Consolidates the previously separate omsorgapp and omsorgCore repos (each had their own nested .git with GitHub history) plus the old root-level website/mitarbeiter-app into a single monorepo, matching the structure already documented in the root CLAUDE.md. Also moves the PHP employee app aside as omsorgWeb/mitarbeiter-app-legacy/ to serve as a template for a ground-up rewrite. Fixes .gitignore in the same pass: the config-secrets/uploads/data patterns were unanchored (relative to repo root, not depth-agnostic), so they silently stopped matching once the app moved under omsorgWeb/. Patterns are now **/-prefixed and cover both mitarbeiter-app and mitarbeiter-app-legacy, keeping DB/SMTP credentials and uploaded employee documents out of version control. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
22 lines
757 B
PHP
22 lines
757 B
PHP
<?php
|
|
require_once __DIR__ . '/../lib/auth.php';
|
|
require_admin();
|
|
|
|
$file = basename($_GET['file'] ?? '');
|
|
if ($file === '') { http_response_code(400); echo 'Ungültige Anfrage.'; exit; }
|
|
|
|
$path = dirname(__DIR__) . '/uploads/' . $file;
|
|
if (!is_file($path)) { http_response_code(404); echo 'Datei nicht gefunden.'; exit; }
|
|
|
|
$display = $_GET['name'] ?? $file;
|
|
$safe_display = addslashes($display);
|
|
$safe_encoded = rawurlencode($display);
|
|
|
|
header('Content-Type: application/octet-stream');
|
|
header('Content-Disposition: attachment; filename="' . $safe_display . '"; filename*=UTF-8\'\'' . $safe_encoded);
|
|
header('Content-Length: ' . filesize($path));
|
|
header('X-Content-Type-Options: nosniff');
|
|
header('Cache-Control: private, no-store');
|
|
readfile($path);
|
|
exit;
|