Skip to content

Instantly share code, notes, and snippets.

@jeffersonchaves
Created May 21, 2026 17:20
Show Gist options
  • Select an option

  • Save jeffersonchaves/bf52e2e71a0672b0651bdc97056176fc to your computer and use it in GitHub Desktop.

Select an option

Save jeffersonchaves/bf52e2e71a0672b0651bdc97056176fc to your computer and use it in GitHub Desktop.
<?php
namespace app\controllers;
use app\core\Controller;
class ArquivoController extends Controller
{
public function visualizar()
{
// Garante que apenas usuários autenticados possam ver os arquivos
$this->autenticacaoRequired();
if (!isset($_GET['arquivo']) || empty($_GET['arquivo'])) {
http_response_code(400);
echo "Arquivo não especificado.";
return;
}
$arquivo = $_GET['arquivo'];
$storagePath = realpath(STORAGE_PATH);
// Constrói o caminho completo e resolve o caminho real do arquivo
$caminhoCompleto = realpath($storagePath . '/' . $arquivo);
// Verifica se o arquivo existe e se está dentro do diretório de storage permitido (evita Directory Traversal)
if ($caminhoCompleto && is_file($caminhoCompleto) && strpos($caminhoCompleto, $storagePath) === 0) {
// Obtém o tipo do arquivo (MIME type)
$mimeType = mime_content_type($caminhoCompleto);
// Define os cabeçalhos para exibir a imagem corretamente
header('Content-Type: ' . $mimeType);
header('Content-Length: ' . filesize($caminhoCompleto));
// Lê e envia o conteúdo do arquivo para o navegador
readfile($caminhoCompleto);
exit;
} else {
http_response_code(404);
echo "Arquivo não encontrado ou acesso negado.";
}
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment