Files
Felix KemmlerandClaude Sonnet 5 b6c1389c55 Reorganize into monorepo layout, move mitarbeiter-app to legacy reference
Consolidates the previously separate omsorgapp and omsorgCore repos
(each had their own nested .git with GitHub history) plus the old
root-level website/mitarbeiter-app into a single monorepo, matching
the structure already documented in the root CLAUDE.md. Also moves
the PHP employee app aside as omsorgWeb/mitarbeiter-app-legacy/ to
serve as a template for a ground-up rewrite.

Fixes .gitignore in the same pass: the config-secrets/uploads/data
patterns were unanchored (relative to repo root, not depth-agnostic),
so they silently stopped matching once the app moved under omsorgWeb/.
Patterns are now **/-prefixed and cover both mitarbeiter-app and
mitarbeiter-app-legacy, keeping DB/SMTP credentials and uploaded
employee documents out of version control.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-07 14:21:37 +02:00

41 lines
1.0 KiB
PHP

<?php
require_once __DIR__ . '/../lib/auth.php';
require_login();
$current = current_user();
if (is_admin() && isset($_GET['user_id'])) {
$target_id = (int)$_GET['user_id'];
} else {
$target_id = (int)$current['id'];
}
$stmt = db()->prepare('SELECT * FROM einsatzanweisung WHERE user_id = ?');
$stmt->execute([$target_id]);
$ea = $stmt->fetch();
if (!$ea || $ea['filename'] === '') {
http_response_code(404);
echo 'Keine Datei gefunden.';
exit;
}
$path = dirname(__DIR__) . '/uploads/' . basename($ea['filename']);
if (!is_file($path)) {
http_response_code(404);
echo 'Datei nicht gefunden.';
exit;
}
$display = $ea['original_name'];
$safe_display = addslashes($display);
$safe_encoded = rawurlencode($display);
header('Content-Type: application/pdf');
header('Content-Disposition: attachment; filename="' . $safe_display . '"; filename*=UTF-8\'\'' . $safe_encoded);
header('Content-Length: ' . filesize($path));
header('X-Content-Type-Options: nosniff');
header('Cache-Control: private, no-store');
readfile($path);
exit;