q("SELECT * FROM `_sys_files` WHERE `id` = '" . $id . "'"); if ($core_db->nr()) { if ($core_db->f('private') == 1) { session_start(); $sess_id = session_id(); $dbAuth = $core_db->new_db(); $dbAuth->q('SELECT `id` FROM `_sys_user_sessions` WHERE `session_id` = "'.db_escape_string($sess_id).'" '); // Неавторизированному пользователю пустая картинка if (!$dbAuth->nr()) { header('Content-type: image/gif'); die(base64_decode($transparentPixelGif)); } } header('Content-type: ' . $core_db->f('ext')); $data = file_get_contents(_FILES_DIR_ . $pref . $core_db->f('filename')); die($data); } else { header('Content-type: image/gif'); die(base64_decode($transparentPixelGif)); }