdentify(book.Identify, c.Member.MemberId)
  281. if err != nil || bookResult.RoleId == conf.BookObserver {
  282. beego.Error("FindByIdentify => ", err)
  283. c.JsonResult(6002, "关联文档不存在或权限不足")
  284. }
  285. }
  286. doc.Markdown = blogContent
  287. doc.Release = blogHtml
  288. doc.Content = blogHtml
  289. doc.ModifyTime = time.Now()
  290. doc.ModifyAt = c.Member.MemberId
  291. if err := doc.InsertOrUpdate("markdown", "release", "content", "modify_time", "modify_at"); err != nil {
  292. beego.Error("保存关联文档时出错 ->", err)
  293. c.JsonResult(6004, "保存关联文档时出错")
  294. }
  295. }
  296. blog.BlogContent = blogContent
  297. blog.BlogRelease = blogHtml
  298. blog.ModifyAt = c.Member.MemberId
  299. blog.Modified = time.Now()
  300. if err := blog.Save("blog_content", "blog_release", "modify_at", "modify_time", "version"); err != nil {
  301. beego.Error("保存文章失败 -> ", err)
  302. c.JsonResult(6011, "保存文章失败")
  303. } else {
  304. c.JsonResult(0, "ok", blog)
  305. }
  306. }
  307. blogId, _ := strconv.Atoi(c.Ctx.Input.Param(":id"))
  308. if blogId <= 0 {
  309. c.ShowErrorPage(500, "参数错误")
  310. }
  311. var blog *models.Blog
  312. var err error
  313. if c.Member.IsAdministrator() {
  314. blog, err = models.NewBlog().Find(blogId)
  315. } else {
  316. blog, err = models.NewBlog().FindByIdAndMemberId(blogId, c.Member.MemberId)
  317. }
  318. if err != nil {
  319. c.ShowErrorPage(404, "文章不存在或已删除")
  320. }
  321. blog.LinkAttach()
  322. if len(blog.AttachList) > 0 {
  323. returnJSON, err := json.Marshal(blog.AttachList)
  324. if err != nil {
  325. beego.Error("序列化文章附件时出错 ->", err)
  326. } else {
  327. c.Data["AttachList"] = template.JS(string(returnJSON))
  328. }
  329. } else {
  330. c.Data["AttachList"] = template.JS("[]")
  331. }
  332. if conf.GetUploadFileSize() > 0 {
  333. c.Data["UploadFileSize"] = conf.GetUploadFileSize()
  334. } else {
  335. c.Data["UploadFileSize"] = "undefined";
  336. }
  337. c.Data["Model"] = blog
  338. }
  339. //删除文章
  340. func (c *BlogController) ManageDelete() {
  341. c.Prepare()
  342. blogId, _ := c.GetInt("blog_id", 0)
  343. if blogId <= 0 {
  344. c.JsonResult(6001, "参数错误")
  345. }
  346. var blog *models.Blog
  347. var err error
  348. if c.Member.IsAdministrator() {
  349. blog, err = models.NewBlog().Find(blogId)
  350. } else {
  351. blog, err = models.NewBlog().FindByIdAndMemberId(blogId, c.Member.MemberId)
  352. }
  353. if err != nil {
  354. c.JsonResult(6002, "文章不存在或已删除")
  355. }
  356. if err := blog.Delete(blogId); err != nil {
  357. c.JsonResult(6003, "删除失败")
  358. } else {
  359. c.JsonResult(0, "删除成功")
  360. }
  361. }
  362. // 上传附件或图片
  363. func (c *BlogController) Upload() {
  364. c.Prepare()
  365. blogId, _ := c.GetInt("blogId")
  366. if blogId <= 0 {
  367. c.JsonResult(6001, "参数错误")
  368. }
  369. blog, err := models.NewBlog().Find(blogId)
  370. if err != nil {
  371. c.JsonResult(6010, "文章不存在")
  372. }
  373. if !c.Member.IsAdministrator() && blog.MemberId != c.Member.MemberId {
  374. c.JsonResult(6011, "没有文章的访问权限")
  375. }
  376. name := "editormd-file-file"
  377. file, moreFile, err := c.GetFile(name)
  378. if err == http.ErrMissingFile {
  379. name = "editormd-image-file"
  380. file, moreFile, err = c.GetFile(name)
  381. if err == http.ErrMissingFile {
  382. c.JsonResult(6003, "没有发现需要上传的图片")
  383. }
  384. }
  385. if err != nil {
  386. c.JsonResult(6002, err.Error())
  387. }
  388. defer file.Close()
  389. type Size interface {
  390. Size() int64
  391. }
  392. if conf.GetUploadFileSize() > 0 && moreFile.Size > conf.GetUploadFileSize() {
  393. c.JsonResult(6009, "查过文件允许的上传最大值")
  394. }
  395. ext := filepath.Ext(moreFile.Filename)
  396. if ext == "" {
  397. c.JsonResult(6003, "无法解析文件的格式")
  398. }
  399. //如果文件类型设置为 * 标识不限制文件类型
  400. if beego.AppConfig.DefaultString("upload_file_ext", "") != "*" {
  401. if !conf.IsAllowUploadFileExt(ext) {
  402. c.JsonResult(6004, "不允许的文件类型")
  403. }
  404. }
  405. // 如果是超级管理员,则不判断权限
  406. if c.Member.IsAdministrator() {
  407. _, err := models.NewBlog().Find(blogId)
  408. if err != nil {
  409. c.JsonResult(6006, "文档不存在或权限不足")
  410. }
  411. } else {
  412. _, err := models.NewBlog().FindByIdAndMemberId(blogId, c.Member.MemberId)
  413. if err != nil {
  414. beego.Error("查询文章时出错 -> ", err)
  415. if err == orm.ErrNoRows {
  416. c.JsonResult(6006, "权限不足")
  417. }
  418. c.JsonResult(6001, err.Error())
  419. }
  420. }
  421. fileName := "attach_" + strconv.FormatInt(time.Now().UnixNano(), 16)
  422. filePath := filepath.Join(conf.WorkingDirectory, "uploads", "blog", time.Now().Format("200601"), fileName+ext)
  423. path := filepath.Dir(filePath)
  424. os.MkdirAll(path, os.ModePerm)
  425. err = c.SaveToFile(name, filePath)
  426. if err != nil {
  427. beego.Error("SaveToFile => ", err)
  428. c.JsonResult(6005, "保存文件失败")
  429. }
  430. var httpPath string
  431. result := make(map[string]interface{})
  432. //如果是图片,则当做内置图片处理,否则当做附件处理
  433. if strings.EqualFold(ext, ".jpg") || strings.EqualFold(ext, ".jpeg") || strings.EqualFold(ext, ".png") || strings.EqualFold(ext, ".gif") {
  434. httpPath = "/" + strings.Replace(strings.TrimPrefix(filePath, conf.WorkingDirectory), "\\", "/", -1)
  435. if strings.HasPrefix(httpPath, "//") {
  436. httpPath = conf.URLForWithCdnImage(string(httpPath[1:]))
  437. }
  438. } else {
  439. attachment := models.NewAttachment()
  440. attachment.BookId = 0
  441. attachment.FileName = moreFile.Filename
  442. attachment.CreateAt = c.Member.MemberId
  443. attachment.FileExt = ext
  444. attachment.FilePath = strings.TrimPrefix(filePath, conf.WorkingDirectory)
  445. attachment.DocumentId = blogId
  446. //如果是关联文章,则将附件设置为关联文档的文档上
  447. if blog.BlogType == 1 {
  448. attachment.BookId = blog.BookId
  449. attachment.DocumentId = blog.DocumentId
  450. }
  451. if fileInfo, err := os.Stat(filePath); err == nil {
  452. attachment.FileSize = float64(fileInfo.Size())
  453. }
  454. attachment.HttpPath = httpPath
  455. if err := attachment.Insert(); err != nil {
  456. os.Remove(filePath)
  457. beego.Error("保存文件附件失败 -> ", err)
  458. c.JsonResult(6006, "文件保存失败")
  459. }
  460. if attachment.HttpPath == "" {
  461. attachment.HttpPath = conf.URLForNotHost("BlogController.Download", ":id", blogId, ":attach_id", attachment.AttachmentId)
  462. if err := attachment.Update(); err != nil {
  463. beego.Error("保存文件失败 -> ",attachment.FilePath, err)
  464. c.JsonResult(6005, "保存文件失败")
  465. }
  466. }
  467. result["attach"] = attachment
  468. }
  469. result["errcode"] = 0
  470. result["success"] = 1
  471. result["message"] = "ok"
  472. result["url"] = httpPath
  473. result["alt"] = fileName
  474. c.Ctx.Output.JSON(result, true, false)
  475. c.StopRun()
  476. }
  477. // 删除附件
  478. func (c *BlogController) RemoveAttachment() {
  479. c.Prepare()
  480. attachId, _ := c.GetInt("attach_id")
  481. blogId, _ := strconv.Atoi(c.Ctx.Input.Param(":id"))
  482. if attachId <= 0 {
  483. c.JsonResult(6001, "参数错误")
  484. }
  485. blog, err := models.NewBlog().Find(blogId)
  486. if err != nil {
  487. if err == orm.ErrNoRows {
  488. c.ShowErrorPage(500, "文档不存在")
  489. } else {
  490. c.ShowErrorPage(500, "查询文章时异常")
  491. }
  492. }
  493. attach, err := models.NewAttachment().Find(attachId)
  494. if err != nil {
  495. beego.Error(err)
  496. c.JsonResult(6002, "附件不存在")
  497. }
  498. if !c.Member.IsAdministrator() {
  499. _, err := models.NewBlog().FindByIdAndMemberId(attach.DocumentId, c.Member.MemberId)
  500. if err != nil {
  501. beego.Error(err)
  502. c.JsonResult(6003, "文档不存在")
  503. }
  504. }
  505. if blog.BlogType == 1 && attach.BookId != blog.BookId && attach.DocumentId != blog.DocumentId {
  506. c.ShowErrorPage(404, "附件不存在")
  507. } else if attach.BookId != 0 || attach.DocumentId != blogId {
  508. c.ShowErrorPage(404, "附件不存在")
  509. }
  510. if err := attach.Delete(); err != nil {
  511. beego.Error(err)
  512. c.JsonResult(6005, "删除失败")
  513. }
  514. os.Remove(filepath.Join(conf.WorkingDirectory, attach.FilePath))
  515. c.JsonResult(0, "ok", attach)
  516. }
  517. //下载附件
  518. func (c *BlogController) Download() {
  519. c.Prepare()
  520. blogId, _ := strconv.Atoi(c.Ctx.Input.Param(":id"))
  521. attachId, _ := strconv.Atoi(c.Ctx.Input.Param(":attach_id"))
  522. password := c.GetString("password")
  523. blog, err := models.NewBlog().Find(blogId)
  524. if err != nil {
  525. if err == orm.ErrNoRows {
  526. c.ShowErrorPage(500, "文档不存在")
  527. } else {
  528. c.ShowErrorPage(500, "查询文章时异常")
  529. }
  530. }
  531. blogReadSession := fmt.Sprintf("blog:read:%d", blogId)
  532. //如果没有启动匿名访问,或者设置了访问密码
  533. if (c.Member == nil && !c.EnableAnonymous) || (blog.BlogStatus == "password" && password != blog.Password && c.CruSession.Get(blogReadSession) == nil) {
  534. c.ShowErrorPage(403, "没有下载权限")
  535. }
  536. // 查找附件
  537. attachment, err := models.NewAttachment().Find(attachId)
  538. if err != nil {
  539. if err == orm.ErrNoRows {
  540. c.ShowErrorPage(404, "附件不存在")
  541. } else {
  542. beego.Error("查询附件时出现异常 -> ", err)
  543. c.ShowErrorPage(500, "查询附件时出现异常")
  544. }
  545. }
  546. //如果是链接的文章,需要校验文档ID是否一致,如果不是,需要保证附件的项目ID为0且文档的ID等于博文ID
  547. if blog.BlogType == 1 && attachment.DocumentId != blog.DocumentId {
  548. c.ShowErrorPage(404, "附件不存在")
  549. } else if blog.BlogType != 1 && (attachment.BookId != 0 || attachment.DocumentId != blogId ) {
  550. c.ShowErrorPage(404, "附件不存在")
  551. }
  552. c.Ctx.Output.Download(filepath.Join(conf.WorkingDirectory, attachment.FilePath), attachment.FileName)
  553. c.StopRun()
  554. }