Response.php 42 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136
  1. <?php
  2. /**
  3. * @link https://www.yiiframework.com/
  4. * @copyright Copyright (c) 2008 Yii Software LLC
  5. * @license https://www.yiiframework.com/license/
  6. */
  7. namespace yii\web;
  8. use Yii;
  9. use yii\base\InvalidArgumentException;
  10. use yii\base\InvalidConfigException;
  11. use yii\helpers\FileHelper;
  12. use yii\helpers\Inflector;
  13. use yii\helpers\StringHelper;
  14. use yii\helpers\Url;
  15. /**
  16. * The web Response class represents an HTTP response.
  17. *
  18. * It holds the [[headers]], [[cookies]] and [[content]] that is to be sent to the client.
  19. * It also controls the HTTP [[statusCode|status code]].
  20. *
  21. * Response is configured as an application component in [[\yii\web\Application]] by default.
  22. * You can access that instance via `Yii::$app->response`.
  23. *
  24. * You can modify its configuration by adding an array to your application config under `components`
  25. * as it is shown in the following example:
  26. *
  27. * ```php
  28. * 'response' => [
  29. * 'format' => yii\web\Response::FORMAT_JSON,
  30. * 'charset' => 'UTF-8',
  31. * // ...
  32. * ]
  33. * ```
  34. *
  35. * For more details and usage information on Response, see the [guide article on responses](guide:runtime-responses).
  36. *
  37. * @property-read CookieCollection $cookies The cookie collection.
  38. * @property-write string $downloadHeaders The attachment file name.
  39. * @property-read HeaderCollection $headers The header collection.
  40. * @property-read bool $isClientError Whether this response indicates a client error.
  41. * @property-read bool $isEmpty Whether this response is empty.
  42. * @property-read bool $isForbidden Whether this response indicates the current request is forbidden.
  43. * @property-read bool $isInformational Whether this response is informational.
  44. * @property-read bool $isInvalid Whether this response has a valid [[statusCode]].
  45. * @property-read bool $isNotFound Whether this response indicates the currently requested resource is not
  46. * found.
  47. * @property-read bool $isOk Whether this response is OK.
  48. * @property-read bool $isRedirection Whether this response is a redirection.
  49. * @property-read bool $isServerError Whether this response indicates a server error.
  50. * @property-read bool $isSuccessful Whether this response is successful.
  51. * @property int $statusCode The HTTP status code to send with the response.
  52. * @property-write \Throwable $statusCodeByException The exception object.
  53. *
  54. * @author Qiang Xue <qiang.xue@gmail.com>
  55. * @author Carsten Brandt <mail@cebe.cc>
  56. * @since 2.0
  57. */
  58. class Response extends \yii\base\Response
  59. {
  60. /**
  61. * @event \yii\base\Event an event that is triggered at the beginning of [[send()]].
  62. */
  63. const EVENT_BEFORE_SEND = 'beforeSend';
  64. /**
  65. * @event \yii\base\Event an event that is triggered at the end of [[send()]].
  66. */
  67. const EVENT_AFTER_SEND = 'afterSend';
  68. /**
  69. * @event \yii\base\Event an event that is triggered right after [[prepare()]] is called in [[send()]].
  70. * You may respond to this event to filter the response content before it is sent to the client.
  71. */
  72. const EVENT_AFTER_PREPARE = 'afterPrepare';
  73. const FORMAT_RAW = 'raw';
  74. const FORMAT_HTML = 'html';
  75. const FORMAT_JSON = 'json';
  76. const FORMAT_JSONP = 'jsonp';
  77. const FORMAT_XML = 'xml';
  78. /**
  79. * @var string the response format. This determines how to convert [[data]] into [[content]]
  80. * when the latter is not set. The value of this property must be one of the keys declared in the [[formatters]] array.
  81. * By default, the following formats are supported:
  82. *
  83. * - [[FORMAT_RAW]]: the data will be treated as the response content without any conversion.
  84. * No extra HTTP header will be added.
  85. * - [[FORMAT_HTML]]: the data will be treated as the response content without any conversion.
  86. * The "Content-Type" header will set as "text/html".
  87. * - [[FORMAT_JSON]]: the data will be converted into JSON format, and the "Content-Type"
  88. * header will be set as "application/json".
  89. * - [[FORMAT_JSONP]]: the data will be converted into JSONP format, and the "Content-Type"
  90. * header will be set as "text/javascript". Note that in this case `$data` must be an array
  91. * with "data" and "callback" elements. The former refers to the actual data to be sent,
  92. * while the latter refers to the name of the JavaScript callback.
  93. * - [[FORMAT_XML]]: the data will be converted into XML format. Please refer to [[XmlResponseFormatter]]
  94. * for more details.
  95. *
  96. * You may customize the formatting process or support additional formats by configuring [[formatters]].
  97. * @see formatters
  98. */
  99. public $format = self::FORMAT_HTML;
  100. /**
  101. * @var string the MIME type (e.g. `application/json`) from the request ACCEPT header chosen for this response.
  102. * This property is mainly set by [[\yii\filters\ContentNegotiator]].
  103. */
  104. public $acceptMimeType;
  105. /**
  106. * @var array the parameters (e.g. `['q' => 1, 'version' => '1.0']`) associated with the [[acceptMimeType|chosen MIME type]].
  107. * This is a list of name-value pairs associated with [[acceptMimeType]] from the ACCEPT HTTP header.
  108. * This property is mainly set by [[\yii\filters\ContentNegotiator]].
  109. */
  110. public $acceptParams = [];
  111. /**
  112. * @var array the formatters for converting data into the response content of the specified [[format]].
  113. * The array keys are the format names, and the array values are the corresponding configurations
  114. * for creating the formatter objects.
  115. * @see format
  116. * @see defaultFormatters
  117. */
  118. public $formatters = [];
  119. /**
  120. * @var mixed the original response data. When this is not null, it will be converted into [[content]]
  121. * according to [[format]] when the response is being sent out.
  122. * @see content
  123. */
  124. public $data;
  125. /**
  126. * @var string|null the response content. When [[data]] is not null, it will be converted into [[content]]
  127. * according to [[format]] when the response is being sent out.
  128. * @see data
  129. */
  130. public $content;
  131. /**
  132. * @var resource|array|callable the stream to be sent. This can be a stream handle or an array of stream handle,
  133. * the begin position and the end position. Alternatively it can be set to a callable, which returns
  134. * (or [yields](https://www.php.net/manual/en/language.generators.syntax.php)) an array of strings that should
  135. * be echoed and flushed out one by one.
  136. *
  137. * Note that when this property is set, the [[data]] and [[content]] properties will be ignored by [[send()]].
  138. */
  139. public $stream;
  140. /**
  141. * @var string|null the charset of the text response. If not set, it will use
  142. * the value of [[Application::charset]].
  143. */
  144. public $charset;
  145. /**
  146. * @var string the HTTP status description that comes together with the status code.
  147. * @see httpStatuses
  148. */
  149. public $statusText = 'OK';
  150. /**
  151. * @var string|null the version of the HTTP protocol to use. If not set, it will be determined via `$_SERVER['SERVER_PROTOCOL']`,
  152. * or '1.1' if that is not available.
  153. */
  154. public $version;
  155. /**
  156. * @var bool whether the response has been sent. If this is true, calling [[send()]] will do nothing.
  157. */
  158. public $isSent = false;
  159. /**
  160. * @var array list of HTTP status codes and the corresponding texts
  161. */
  162. public static $httpStatuses = [
  163. 100 => 'Continue',
  164. 101 => 'Switching Protocols',
  165. 102 => 'Processing',
  166. 118 => 'Connection timed out',
  167. 200 => 'OK',
  168. 201 => 'Created',
  169. 202 => 'Accepted',
  170. 203 => 'Non-Authoritative',
  171. 204 => 'No Content',
  172. 205 => 'Reset Content',
  173. 206 => 'Partial Content',
  174. 207 => 'Multi-Status',
  175. 208 => 'Already Reported',
  176. 210 => 'Content Different',
  177. 226 => 'IM Used',
  178. 300 => 'Multiple Choices',
  179. 301 => 'Moved Permanently',
  180. 302 => 'Found',
  181. 303 => 'See Other',
  182. 304 => 'Not Modified',
  183. 305 => 'Use Proxy',
  184. 306 => 'Reserved',
  185. 307 => 'Temporary Redirect',
  186. 308 => 'Permanent Redirect',
  187. 310 => 'Too many Redirect',
  188. 400 => 'Bad Request',
  189. 401 => 'Unauthorized',
  190. 402 => 'Payment Required',
  191. 403 => 'Forbidden',
  192. 404 => 'Not Found',
  193. 405 => 'Method Not Allowed',
  194. 406 => 'Not Acceptable',
  195. 407 => 'Proxy Authentication Required',
  196. 408 => 'Request Time-out',
  197. 409 => 'Conflict',
  198. 410 => 'Gone',
  199. 411 => 'Length Required',
  200. 412 => 'Precondition Failed',
  201. 413 => 'Request Entity Too Large',
  202. 414 => 'Request-URI Too Long',
  203. 415 => 'Unsupported Media Type',
  204. 416 => 'Requested range unsatisfiable',
  205. 417 => 'Expectation failed',
  206. 418 => 'I\'m a teapot',
  207. 421 => 'Misdirected Request',
  208. 422 => 'Unprocessable entity',
  209. 423 => 'Locked',
  210. 424 => 'Method failure',
  211. 425 => 'Unordered Collection',
  212. 426 => 'Upgrade Required',
  213. 428 => 'Precondition Required',
  214. 429 => 'Too Many Requests',
  215. 431 => 'Request Header Fields Too Large',
  216. 449 => 'Retry With',
  217. 450 => 'Blocked by Windows Parental Controls',
  218. 451 => 'Unavailable For Legal Reasons',
  219. 500 => 'Internal Server Error',
  220. 501 => 'Not Implemented',
  221. 502 => 'Bad Gateway or Proxy Error',
  222. 503 => 'Service Unavailable',
  223. 504 => 'Gateway Time-out',
  224. 505 => 'HTTP Version not supported',
  225. 507 => 'Insufficient storage',
  226. 508 => 'Loop Detected',
  227. 509 => 'Bandwidth Limit Exceeded',
  228. 510 => 'Not Extended',
  229. 511 => 'Network Authentication Required',
  230. ];
  231. /**
  232. * @var int the HTTP status code to send with the response.
  233. */
  234. private $_statusCode = 200;
  235. /**
  236. * @var HeaderCollection
  237. */
  238. private $_headers;
  239. /**
  240. * Initializes this component.
  241. */
  242. public function init()
  243. {
  244. if ($this->version === null) {
  245. if (isset($_SERVER['SERVER_PROTOCOL']) && $_SERVER['SERVER_PROTOCOL'] === 'HTTP/1.0') {
  246. $this->version = '1.0';
  247. } else {
  248. $this->version = '1.1';
  249. }
  250. }
  251. if ($this->charset === null) {
  252. $this->charset = Yii::$app->charset;
  253. }
  254. $this->formatters = array_merge($this->defaultFormatters(), $this->formatters);
  255. }
  256. /**
  257. * @return int the HTTP status code to send with the response.
  258. */
  259. public function getStatusCode()
  260. {
  261. return $this->_statusCode;
  262. }
  263. /**
  264. * Sets the response status code.
  265. * This method will set the corresponding status text if `$text` is null.
  266. * @param int $value the status code
  267. * @param string|null $text the status text. If not set, it will be set automatically based on the status code.
  268. * @throws InvalidArgumentException if the status code is invalid.
  269. * @return $this the response object itself
  270. */
  271. public function setStatusCode($value, $text = null)
  272. {
  273. if ($value === null) {
  274. $value = 200;
  275. }
  276. $this->_statusCode = (int) $value;
  277. if ($this->getIsInvalid()) {
  278. throw new InvalidArgumentException("The HTTP status code is invalid: $value");
  279. }
  280. if ($text === null) {
  281. $this->statusText = isset(static::$httpStatuses[$this->_statusCode]) ? static::$httpStatuses[$this->_statusCode] : '';
  282. } else {
  283. $this->statusText = $text;
  284. }
  285. return $this;
  286. }
  287. /**
  288. * Sets the response status code based on the exception.
  289. * @param \Throwable $e the exception object.
  290. * @throws InvalidArgumentException if the status code is invalid.
  291. * @return $this the response object itself
  292. * @since 2.0.12
  293. */
  294. public function setStatusCodeByException($e)
  295. {
  296. if ($e instanceof HttpException) {
  297. $this->setStatusCode($e->statusCode);
  298. } else {
  299. $this->setStatusCode(500);
  300. }
  301. return $this;
  302. }
  303. /**
  304. * Returns the header collection.
  305. * The header collection contains the currently registered HTTP headers.
  306. * @return HeaderCollection the header collection
  307. */
  308. public function getHeaders()
  309. {
  310. if ($this->_headers === null) {
  311. $this->_headers = new HeaderCollection();
  312. }
  313. return $this->_headers;
  314. }
  315. /**
  316. * Sends the response to the client.
  317. */
  318. public function send()
  319. {
  320. if ($this->isSent) {
  321. return;
  322. }
  323. $this->trigger(self::EVENT_BEFORE_SEND);
  324. $this->prepare();
  325. $this->trigger(self::EVENT_AFTER_PREPARE);
  326. $this->sendHeaders();
  327. $this->sendContent();
  328. $this->trigger(self::EVENT_AFTER_SEND);
  329. $this->isSent = true;
  330. }
  331. /**
  332. * Clears the headers, cookies, content, status code of the response.
  333. */
  334. public function clear()
  335. {
  336. $this->_headers = null;
  337. $this->_cookies = null;
  338. $this->_statusCode = 200;
  339. $this->statusText = 'OK';
  340. $this->data = null;
  341. $this->stream = null;
  342. $this->content = null;
  343. $this->isSent = false;
  344. }
  345. /**
  346. * Sends the response headers to the client.
  347. */
  348. protected function sendHeaders()
  349. {
  350. if (headers_sent($file, $line)) {
  351. throw new HeadersAlreadySentException($file, $line);
  352. }
  353. if ($this->_headers) {
  354. foreach ($this->getHeaders() as $name => $values) {
  355. $name = str_replace(' ', '-', ucwords(str_replace('-', ' ', $name)));
  356. // set replace for first occurrence of header but false afterwards to allow multiple
  357. $replace = true;
  358. foreach ($values as $value) {
  359. header("$name: $value", $replace);
  360. $replace = false;
  361. }
  362. }
  363. }
  364. $statusCode = $this->getStatusCode();
  365. header("HTTP/{$this->version} {$statusCode} {$this->statusText}");
  366. $this->sendCookies();
  367. }
  368. /**
  369. * Sends the cookies to the client.
  370. */
  371. protected function sendCookies()
  372. {
  373. if ($this->_cookies === null) {
  374. return;
  375. }
  376. $request = Yii::$app->getRequest();
  377. if ($request->enableCookieValidation) {
  378. if ($request->cookieValidationKey == '') {
  379. throw new InvalidConfigException(get_class($request) . '::cookieValidationKey must be configured with a secret key.');
  380. }
  381. $validationKey = $request->cookieValidationKey;
  382. }
  383. foreach ($this->getCookies() as $cookie) {
  384. $value = $cookie->value;
  385. if ($cookie->expire != 1 && isset($validationKey)) {
  386. $value = Yii::$app->getSecurity()->hashData(serialize([$cookie->name, $value]), $validationKey);
  387. }
  388. if (PHP_VERSION_ID >= 70300) {
  389. setcookie($cookie->name, $value, [
  390. 'expires' => $cookie->expire,
  391. 'path' => $cookie->path,
  392. 'domain' => $cookie->domain,
  393. 'secure' => $cookie->secure,
  394. 'httpOnly' => $cookie->httpOnly,
  395. 'sameSite' => !empty($cookie->sameSite) ? $cookie->sameSite : null,
  396. ]);
  397. } else {
  398. // Work around for setting sameSite cookie prior PHP 7.3
  399. // https://stackoverflow.com/questions/39750906/php-setcookie-samesite-strict/46971326#46971326
  400. $cookiePath = $cookie->path;
  401. if (!is_null($cookie->sameSite)) {
  402. $cookiePath .= '; samesite=' . $cookie->sameSite;
  403. }
  404. setcookie($cookie->name, $value, $cookie->expire, $cookiePath, $cookie->domain, $cookie->secure, $cookie->httpOnly);
  405. }
  406. }
  407. }
  408. /**
  409. * Sends the response content to the client.
  410. */
  411. protected function sendContent()
  412. {
  413. if ($this->stream === null) {
  414. echo $this->content;
  415. return;
  416. }
  417. // Try to reset time limit for big files
  418. if (!function_exists('set_time_limit') || !@set_time_limit(0)) {
  419. Yii::warning('set_time_limit() is not available', __METHOD__);
  420. }
  421. if (is_callable($this->stream)) {
  422. $data = call_user_func($this->stream);
  423. foreach ($data as $datum) {
  424. echo $datum;
  425. flush();
  426. }
  427. return;
  428. }
  429. $chunkSize = 8 * 1024 * 1024; // 8MB per chunk
  430. if (is_array($this->stream)) {
  431. list($handle, $begin, $end) = $this->stream;
  432. // only seek if stream is seekable
  433. if ($this->isSeekable($handle)) {
  434. fseek($handle, $begin);
  435. }
  436. while (!feof($handle) && ($pos = ftell($handle)) <= $end) {
  437. if ($pos + $chunkSize > $end) {
  438. $chunkSize = $end - $pos + 1;
  439. }
  440. echo fread($handle, $chunkSize);
  441. flush(); // Free up memory. Otherwise large files will trigger PHP's memory limit.
  442. }
  443. fclose($handle);
  444. } else {
  445. while (!feof($this->stream)) {
  446. echo fread($this->stream, $chunkSize);
  447. flush();
  448. }
  449. fclose($this->stream);
  450. }
  451. }
  452. /**
  453. * Sends a file to the browser.
  454. *
  455. * Note that this method only prepares the response for file sending. The file is not sent
  456. * until [[send()]] is called explicitly or implicitly. The latter is done after you return from a controller action.
  457. *
  458. * The following is an example implementation of a controller action that allows requesting files from a directory
  459. * that is not accessible from web:
  460. *
  461. * ```php
  462. * public function actionFile($filename)
  463. * {
  464. * $storagePath = Yii::getAlias('@app/files');
  465. *
  466. * // check filename for allowed chars (do not allow ../ to avoid security issue: downloading arbitrary files)
  467. * if (!preg_match('/^[a-z0-9]+\.[a-z0-9]+$/i', $filename) || !is_file("$storagePath/$filename")) {
  468. * throw new \yii\web\NotFoundHttpException('The file does not exists.');
  469. * }
  470. * return Yii::$app->response->sendFile("$storagePath/$filename", $filename);
  471. * }
  472. * ```
  473. *
  474. * @param string $filePath the path of the file to be sent.
  475. * @param string|null $attachmentName the file name shown to the user. If null, it will be determined from `$filePath`.
  476. * @param array $options additional options for sending the file. The following options are supported:
  477. *
  478. * - `mimeType`: the MIME type of the content. If not set, it will be guessed based on `$filePath`
  479. * - `inline`: boolean, whether the browser should open the file within the browser window. Defaults to false,
  480. * meaning a download dialog will pop up.
  481. *
  482. * @return $this the response object itself
  483. * @see sendContentAsFile()
  484. * @see sendStreamAsFile()
  485. * @see xSendFile()
  486. */
  487. public function sendFile($filePath, $attachmentName = null, $options = [])
  488. {
  489. if (!isset($options['mimeType'])) {
  490. $options['mimeType'] = FileHelper::getMimeTypeByExtension($filePath);
  491. }
  492. if ($attachmentName === null) {
  493. $attachmentName = basename($filePath);
  494. }
  495. $handle = fopen($filePath, 'rb');
  496. $this->sendStreamAsFile($handle, $attachmentName, $options);
  497. return $this;
  498. }
  499. /**
  500. * Sends the specified content as a file to the browser.
  501. *
  502. * Note that this method only prepares the response for file sending. The file is not sent
  503. * until [[send()]] is called explicitly or implicitly. The latter is done after you return from a controller action.
  504. *
  505. * @param string $content the content to be sent. The existing [[content]] will be discarded.
  506. * @param string $attachmentName the file name shown to the user.
  507. * @param array $options additional options for sending the file. The following options are supported:
  508. *
  509. * - `mimeType`: the MIME type of the content. Defaults to 'application/octet-stream'.
  510. * - `inline`: boolean, whether the browser should open the file within the browser window. Defaults to false,
  511. * meaning a download dialog will pop up.
  512. *
  513. * @return $this the response object itself
  514. * @throws RangeNotSatisfiableHttpException if the requested range is not satisfiable
  515. * @see sendFile() for an example implementation.
  516. */
  517. public function sendContentAsFile($content, $attachmentName, $options = [])
  518. {
  519. $headers = $this->getHeaders();
  520. $contentLength = StringHelper::byteLength($content);
  521. $range = $this->getHttpRange($contentLength);
  522. if ($range === false) {
  523. $headers->set('Content-Range', "bytes */$contentLength");
  524. throw new RangeNotSatisfiableHttpException();
  525. }
  526. list($begin, $end) = $range;
  527. if ($begin != 0 || $end != $contentLength - 1) {
  528. $this->setStatusCode(206);
  529. $headers->set('Content-Range', "bytes $begin-$end/$contentLength");
  530. $this->content = StringHelper::byteSubstr($content, $begin, $end - $begin + 1);
  531. } else {
  532. $this->setStatusCode(200);
  533. $this->content = $content;
  534. }
  535. $mimeType = isset($options['mimeType']) ? $options['mimeType'] : 'application/octet-stream';
  536. $this->setDownloadHeaders($attachmentName, $mimeType, !empty($options['inline']), $end - $begin + 1);
  537. $this->format = self::FORMAT_RAW;
  538. return $this;
  539. }
  540. /**
  541. * Sends the specified stream as a file to the browser.
  542. *
  543. * Note that this method only prepares the response for file sending. The file is not sent
  544. * until [[send()]] is called explicitly or implicitly. The latter is done after you return from a controller action.
  545. *
  546. * @param resource $handle the handle of the stream to be sent.
  547. * @param string $attachmentName the file name shown to the user.
  548. * @param array $options additional options for sending the file. The following options are supported:
  549. *
  550. * - `mimeType`: the MIME type of the content. Defaults to 'application/octet-stream'.
  551. * - `inline`: boolean, whether the browser should open the file within the browser window. Defaults to false,
  552. * meaning a download dialog will pop up.
  553. * - `fileSize`: the size of the content to stream this is useful when size of the content is known
  554. * and the content is not seekable. Defaults to content size using `ftell()`.
  555. * This option is available since version 2.0.4.
  556. *
  557. * @return $this the response object itself
  558. * @throws RangeNotSatisfiableHttpException if the requested range is not satisfiable
  559. * @see sendFile() for an example implementation.
  560. */
  561. public function sendStreamAsFile($handle, $attachmentName, $options = [])
  562. {
  563. $headers = $this->getHeaders();
  564. if (isset($options['fileSize'])) {
  565. $fileSize = $options['fileSize'];
  566. } else {
  567. if ($this->isSeekable($handle)) {
  568. fseek($handle, 0, SEEK_END);
  569. $fileSize = ftell($handle);
  570. } else {
  571. $fileSize = 0;
  572. }
  573. }
  574. $range = $this->getHttpRange($fileSize);
  575. if ($range === false) {
  576. $headers->set('Content-Range', "bytes */$fileSize");
  577. throw new RangeNotSatisfiableHttpException();
  578. }
  579. list($begin, $end) = $range;
  580. if ($begin != 0 || $end != $fileSize - 1) {
  581. $this->setStatusCode(206);
  582. $headers->set('Content-Range', "bytes $begin-$end/$fileSize");
  583. } else {
  584. $this->setStatusCode(200);
  585. }
  586. $mimeType = isset($options['mimeType']) ? $options['mimeType'] : 'application/octet-stream';
  587. $this->setDownloadHeaders($attachmentName, $mimeType, !empty($options['inline']), $end - $begin + 1);
  588. $this->format = self::FORMAT_RAW;
  589. $this->stream = [$handle, $begin, $end];
  590. return $this;
  591. }
  592. /**
  593. * Sets a default set of HTTP headers for file downloading purpose.
  594. * @param string $attachmentName the attachment file name
  595. * @param string|null $mimeType the MIME type for the response. If null, `Content-Type` header will NOT be set.
  596. * @param bool $inline whether the browser should open the file within the browser window. Defaults to false,
  597. * meaning a download dialog will pop up.
  598. * @param int|null $contentLength the byte length of the file being downloaded. If null, `Content-Length` header will NOT be set.
  599. * @return $this the response object itself
  600. */
  601. public function setDownloadHeaders($attachmentName, $mimeType = null, $inline = false, $contentLength = null)
  602. {
  603. $headers = $this->getHeaders();
  604. $disposition = $inline ? 'inline' : 'attachment';
  605. $headers->setDefault('Pragma', 'public')
  606. ->setDefault('Accept-Ranges', 'bytes')
  607. ->setDefault('Expires', '0')
  608. ->setDefault('Cache-Control', 'must-revalidate, post-check=0, pre-check=0')
  609. ->setDefault('Content-Disposition', $this->getDispositionHeaderValue($disposition, $attachmentName));
  610. if ($mimeType !== null) {
  611. $headers->setDefault('Content-Type', $mimeType);
  612. }
  613. if ($contentLength !== null) {
  614. $headers->setDefault('Content-Length', $contentLength);
  615. }
  616. return $this;
  617. }
  618. /**
  619. * Determines the HTTP range given in the request.
  620. * @param int $fileSize the size of the file that will be used to validate the requested HTTP range.
  621. * @return array|bool the range (begin, end), or false if the range request is invalid.
  622. */
  623. protected function getHttpRange($fileSize)
  624. {
  625. $rangeHeader = Yii::$app->getRequest()->getHeaders()->get('Range', '-');
  626. if ($rangeHeader === '-') {
  627. return [0, $fileSize - 1];
  628. }
  629. if (!preg_match('/^bytes=(\d*)-(\d*)$/', $rangeHeader, $matches)) {
  630. return false;
  631. }
  632. if ($matches[1] === '') {
  633. $start = $fileSize - $matches[2];
  634. $end = $fileSize - 1;
  635. } elseif ($matches[2] !== '') {
  636. $start = $matches[1];
  637. $end = $matches[2];
  638. if ($end >= $fileSize) {
  639. $end = $fileSize - 1;
  640. }
  641. } else {
  642. $start = $matches[1];
  643. $end = $fileSize - 1;
  644. }
  645. if ($start < 0 || $start > $end) {
  646. return false;
  647. }
  648. return [$start, $end];
  649. }
  650. /**
  651. * Sends existing file to a browser as a download using x-sendfile.
  652. *
  653. * X-Sendfile is a feature allowing a web application to redirect the request for a file to the webserver
  654. * that in turn processes the request, this way eliminating the need to perform tasks like reading the file
  655. * and sending it to the user. When dealing with a lot of files (or very big files) this can lead to a great
  656. * increase in performance as the web application is allowed to terminate earlier while the webserver is
  657. * handling the request.
  658. *
  659. * The request is sent to the server through a special non-standard HTTP-header.
  660. * When the web server encounters the presence of such header it will discard all output and send the file
  661. * specified by that header using web server internals including all optimizations like caching-headers.
  662. *
  663. * As this header directive is non-standard different directives exists for different web servers applications:
  664. *
  665. * - Apache: [X-Sendfile](https://tn123.org/mod_xsendfile/)
  666. * - Lighttpd v1.4: [X-LIGHTTPD-send-file](https://redmine.lighttpd.net/projects/lighttpd/wiki/X-LIGHTTPD-send-file)
  667. * - Lighttpd v1.5: [X-Sendfile](https://redmine.lighttpd.net/projects/lighttpd/wiki/X-LIGHTTPD-send-file)
  668. * - Nginx: [X-Accel-Redirect](https://www.nginx.com/resources/wiki/XSendfile)
  669. * - Cherokee: [X-Sendfile and X-Accel-Redirect](https://cherokee-project.com/doc/other_goodies.html#x-sendfile)
  670. *
  671. * So for this method to work the X-SENDFILE option/module should be enabled by the web server and
  672. * a proper xHeader should be sent.
  673. *
  674. * **Note**
  675. *
  676. * This option allows to download files that are not under web folders, and even files that are otherwise protected
  677. * (deny from all) like `.htaccess`.
  678. *
  679. * **Side effects**
  680. *
  681. * If this option is disabled by the web server, when this method is called a download configuration dialog
  682. * will open but the downloaded file will have 0 bytes.
  683. *
  684. * **Known issues**
  685. *
  686. * There is a Bug with Internet Explorer 6, 7 and 8 when X-SENDFILE is used over an SSL connection, it will show
  687. * an error message like this: "Internet Explorer was not able to open this Internet site. The requested site
  688. * is either unavailable or cannot be found.". You can work around this problem by removing the `Pragma`-header.
  689. *
  690. * **Example**
  691. *
  692. * ```php
  693. * Yii::$app->response->xSendFile('/home/user/Pictures/picture1.jpg');
  694. * ```
  695. *
  696. * @param string $filePath file name with full path
  697. * @param string|null $attachmentName file name shown to the user. If null, it will be determined from `$filePath`.
  698. * @param array $options additional options for sending the file. The following options are supported:
  699. *
  700. * - `mimeType`: the MIME type of the content. If not set, it will be guessed based on `$filePath`
  701. * - `inline`: boolean, whether the browser should open the file within the browser window. Defaults to false,
  702. * meaning a download dialog will pop up.
  703. * - xHeader: string, the name of the x-sendfile header. Defaults to "X-Sendfile".
  704. *
  705. * @return $this the response object itself
  706. * @see sendFile()
  707. */
  708. public function xSendFile($filePath, $attachmentName = null, $options = [])
  709. {
  710. if ($attachmentName === null) {
  711. $attachmentName = basename($filePath);
  712. }
  713. if (isset($options['mimeType'])) {
  714. $mimeType = $options['mimeType'];
  715. } elseif (($mimeType = FileHelper::getMimeTypeByExtension($filePath)) === null) {
  716. $mimeType = 'application/octet-stream';
  717. }
  718. if (isset($options['xHeader'])) {
  719. $xHeader = $options['xHeader'];
  720. } else {
  721. $xHeader = 'X-Sendfile';
  722. }
  723. $disposition = empty($options['inline']) ? 'attachment' : 'inline';
  724. $this->getHeaders()
  725. ->setDefault($xHeader, $filePath)
  726. ->setDefault('Content-Type', $mimeType)
  727. ->setDefault('Content-Disposition', $this->getDispositionHeaderValue($disposition, $attachmentName));
  728. $this->format = self::FORMAT_RAW;
  729. return $this;
  730. }
  731. /**
  732. * Returns Content-Disposition header value that is safe to use with both old and new browsers.
  733. *
  734. * Fallback name:
  735. *
  736. * - Causes issues if contains non-ASCII characters with codes less than 32 or more than 126.
  737. * - Causes issues if contains urlencoded characters (starting with `%`) or `%` character. Some browsers interpret
  738. * `filename="X"` as urlencoded name, some don't.
  739. * - Causes issues if contains path separator characters such as `\` or `/`.
  740. * - Since value is wrapped with `"`, it should be escaped as `\"`.
  741. * - Since input could contain non-ASCII characters, fallback is obtained by transliteration.
  742. *
  743. * UTF name:
  744. *
  745. * - Causes issues if contains path separator characters such as `\` or `/`.
  746. * - Should be urlencoded since headers are ASCII-only.
  747. * - Could be omitted if it exactly matches fallback name.
  748. *
  749. * @param string $disposition
  750. * @param string $attachmentName
  751. * @return string
  752. *
  753. * @since 2.0.10
  754. */
  755. protected function getDispositionHeaderValue($disposition, $attachmentName)
  756. {
  757. $fallbackName = str_replace(
  758. ['%', '/', '\\', '"', "\x7F"],
  759. ['_', '_', '_', '\\"', '_'],
  760. Inflector::transliterate($attachmentName, Inflector::TRANSLITERATE_LOOSE)
  761. );
  762. $utfName = rawurlencode(str_replace(['%', '/', '\\'], '', $attachmentName));
  763. $dispositionHeader = "{$disposition}; filename=\"{$fallbackName}\"";
  764. if ($utfName !== $fallbackName) {
  765. $dispositionHeader .= "; filename*=utf-8''{$utfName}";
  766. }
  767. return $dispositionHeader;
  768. }
  769. /**
  770. * Redirects the browser to the specified URL.
  771. *
  772. * This method adds a "Location" header to the current response. Note that it does not send out
  773. * the header until [[send()]] is called. In a controller action you may use this method as follows:
  774. *
  775. * ```php
  776. * return Yii::$app->getResponse()->redirect($url);
  777. * ```
  778. *
  779. * In other places, if you want to send out the "Location" header immediately, you should use
  780. * the following code:
  781. *
  782. * ```php
  783. * Yii::$app->getResponse()->redirect($url)->send();
  784. * return;
  785. * ```
  786. *
  787. * In AJAX mode, this normally will not work as expected unless there are some
  788. * client-side JavaScript code handling the redirection. To help achieve this goal,
  789. * this method will send out a "X-Redirect" header instead of "Location".
  790. *
  791. * If you use the "yii" JavaScript module, it will handle the AJAX redirection as
  792. * described above. Otherwise, you should write the following JavaScript code to
  793. * handle the redirection:
  794. *
  795. * ```javascript
  796. * $document.ajaxComplete(function (event, xhr, settings) {
  797. * var url = xhr && xhr.getResponseHeader('X-Redirect');
  798. * if (url) {
  799. * window.location = url;
  800. * }
  801. * });
  802. * ```
  803. *
  804. * @param string|array $url the URL to be redirected to. This can be in one of the following formats:
  805. *
  806. * - a string representing a URL (e.g. "https://example.com")
  807. * - a string representing a URL alias (e.g. "@example.com")
  808. * - an array in the format of `[$route, ...name-value pairs...]` (e.g. `['site/index', 'ref' => 1]`).
  809. * Note that the route is with respect to the whole application, instead of relative to a controller or module.
  810. * [[Url::to()]] will be used to convert the array into a URL.
  811. *
  812. * Any relative URL that starts with a single forward slash "/" will be converted
  813. * into an absolute one by prepending it with the host info of the current request.
  814. *
  815. * @param int $statusCode the HTTP status code. Defaults to 302.
  816. * See <https://tools.ietf.org/html/rfc2616#section-10>
  817. * for details about HTTP status code
  818. * @param bool $checkAjax whether to specially handle AJAX (and PJAX) requests. Defaults to true,
  819. * meaning if the current request is an AJAX or PJAX request, then calling this method will cause the browser
  820. * to redirect to the given URL. If this is false, a `Location` header will be sent, which when received as
  821. * an AJAX/PJAX response, may NOT cause browser redirection.
  822. * Takes effect only when request header `X-Ie-Redirect-Compatibility` is absent.
  823. * @return $this the response object itself
  824. */
  825. public function redirect($url, $statusCode = 302, $checkAjax = true)
  826. {
  827. if (is_array($url) && isset($url[0])) {
  828. // ensure the route is absolute
  829. $url[0] = '/' . ltrim($url[0], '/');
  830. }
  831. $request = Yii::$app->getRequest();
  832. $normalizedUrl = Url::to($url);
  833. if (
  834. $normalizedUrl !== null
  835. && strncmp($normalizedUrl, '/', 1) === 0
  836. && strncmp($normalizedUrl, '//', 2) !== 0
  837. ) {
  838. $normalizedUrl = $request->getHostInfo() . $normalizedUrl;
  839. }
  840. if ($checkAjax && $request->getIsAjax()) {
  841. if (
  842. in_array($statusCode, [301, 302])
  843. && preg_match('/Trident\/|MSIE[ ]/', (string)$request->userAgent)
  844. ) {
  845. $statusCode = 200;
  846. }
  847. if ($request->getIsPjax()) {
  848. $this->getHeaders()->set('X-Pjax-Url', $normalizedUrl);
  849. } else {
  850. $this->getHeaders()->set('X-Redirect', $normalizedUrl);
  851. }
  852. } else {
  853. $this->getHeaders()->set('Location', $normalizedUrl);
  854. }
  855. $this->setStatusCode($statusCode);
  856. return $this;
  857. }
  858. /**
  859. * Refreshes the current page.
  860. * The effect of this method call is the same as the user pressing the refresh button of his browser
  861. * (without re-posting data).
  862. *
  863. * In a controller action you may use this method like this:
  864. *
  865. * ```php
  866. * return Yii::$app->getResponse()->refresh();
  867. * ```
  868. *
  869. * @param string $anchor the anchor that should be appended to the redirection URL.
  870. * Defaults to empty. Make sure the anchor starts with '#' if you want to specify it.
  871. * @return Response the response object itself
  872. */
  873. public function refresh($anchor = '')
  874. {
  875. return $this->redirect(Yii::$app->getRequest()->getUrl() . $anchor);
  876. }
  877. private $_cookies;
  878. /**
  879. * Returns the cookie collection.
  880. *
  881. * Through the returned cookie collection, you add or remove cookies as follows,
  882. *
  883. * ```php
  884. * // add a cookie
  885. * $response->cookies->add(new Cookie([
  886. * 'name' => $name,
  887. * 'value' => $value,
  888. * ]);
  889. *
  890. * // remove a cookie
  891. * $response->cookies->remove('name');
  892. * // alternatively
  893. * unset($response->cookies['name']);
  894. * ```
  895. *
  896. * @return CookieCollection the cookie collection.
  897. */
  898. public function getCookies()
  899. {
  900. if ($this->_cookies === null) {
  901. $this->_cookies = new CookieCollection();
  902. }
  903. return $this->_cookies;
  904. }
  905. /**
  906. * @return bool whether this response has a valid [[statusCode]].
  907. */
  908. public function getIsInvalid()
  909. {
  910. return $this->getStatusCode() < 100 || $this->getStatusCode() >= 600;
  911. }
  912. /**
  913. * @return bool whether this response is informational
  914. */
  915. public function getIsInformational()
  916. {
  917. return $this->getStatusCode() >= 100 && $this->getStatusCode() < 200;
  918. }
  919. /**
  920. * @return bool whether this response is successful
  921. */
  922. public function getIsSuccessful()
  923. {
  924. return $this->getStatusCode() >= 200 && $this->getStatusCode() < 300;
  925. }
  926. /**
  927. * @return bool whether this response is a redirection
  928. */
  929. public function getIsRedirection()
  930. {
  931. return $this->getStatusCode() >= 300 && $this->getStatusCode() < 400;
  932. }
  933. /**
  934. * @return bool whether this response indicates a client error
  935. */
  936. public function getIsClientError()
  937. {
  938. return $this->getStatusCode() >= 400 && $this->getStatusCode() < 500;
  939. }
  940. /**
  941. * @return bool whether this response indicates a server error
  942. */
  943. public function getIsServerError()
  944. {
  945. return $this->getStatusCode() >= 500 && $this->getStatusCode() < 600;
  946. }
  947. /**
  948. * @return bool whether this response is OK
  949. */
  950. public function getIsOk()
  951. {
  952. return $this->getStatusCode() == 200;
  953. }
  954. /**
  955. * @return bool whether this response indicates the current request is forbidden
  956. */
  957. public function getIsForbidden()
  958. {
  959. return $this->getStatusCode() == 403;
  960. }
  961. /**
  962. * @return bool whether this response indicates the currently requested resource is not found
  963. */
  964. public function getIsNotFound()
  965. {
  966. return $this->getStatusCode() == 404;
  967. }
  968. /**
  969. * @return bool whether this response is empty
  970. */
  971. public function getIsEmpty()
  972. {
  973. return in_array($this->getStatusCode(), [201, 204, 304]);
  974. }
  975. /**
  976. * @return array the formatters that are supported by default
  977. */
  978. protected function defaultFormatters()
  979. {
  980. return [
  981. self::FORMAT_HTML => [
  982. 'class' => 'yii\web\HtmlResponseFormatter',
  983. ],
  984. self::FORMAT_XML => [
  985. 'class' => 'yii\web\XmlResponseFormatter',
  986. ],
  987. self::FORMAT_JSON => [
  988. 'class' => 'yii\web\JsonResponseFormatter',
  989. ],
  990. self::FORMAT_JSONP => [
  991. 'class' => 'yii\web\JsonResponseFormatter',
  992. 'useJsonp' => true,
  993. ],
  994. ];
  995. }
  996. /**
  997. * Prepares for sending the response.
  998. * The default implementation will convert [[data]] into [[content]] and set headers accordingly.
  999. * @throws InvalidConfigException if the formatter for the specified format is invalid or [[format]] is not supported
  1000. *
  1001. * @see https://tools.ietf.org/html/rfc7231#page-53
  1002. * @see https://tools.ietf.org/html/rfc7232#page-18
  1003. */
  1004. protected function prepare()
  1005. {
  1006. if (in_array($this->getStatusCode(), [204, 304])) {
  1007. // A 204/304 response cannot contain a message body according to rfc7231/rfc7232
  1008. $this->content = '';
  1009. $this->stream = null;
  1010. return;
  1011. }
  1012. if ($this->stream !== null) {
  1013. return;
  1014. }
  1015. if (isset($this->formatters[$this->format])) {
  1016. $formatter = $this->formatters[$this->format];
  1017. if (!is_object($formatter)) {
  1018. $this->formatters[$this->format] = $formatter = Yii::createObject($formatter);
  1019. }
  1020. if ($formatter instanceof ResponseFormatterInterface) {
  1021. $formatter->format($this);
  1022. } else {
  1023. throw new InvalidConfigException("The '{$this->format}' response formatter is invalid. It must implement the ResponseFormatterInterface.");
  1024. }
  1025. } elseif ($this->format === self::FORMAT_RAW) {
  1026. if ($this->data !== null) {
  1027. $this->content = $this->data;
  1028. }
  1029. } else {
  1030. throw new InvalidConfigException("Unsupported response format: {$this->format}");
  1031. }
  1032. if (is_array($this->content)) {
  1033. throw new InvalidArgumentException('Response content must not be an array.');
  1034. } elseif (is_object($this->content)) {
  1035. if (method_exists($this->content, '__toString')) {
  1036. $this->content = $this->content->__toString();
  1037. } else {
  1038. throw new InvalidArgumentException('Response content must be a string or an object implementing __toString().');
  1039. }
  1040. }
  1041. }
  1042. /**
  1043. * Checks if a stream is seekable
  1044. *
  1045. * @param $handle
  1046. * @return bool
  1047. */
  1048. private function isSeekable($handle)
  1049. {
  1050. if (!is_resource($handle)) {
  1051. return true;
  1052. }
  1053. $metaData = stream_get_meta_data($handle);
  1054. return isset($metaData['seekable']) && $metaData['seekable'] === true;
  1055. }
  1056. }