class.phpmailer.php 144 KB
Newer Older
Scott committed
1 2 3
<?php
/**
 * PHPMailer - PHP email creation and transport class.
Scott committed
4
 * PHP Version 5
Scott committed
5
 * @package PHPMailer
Scott committed
6 7
 * @link https://github.com/PHPMailer/PHPMailer/ The PHPMailer GitHub project
 * @author Marcus Bointon (Synchro/coolbru) <phpmailer@synchromedia.co.uk>
Scott committed
8 9 10
 * @author Jim Jagielski (jimjag) <jimjag@gmail.com>
 * @author Andy Prevost (codeworxtech) <codeworxtech@users.sourceforge.net>
 * @author Brent R. Matzelle (original founder)
Scott committed
11
 * @copyright 2012 - 2014 Marcus Bointon
Scott committed
12 13 14 15 16 17 18 19 20 21 22
 * @copyright 2010 - 2012 Jim Jagielski
 * @copyright 2004 - 2009 Andy Prevost
 * @license http://www.gnu.org/copyleft/lesser.html GNU Lesser General Public License
 * @note This program is distributed in the hope that it will be useful - WITHOUT
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
 * FITNESS FOR A PARTICULAR PURPOSE.
 */

/**
 * PHPMailer - PHP email creation and transport class.
 * @package PHPMailer
Scott committed
23
 * @author Marcus Bointon (Synchro/coolbru) <phpmailer@synchromedia.co.uk>
Scott committed
24 25 26 27 28 29 30 31
 * @author Jim Jagielski (jimjag) <jimjag@gmail.com>
 * @author Andy Prevost (codeworxtech) <codeworxtech@users.sourceforge.net>
 * @author Brent R. Matzelle (original founder)
 */
class PHPMailer
{
    /**
     * The PHPMailer Version number.
Scott committed
32
     * @var string
Scott committed
33
     */
Scott committed
34
    public $Version = '5.2.26';
Scott committed
35 36 37

    /**
     * Email priority.
Scott committed
38 39
     * Options: null (default), 1 = High, 3 = Normal, 5 = low.
     * When null, the header is not set at all.
Scott committed
40
     * @var integer
Scott committed
41
     */
Scott committed
42
    public $Priority = null;
Scott committed
43 44 45

    /**
     * The character set of the message.
Scott committed
46
     * @var string
Scott committed
47 48 49 50 51
     */
    public $CharSet = 'iso-8859-1';

    /**
     * The MIME Content-type of the message.
Scott committed
52
     * @var string
Scott committed
53 54 55 56 57 58
     */
    public $ContentType = 'text/plain';

    /**
     * The message encoding.
     * Options: "8bit", "7bit", "binary", "base64", and "quoted-printable".
Scott committed
59
     * @var string
Scott committed
60 61 62 63 64
     */
    public $Encoding = '8bit';

    /**
     * Holds the most recent mailer error message.
Scott committed
65
     * @var string
Scott committed
66 67 68 69 70
     */
    public $ErrorInfo = '';

    /**
     * The From email address for the message.
Scott committed
71
     * @var string
Scott committed
72 73 74 75 76
     */
    public $From = 'root@localhost';

    /**
     * The From name of the message.
Scott committed
77
     * @var string
Scott committed
78 79 80 81 82 83
     */
    public $FromName = 'Root User';

    /**
     * The Sender email (Return-Path) of the message.
     * If not empty, will be sent via -f to sendmail or as 'MAIL FROM' in smtp mode.
Scott committed
84
     * @var string
Scott committed
85 86 87 88 89 90
     */
    public $Sender = '';

    /**
     * The Return-Path of the message.
     * If empty, it will be set to either From or Sender.
Scott committed
91
     * @var string
Scott committed
92 93 94
     * @deprecated Email senders should never set a return-path header;
     * it's the receiver's job (RFC5321 section 4.4), so this no longer does anything.
     * @link https://tools.ietf.org/html/rfc5321#section-4.4 RFC5321 reference
Scott committed
95 96 97 98 99
     */
    public $ReturnPath = '';

    /**
     * The Subject of the message.
Scott committed
100
     * @var string
Scott committed
101 102 103 104 105 106
     */
    public $Subject = '';

    /**
     * An HTML or plain text message body.
     * If HTML then call isHTML(true).
Scott committed
107
     * @var string
Scott committed
108 109 110 111 112 113 114 115
     */
    public $Body = '';

    /**
     * The plain-text message body.
     * This body can be read by mail clients that do not have HTML email
     * capability such as mutt & Eudora.
     * Clients that can read HTML will view the normal Body.
Scott committed
116
     * @var string
Scott committed
117 118 119 120 121 122 123 124 125
     */
    public $AltBody = '';

    /**
     * An iCal message part body.
     * Only supported in simple alt or alt_inline message types
     * To generate iCal events, use the bundled extras/EasyPeasyICS.php class or iCalcreator
     * @link http://sprain.ch/blog/downloads/php-class-easypeasyics-create-ical-files-with-php/
     * @link http://kigkonsult.se/iCalcreator/
Scott committed
126
     * @var string
Scott committed
127 128 129 130 131 132
     */
    public $Ical = '';

    /**
     * The complete compiled MIME message body.
     * @access protected
Scott committed
133
     * @var string
Scott committed
134 135 136 137 138
     */
    protected $MIMEBody = '';

    /**
     * The complete compiled MIME message headers.
Scott committed
139
     * @var string
Scott committed
140 141 142 143 144 145
     * @access protected
     */
    protected $MIMEHeader = '';

    /**
     * Extra headers that createHeader() doesn't fold in.
Scott committed
146
     * @var string
Scott committed
147 148 149 150 151 152
     * @access protected
     */
    protected $mailHeader = '';

    /**
     * Word-wrap the message body to this number of chars.
Scott committed
153
     * Set to 0 to not wrap. A useful value here is 78, for RFC2822 section 2.1.1 compliance.
Scott committed
154
     * @var integer
Scott committed
155 156 157 158 159 160
     */
    public $WordWrap = 0;

    /**
     * Which method to use to send mail.
     * Options: "mail", "sendmail", or "smtp".
Scott committed
161
     * @var string
Scott committed
162 163 164 165 166
     */
    public $Mailer = 'mail';

    /**
     * The path to the sendmail program.
Scott committed
167
     * @var string
Scott committed
168 169 170 171 172 173
     */
    public $Sendmail = '/usr/sbin/sendmail';

    /**
     * Whether mail() uses a fully sendmail-compatible MTA.
     * One which supports sendmail's "-oi -f" options.
Scott committed
174
     * @var boolean
Scott committed
175 176 177 178 179 180
     */
    public $UseSendmailOptions = true;

    /**
     * Path to PHPMailer plugins.
     * Useful if the SMTP class is not in the PHP include path.
Scott committed
181
     * @var string
Scott committed
182 183 184 185 186
     * @deprecated Should not be needed now there is an autoloader.
     */
    public $PluginDir = '';

    /**
Scott committed
187 188
     * The email address that a reading confirmation should be sent to, also known as read receipt.
     * @var string
Scott committed
189 190 191 192
     */
    public $ConfirmReadingTo = '';

    /**
Scott committed
193 194 195 196 197
     * The hostname to use in the Message-ID header and as default HELO string.
     * If empty, PHPMailer attempts to find one with, in order,
     * $_SERVER['SERVER_NAME'], gethostname(), php_uname('n'), or the value
     * 'localhost.localdomain'.
     * @var string
Scott committed
198 199 200 201
     */
    public $Hostname = '';

    /**
Scott committed
202
     * An ID to be used in the Message-ID header.
Scott committed
203
     * If empty, a unique id will be generated.
ProThoughts committed
204 205 206
     * You can set your own, but it must be in the format "<id@domain>",
     * as defined in RFC5322 section 3.6.4 or it will be ignored.
     * @see https://tools.ietf.org/html/rfc5322#section-3.6.4
Scott committed
207
     * @var string
Scott committed
208 209 210 211 212 213
     */
    public $MessageID = '';

    /**
     * The message Date to be used in the Date header.
     * If empty, the current date will be added.
Scott committed
214
     * @var string
Scott committed
215 216 217 218 219 220 221 222 223
     */
    public $MessageDate = '';

    /**
     * SMTP hosts.
     * Either a single hostname or multiple semicolon-delimited hostnames.
     * You can also specify a different port
     * for each host by using this format: [hostname:port]
     * (e.g. "smtp1.example.com:25;smtp2.example.com").
Scott committed
224 225
     * You can also specify encryption type, for example:
     * (e.g. "tls://smtp1.example.com:587;ssl://smtp2.example.com:465").
Scott committed
226
     * Hosts will be tried in order.
Scott committed
227
     * @var string
Scott committed
228 229 230 231 232
     */
    public $Host = 'localhost';

    /**
     * The default SMTP server port.
Scott committed
233
     * @var integer
Scott committed
234
     * @TODO Why is this needed when the SMTP class takes care of it?
Scott committed
235 236 237 238 239
     */
    public $Port = 25;

    /**
     * The SMTP HELO of the message.
Scott committed
240 241 242
     * Default is $Hostname. If $Hostname is empty, PHPMailer attempts to find
     * one with the same method described above for $Hostname.
     * @var string
Scott committed
243 244 245 246 247
     * @see PHPMailer::$Hostname
     */
    public $Helo = '';

    /**
Scott committed
248 249
     * What kind of encryption to use on the SMTP connection.
     * Options: '', 'ssl' or 'tls'
Scott committed
250
     * @var string
Scott committed
251 252 253
     */
    public $SMTPSecure = '';

Scott committed
254 255 256 257
    /**
     * Whether to enable TLS encryption automatically if a server supports it,
     * even if `SMTPSecure` is not set to 'tls'.
     * Be aware that in PHP >= 5.6 this requires that the server's certificates are valid.
Scott committed
258
     * @var boolean
Scott committed
259 260 261
     */
    public $SMTPAutoTLS = true;

Scott committed
262 263 264
    /**
     * Whether to use SMTP authentication.
     * Uses the Username and Password properties.
Scott committed
265
     * @var boolean
Scott committed
266 267 268 269 270
     * @see PHPMailer::$Username
     * @see PHPMailer::$Password
     */
    public $SMTPAuth = false;

Scott committed
271 272
    /**
     * Options array passed to stream_context_create when connecting via SMTP.
Scott committed
273
     * @var array
Scott committed
274 275 276
     */
    public $SMTPOptions = array();

Scott committed
277 278
    /**
     * SMTP username.
Scott committed
279
     * @var string
Scott committed
280 281 282 283 284
     */
    public $Username = '';

    /**
     * SMTP password.
Scott committed
285
     * @var string
Scott committed
286 287 288 289 290
     */
    public $Password = '';

    /**
     * SMTP auth type.
ProThoughts committed
291
     * Options are CRAM-MD5, LOGIN, PLAIN, NTLM, XOAUTH2, attempted in that order if not specified
Scott committed
292
     * @var string
Scott committed
293 294 295 296 297 298
     */
    public $AuthType = '';

    /**
     * SMTP realm.
     * Used for NTLM auth
Scott committed
299
     * @var string
Scott committed
300 301 302 303 304 305
     */
    public $Realm = '';

    /**
     * SMTP workstation.
     * Used for NTLM auth
Scott committed
306
     * @var string
Scott committed
307 308 309 310 311
     */
    public $Workstation = '';

    /**
     * The SMTP server timeout in seconds.
Scott committed
312
     * Default of 5 minutes (300sec) is from RFC2821 section 4.5.3.2
Scott committed
313
     * @var integer
Scott committed
314
     */
Scott committed
315
    public $Timeout = 300;
Scott committed
316 317 318

    /**
     * SMTP class debug output mode.
Scott committed
319 320 321 322 323 324 325
     * Debug output level.
     * Options:
     * * `0` No output
     * * `1` Commands
     * * `2` Data and commands
     * * `3` As 2 plus connection status
     * * `4` Low-level data output
Scott committed
326
     * @var integer
Scott committed
327 328 329 330 331
     * @see SMTP::$do_debug
     */
    public $SMTPDebug = 0;

    /**
Scott committed
332 333 334 335 336 337 338 339 340 341
     * How to handle debug output.
     * Options:
     * * `echo` Output plain-text as-is, appropriate for CLI
     * * `html` Output escaped, line breaks converted to `<br>`, appropriate for browser output
     * * `error_log` Output to error log as configured in php.ini
     *
     * Alternatively, you can provide a callable expecting two params: a message string and the debug level:
     * <code>
     * $mail->Debugoutput = function($str, $level) {echo "debug level $level; message: $str";};
     * </code>
Scott committed
342
     * @var string|callable
Scott committed
343 344
     * @see SMTP::$Debugoutput
     */
Scott committed
345
    public $Debugoutput = 'echo';
Scott committed
346 347 348 349 350

    /**
     * Whether to keep SMTP connection open after each message.
     * If this is set to true then to close the connection
     * requires an explicit call to smtpClose().
Scott committed
351
     * @var boolean
Scott committed
352 353 354 355 356 357
     */
    public $SMTPKeepAlive = false;

    /**
     * Whether to split multiple to addresses into multiple messages
     * or send them all in one message.
ProThoughts committed
358
     * Only supported in `mail` and `sendmail` transports, not in SMTP.
Scott committed
359
     * @var boolean
Scott committed
360 361 362 363 364
     */
    public $SingleTo = false;

    /**
     * Storage for addresses when SingleTo is enabled.
Scott committed
365
     * @var array
Scott committed
366
     * @TODO This should really not be public
Scott committed
367 368 369 370 371 372
     */
    public $SingleToArray = array();

    /**
     * Whether to generate VERP addresses on send.
     * Only applicable when sending via SMTP.
Scott committed
373
     * @link https://en.wikipedia.org/wiki/Variable_envelope_return_path
Scott committed
374
     * @link http://www.postfix.org/VERP_README.html Postfix VERP info
Scott committed
375
     * @var boolean
Scott committed
376 377 378 379 380
     */
    public $do_verp = false;

    /**
     * Whether to allow sending messages with an empty body.
Scott committed
381
     * @var boolean
Scott committed
382 383 384 385 386 387 388
     */
    public $AllowEmpty = false;

    /**
     * The default line ending.
     * @note The default remains "\n". We force CRLF where we know
     *        it must be used via self::CRLF.
Scott committed
389
     * @var string
Scott committed
390 391 392 393 394
     */
    public $LE = "\n";

    /**
     * DKIM selector.
Scott committed
395
     * @var string
Scott committed
396 397 398 399 400
     */
    public $DKIM_selector = '';

    /**
     * DKIM Identity.
ProThoughts committed
401
     * Usually the email address used as the source of the email.
Scott committed
402
     * @var string
Scott committed
403 404 405 406 407 408
     */
    public $DKIM_identity = '';

    /**
     * DKIM passphrase.
     * Used if your key is encrypted.
Scott committed
409
     * @var string
Scott committed
410 411 412 413 414 415
     */
    public $DKIM_passphrase = '';

    /**
     * DKIM signing domain name.
     * @example 'example.com'
Scott committed
416
     * @var string
Scott committed
417 418 419 420 421
     */
    public $DKIM_domain = '';

    /**
     * DKIM private key file path.
Scott committed
422
     * @var string
Scott committed
423 424 425
     */
    public $DKIM_private = '';

ProThoughts committed
426 427 428 429 430 431 432
    /**
     * DKIM private key string.
     * If set, takes precedence over `$DKIM_private`.
     * @var string
     */
    public $DKIM_private_string = '';

Scott committed
433 434 435 436 437 438 439 440 441
    /**
     * Callback Action function name.
     *
     * The function that handles the result of the send email action.
     * It is called out by send() for each email sent.
     *
     * Value can be any php callable: http://www.php.net/is_callable
     *
     * Parameters:
Scott committed
442
     *   boolean $result        result of the send action
443 444 445
     *   array   $to            email addresses of the recipients
     *   array   $cc            cc email addresses
     *   array   $bcc           bcc email addresses
Scott committed
446 447 448
     *   string  $subject       the subject
     *   string  $body          the email body
     *   string  $from          email address of sender
Scott committed
449
     * @var string
Scott committed
450 451 452 453
     */
    public $action_function = '';

    /**
Scott committed
454 455
     * What to put in the X-Mailer header.
     * Options: An empty string for PHPMailer default, whitespace for none, or a string to use
Scott committed
456
     * @var string
Scott committed
457 458
     */
    public $XMailer = '';
Scott committed
459

ProThoughts committed
460 461 462 463 464 465 466 467 468
    /**
     * Which validator to use by default when validating email addresses.
     * May be a callable to inject your own validator, but there are several built-in validators.
     * @see PHPMailer::validateAddress()
     * @var string|callable
     * @static
     */
    public static $validator = 'auto';

Scott committed
469 470
    /**
     * An instance of the SMTP sender class.
Scott committed
471
     * @var SMTP
Scott committed
472 473 474 475 476
     * @access protected
     */
    protected $smtp = null;

    /**
Scott committed
477 478
     * The array of 'to' names and addresses.
     * @var array
Scott committed
479 480 481 482 483
     * @access protected
     */
    protected $to = array();

    /**
Scott committed
484 485
     * The array of 'cc' names and addresses.
     * @var array
Scott committed
486 487 488 489 490
     * @access protected
     */
    protected $cc = array();

    /**
Scott committed
491 492
     * The array of 'bcc' names and addresses.
     * @var array
Scott committed
493 494 495 496 497 498
     * @access protected
     */
    protected $bcc = array();

    /**
     * The array of reply-to names and addresses.
Scott committed
499
     * @var array
Scott committed
500 501 502 503 504 505
     * @access protected
     */
    protected $ReplyTo = array();

    /**
     * An array of all kinds of addresses.
Scott committed
506
     * Includes all of $to, $cc, $bcc
Scott committed
507
     * @var array
Scott committed
508
     * @access protected
Scott committed
509
     * @see PHPMailer::$to @see PHPMailer::$cc @see PHPMailer::$bcc
Scott committed
510 511 512
     */
    protected $all_recipients = array();

Scott committed
513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534
    /**
     * An array of names and addresses queued for validation.
     * In send(), valid and non duplicate entries are moved to $all_recipients
     * and one of $to, $cc, or $bcc.
     * This array is used only for addresses with IDN.
     * @var array
     * @access protected
     * @see PHPMailer::$to @see PHPMailer::$cc @see PHPMailer::$bcc
     * @see PHPMailer::$all_recipients
     */
    protected $RecipientsQueue = array();

    /**
     * An array of reply-to names and addresses queued for validation.
     * In send(), valid and non duplicate entries are moved to $ReplyTo.
     * This array is used only for addresses with IDN.
     * @var array
     * @access protected
     * @see PHPMailer::$ReplyTo
     */
    protected $ReplyToQueue = array();

Scott committed
535 536
    /**
     * The array of attachments.
Scott committed
537
     * @var array
Scott committed
538 539 540 541 542 543
     * @access protected
     */
    protected $attachment = array();

    /**
     * The array of custom headers.
Scott committed
544
     * @var array
Scott committed
545 546 547 548 549 550
     * @access protected
     */
    protected $CustomHeader = array();

    /**
     * The most recent Message-ID (including angular brackets).
Scott committed
551
     * @var string
Scott committed
552 553 554 555 556 557
     * @access protected
     */
    protected $lastMessageID = '';

    /**
     * The message's MIME type.
Scott committed
558
     * @var string
Scott committed
559 560 561 562 563 564
     * @access protected
     */
    protected $message_type = '';

    /**
     * The array of MIME boundary strings.
Scott committed
565
     * @var array
Scott committed
566 567 568 569 570 571
     * @access protected
     */
    protected $boundary = array();

    /**
     * The array of available languages.
Scott committed
572
     * @var array
Scott committed
573 574 575 576 577 578
     * @access protected
     */
    protected $language = array();

    /**
     * The number of errors encountered.
Scott committed
579
     * @var integer
Scott committed
580 581 582 583 584 585
     * @access protected
     */
    protected $error_count = 0;

    /**
     * The S/MIME certificate file path.
Scott committed
586
     * @var string
Scott committed
587 588 589 590 591 592
     * @access protected
     */
    protected $sign_cert_file = '';

    /**
     * The S/MIME key file path.
Scott committed
593
     * @var string
Scott committed
594 595 596 597
     * @access protected
     */
    protected $sign_key_file = '';

Scott committed
598 599
    /**
     * The optional S/MIME extra certificates ("CA Chain") file path.
Scott committed
600
     * @var string
Scott committed
601 602 603 604
     * @access protected
     */
    protected $sign_extracerts_file = '';

Scott committed
605 606 607
    /**
     * The S/MIME password for the key.
     * Used only if the key is encrypted.
Scott committed
608
     * @var string
Scott committed
609 610 611 612 613 614
     * @access protected
     */
    protected $sign_key_pass = '';

    /**
     * Whether to throw exceptions for errors.
Scott committed
615
     * @var boolean
Scott committed
616 617 618 619 620
     * @access protected
     */
    protected $exceptions = false;

    /**
Scott committed
621
     * Unique ID used for message ID and boundaries.
Scott committed
622
     * @var string
Scott committed
623 624 625 626 627 628
     * @access protected
     */
    protected $uniqueid = '';

    /**
     * Error severity: message only, continue processing.
Scott committed
629 630 631 632
     */
    const STOP_MESSAGE = 0;

    /**
Scott committed
633
     * Error severity: message, likely ok to continue processing.
Scott committed
634 635 636 637
     */
    const STOP_CONTINUE = 1;

    /**
Scott committed
638
     * Error severity: message, plus full stop, critical error reached.
Scott committed
639 640 641 642
     */
    const STOP_CRITICAL = 2;

    /**
Scott committed
643
     * SMTP RFC standard line ending.
Scott committed
644 645 646 647
     */
    const CRLF = "\r\n";

    /**
Scott committed
648
     * The maximum line length allowed by RFC 2822 section 2.1.1
Scott committed
649
     * @var integer
Scott committed
650 651 652 653 654 655
     */
    const MAX_LINE_LENGTH = 998;

    /**
     * Constructor.
     * @param boolean $exceptions Should we throw external exceptions?
Scott committed
656
     */
ProThoughts committed
657
    public function __construct($exceptions = null)
Scott committed
658
    {
ProThoughts committed
659 660 661
        if ($exceptions !== null) {
            $this->exceptions = (boolean)$exceptions;
        }
Scott committed
662 663
        //Pick an appropriate debug output format automatically
        $this->Debugoutput = (strpos(PHP_SAPI, 'cli') !== false ? 'echo' : 'html');
Scott committed
664 665 666 667 668 669 670
    }

    /**
     * Destructor.
     */
    public function __destruct()
    {
Scott committed
671
        //Close any open SMTP connection nicely
ProThoughts committed
672
        $this->smtpClose();
Scott committed
673 674 675 676 677 678 679 680 681 682 683 684 685
    }

    /**
     * Call mail() in a safe_mode-aware fashion.
     * Also, unless sendmail_path points to sendmail (or something that
     * claims to be sendmail), don't pass params (not a perfect fix,
     * but it will do)
     * @param string $to To
     * @param string $subject Subject
     * @param string $body Message Body
     * @param string $header Additional Header(s)
     * @param string $params Params
     * @access private
Scott committed
686
     * @return boolean
Scott committed
687 688 689 690 691 692 693 694 695
     */
    private function mailPassthru($to, $subject, $body, $header, $params)
    {
        //Check overloading of mail function to avoid double-encoding
        if (ini_get('mbstring.func_overload') & 1) {
            $subject = $this->secureHeader($subject);
        } else {
            $subject = $this->encodeHeader($this->secureHeader($subject));
        }
ProThoughts committed
696 697 698 699

        //Can't use additional_parameters in safe_mode, calling mail() with null params breaks
        //@link http://php.net/manual/en/function.mail.php
        if (ini_get('safe_mode') or !$this->UseSendmailOptions or is_null($params)) {
Scott committed
700
            $result = @mail($to, $subject, $body, $header);
Scott committed
701
        } else {
Scott committed
702
            $result = @mail($to, $subject, $body, $header, $params);
Scott committed
703
        }
Scott committed
704
        return $result;
Scott committed
705 706 707
    }
    /**
     * Output debugging info via user-defined method.
Scott committed
708
     * Only generates output if SMTP debug output is enabled (@see SMTP::$do_debug).
Scott committed
709 710 711 712 713 714
     * @see PHPMailer::$Debugoutput
     * @see PHPMailer::$SMTPDebug
     * @param string $str
     */
    protected function edebug($str)
    {
Scott committed
715 716 717 718 719 720
        if ($this->SMTPDebug <= 0) {
            return;
        }
        //Avoid clash with built-in function names
        if (!in_array($this->Debugoutput, array('error_log', 'html', 'echo')) and is_callable($this->Debugoutput)) {
            call_user_func($this->Debugoutput, $str, $this->SMTPDebug);
Scott committed
721 722 723 724
            return;
        }
        switch ($this->Debugoutput) {
            case 'error_log':
Scott committed
725
                //Don't output, just log
Scott committed
726 727 728
                error_log($str);
                break;
            case 'html':
Scott committed
729 730 731 732 733 734 735
                //Cleans up output a bit for a better looking, HTML-safe output
                echo htmlentities(
                    preg_replace('/[\r\n]+/', '', $str),
                    ENT_QUOTES,
                    'UTF-8'
                )
                . "<br>\n";
Scott committed
736 737 738
                break;
            case 'echo':
            default:
Scott committed
739
                //Normalize line breaks
ProThoughts committed
740
                $str = preg_replace('/\r\n?/ms', "\n", $str);
Scott committed
741 742 743 744 745
                echo gmdate('Y-m-d H:i:s') . "\t" . str_replace(
                    "\n",
                    "\n                   \t                  ",
                    trim($str)
                ) . "\n";
Scott committed
746 747 748 749 750
        }
    }

    /**
     * Sets message type to HTML or plain.
Scott committed
751
     * @param boolean $isHtml True for HTML mode.
Scott committed
752 753
     * @return void
     */
Scott committed
754
    public function isHTML($isHtml = true)
Scott committed
755
    {
Scott committed
756
        if ($isHtml) {
Scott committed
757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786
            $this->ContentType = 'text/html';
        } else {
            $this->ContentType = 'text/plain';
        }
    }

    /**
     * Send messages using SMTP.
     * @return void
     */
    public function isSMTP()
    {
        $this->Mailer = 'smtp';
    }

    /**
     * Send messages using PHP's mail() function.
     * @return void
     */
    public function isMail()
    {
        $this->Mailer = 'mail';
    }

    /**
     * Send messages using $Sendmail.
     * @return void
     */
    public function isSendmail()
    {
Scott committed
787 788 789
        $ini_sendmail_path = ini_get('sendmail_path');

        if (!stristr($ini_sendmail_path, 'sendmail')) {
Scott committed
790
            $this->Sendmail = '/usr/sbin/sendmail';
Scott committed
791 792
        } else {
            $this->Sendmail = $ini_sendmail_path;
Scott committed
793 794 795 796 797 798 799 800 801 802
        }
        $this->Mailer = 'sendmail';
    }

    /**
     * Send messages using qmail.
     * @return void
     */
    public function isQmail()
    {
Scott committed
803 804 805
        $ini_sendmail_path = ini_get('sendmail_path');

        if (!stristr($ini_sendmail_path, 'qmail')) {
Scott committed
806
            $this->Sendmail = '/var/qmail/bin/qmail-inject';
Scott committed
807 808
        } else {
            $this->Sendmail = $ini_sendmail_path;
Scott committed
809 810 811 812 813 814
        }
        $this->Mailer = 'qmail';
    }

    /**
     * Add a "To" address.
Scott committed
815
     * @param string $address The email address to send to
Scott committed
816
     * @param string $name
Scott committed
817
     * @return boolean true on success, false if address already used or invalid in some way
Scott committed
818 819 820
     */
    public function addAddress($address, $name = '')
    {
Scott committed
821
        return $this->addOrEnqueueAnAddress('to', $address, $name);
Scott committed
822 823 824 825 826
    }

    /**
     * Add a "CC" address.
     * @note: This function works with the SMTP mailer on win32, not with the "mail" mailer.
Scott committed
827
     * @param string $address The email address to send to
Scott committed
828
     * @param string $name
Scott committed
829
     * @return boolean true on success, false if address already used or invalid in some way
Scott committed
830 831 832
     */
    public function addCC($address, $name = '')
    {
Scott committed
833
        return $this->addOrEnqueueAnAddress('cc', $address, $name);
Scott committed
834 835 836 837 838
    }

    /**
     * Add a "BCC" address.
     * @note: This function works with the SMTP mailer on win32, not with the "mail" mailer.
Scott committed
839
     * @param string $address The email address to send to
Scott committed
840
     * @param string $name
Scott committed
841
     * @return boolean true on success, false if address already used or invalid in some way
Scott committed
842 843 844
     */
    public function addBCC($address, $name = '')
    {
Scott committed
845
        return $this->addOrEnqueueAnAddress('bcc', $address, $name);
Scott committed
846 847 848
    }

    /**
Scott committed
849 850
     * Add a "Reply-To" address.
     * @param string $address The email address to reply to
Scott committed
851
     * @param string $name
Scott committed
852
     * @return boolean true on success, false if address already used or invalid in some way
Scott committed
853 854 855
     */
    public function addReplyTo($address, $name = '')
    {
Scott committed
856
        return $this->addOrEnqueueAnAddress('Reply-To', $address, $name);
Scott committed
857 858 859
    }

    /**
Scott committed
860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876
     * Add an address to one of the recipient arrays or to the ReplyTo array. Because PHPMailer
     * can't validate addresses with an IDN without knowing the PHPMailer::$CharSet (that can still
     * be modified after calling this function), addition of such addresses is delayed until send().
     * Addresses that have been added already return false, but do not throw exceptions.
     * @param string $kind One of 'to', 'cc', 'bcc', or 'ReplyTo'
     * @param string $address The email address to send, resp. to reply to
     * @param string $name
     * @throws phpmailerException
     * @return boolean true on success, false if address already used or invalid in some way
     * @access protected
     */
    protected function addOrEnqueueAnAddress($kind, $address, $name)
    {
        $address = trim($address);
        $name = trim(preg_replace('/[\r\n]+/', '', $name)); //Strip breaks and trim
        if (($pos = strrpos($address, '@')) === false) {
            // At-sign is misssing.
ProThoughts committed
877
            $error_message = $this->lang('invalid_address') . " (addAnAddress $kind): $address";
Scott committed
878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909
            $this->setError($error_message);
            $this->edebug($error_message);
            if ($this->exceptions) {
                throw new phpmailerException($error_message);
            }
            return false;
        }
        $params = array($kind, $address, $name);
        // Enqueue addresses with IDN until we know the PHPMailer::$CharSet.
        if ($this->has8bitChars(substr($address, ++$pos)) and $this->idnSupported()) {
            if ($kind != 'Reply-To') {
                if (!array_key_exists($address, $this->RecipientsQueue)) {
                    $this->RecipientsQueue[$address] = $params;
                    return true;
                }
            } else {
                if (!array_key_exists($address, $this->ReplyToQueue)) {
                    $this->ReplyToQueue[$address] = $params;
                    return true;
                }
            }
            return false;
        }
        // Immediately add standard addresses without IDN.
        return call_user_func_array(array($this, 'addAnAddress'), $params);
    }

    /**
     * Add an address to one of the recipient arrays or to the ReplyTo array.
     * Addresses that have been added already return false, but do not throw exceptions.
     * @param string $kind One of 'to', 'cc', 'bcc', or 'ReplyTo'
     * @param string $address The email address to send, resp. to reply to
Scott committed
910 911
     * @param string $name
     * @throws phpmailerException
Scott committed
912
     * @return boolean true on success, false if address already used or invalid in some way
Scott committed
913 914 915 916
     * @access protected
     */
    protected function addAnAddress($kind, $address, $name = '')
    {
Scott committed
917 918 919 920
        if (!in_array($kind, array('to', 'cc', 'bcc', 'Reply-To'))) {
            $error_message = $this->lang('Invalid recipient kind: ') . $kind;
            $this->setError($error_message);
            $this->edebug($error_message);
Scott committed
921
            if ($this->exceptions) {
Scott committed
922
                throw new phpmailerException($error_message);
Scott committed
923 924 925 926
            }
            return false;
        }
        if (!$this->validateAddress($address)) {
ProThoughts committed
927
            $error_message = $this->lang('invalid_address') . " (addAnAddress $kind): $address";
Scott committed
928 929
            $this->setError($error_message);
            $this->edebug($error_message);
Scott committed
930
            if ($this->exceptions) {
Scott committed
931
                throw new phpmailerException($error_message);
Scott committed
932 933 934 935
            }
            return false;
        }
        if ($kind != 'Reply-To') {
Scott committed
936
            if (!array_key_exists(strtolower($address), $this->all_recipients)) {
Scott committed
937 938 939 940 941 942 943 944 945 946 947 948 949
                array_push($this->$kind, array($address, $name));
                $this->all_recipients[strtolower($address)] = true;
                return true;
            }
        } else {
            if (!array_key_exists(strtolower($address), $this->ReplyTo)) {
                $this->ReplyTo[strtolower($address)] = array($address, $name);
                return true;
            }
        }
        return false;
    }

Scott committed
950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004
    /**
     * Parse and validate a string containing one or more RFC822-style comma-separated email addresses
     * of the form "display name <address>" into an array of name/address pairs.
     * Uses the imap_rfc822_parse_adrlist function if the IMAP extension is available.
     * Note that quotes in the name part are removed.
     * @param string $addrstr The address list string
     * @param bool $useimap Whether to use the IMAP extension to parse the list
     * @return array
     * @link http://www.andrew.cmu.edu/user/agreen1/testing/mrbs/web/Mail/RFC822.php A more careful implementation
     */
    public function parseAddresses($addrstr, $useimap = true)
    {
        $addresses = array();
        if ($useimap and function_exists('imap_rfc822_parse_adrlist')) {
            //Use this built-in parser if it's available
            $list = imap_rfc822_parse_adrlist($addrstr, '');
            foreach ($list as $address) {
                if ($address->host != '.SYNTAX-ERROR.') {
                    if ($this->validateAddress($address->mailbox . '@' . $address->host)) {
                        $addresses[] = array(
                            'name' => (property_exists($address, 'personal') ? $address->personal : ''),
                            'address' => $address->mailbox . '@' . $address->host
                        );
                    }
                }
            }
        } else {
            //Use this simpler parser
            $list = explode(',', $addrstr);
            foreach ($list as $address) {
                $address = trim($address);
                //Is there a separate name part?
                if (strpos($address, '<') === false) {
                    //No separate name, just use the whole thing
                    if ($this->validateAddress($address)) {
                        $addresses[] = array(
                            'name' => '',
                            'address' => $address
                        );
                    }
                } else {
                    list($name, $email) = explode('<', $address);
                    $email = trim(str_replace('>', '', $email));
                    if ($this->validateAddress($email)) {
                        $addresses[] = array(
                            'name' => trim(str_replace(array('"', "'"), '', $name)),
                            'address' => $email
                        );
                    }
                }
            }
        }
        return $addresses;
    }

Scott committed
1005 1006 1007 1008
    /**
     * Set the From and FromName properties.
     * @param string $address
     * @param string $name
Scott committed
1009
     * @param boolean $auto Whether to also set the Sender address, defaults to true
Scott committed
1010
     * @throws phpmailerException
Scott committed
1011
     * @return boolean
Scott committed
1012 1013 1014 1015 1016
     */
    public function setFrom($address, $name = '', $auto = true)
    {
        $address = trim($address);
        $name = trim(preg_replace('/[\r\n]+/', '', $name)); //Strip breaks and trim
Scott committed
1017 1018 1019 1020
        // Don't validate now addresses with IDN. Will be done in send().
        if (($pos = strrpos($address, '@')) === false or
            (!$this->has8bitChars(substr($address, ++$pos)) or !$this->idnSupported()) and
            !$this->validateAddress($address)) {
ProThoughts committed
1021
            $error_message = $this->lang('invalid_address') . " (setFrom) $address";
Scott committed
1022 1023
            $this->setError($error_message);
            $this->edebug($error_message);
Scott committed
1024
            if ($this->exceptions) {
Scott committed
1025
                throw new phpmailerException($error_message);
Scott committed
1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053
            }
            return false;
        }
        $this->From = $address;
        $this->FromName = $name;
        if ($auto) {
            if (empty($this->Sender)) {
                $this->Sender = $address;
            }
        }
        return true;
    }

    /**
     * Return the Message-ID header of the last email.
     * Technically this is the value from the last time the headers were created,
     * but it's also the message ID of the last sent message except in
     * pathological cases.
     * @return string
     */
    public function getLastMessageID()
    {
        return $this->lastMessageID;
    }

    /**
     * Check that a string looks like an email address.
     * @param string $address The email address to check
ProThoughts committed
1054
     * @param string|callable $patternselect A selector for the validation pattern to use :
Scott committed
1055
     * * `auto` Pick best pattern automatically;
Scott committed
1056 1057
     * * `pcre8` Use the squiloople.com pattern, requires PCRE > 8.0, PHP >= 5.3.2, 5.2.14;
     * * `pcre` Use old PCRE implementation;
Scott committed
1058
     * * `php` Use PHP built-in FILTER_VALIDATE_EMAIL;
Scott committed
1059 1060
     * * `html5` Use the pattern given by the HTML5 spec for 'email' type form input elements.
     * * `noregex` Don't use a regex: super fast, really dumb.
ProThoughts committed
1061 1062 1063 1064 1065
     * Alternatively you may pass in a callable to inject your own validator, for example:
     * PHPMailer::validateAddress('user@example.com', function($address) {
     *     return (strpos($address, '@') !== false);
     * });
     * You can also set the PHPMailer::$validator static to a callable, allowing built-in methods to use your validator.
Scott committed
1066
     * @return boolean
Scott committed
1067 1068 1069
     * @static
     * @access public
     */
ProThoughts committed
1070
    public static function validateAddress($address, $patternselect = null)
Scott committed
1071
    {
ProThoughts committed
1072 1073 1074 1075 1076 1077
        if (is_null($patternselect)) {
            $patternselect = self::$validator;
        }
        if (is_callable($patternselect)) {
            return call_user_func($patternselect, $address);
        }
Scott committed
1078 1079 1080 1081
        //Reject line breaks in addresses; it's valid RFC5322, but not RFC5321
        if (strpos($address, "\n") !== false or strpos($address, "\r") !== false) {
            return false;
        }
Scott committed
1082 1083 1084 1085 1086 1087
        if (!$patternselect or $patternselect == 'auto') {
            //Check this constant first so it works when extension_loaded() is disabled by safe mode
            //Constant was added in PHP 5.2.4
            if (defined('PCRE_VERSION')) {
                //This pattern can get stuck in a recursive loop in PCRE <= 8.0.2
                if (version_compare(PCRE_VERSION, '8.0.3') >= 0) {
Scott committed
1088 1089 1090 1091
                    $patternselect = 'pcre8';
                } else {
                    $patternselect = 'pcre';
                }
Scott committed
1092 1093 1094
            } elseif (function_exists('extension_loaded') and extension_loaded('pcre')) {
                //Fall back to older PCRE
                $patternselect = 'pcre';
Scott committed
1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106
            } else {
                //Filter_var appeared in PHP 5.2.0 and does not require the PCRE extension
                if (version_compare(PHP_VERSION, '5.2.0') >= 0) {
                    $patternselect = 'php';
                } else {
                    $patternselect = 'noregex';
                }
            }
        }
        switch ($patternselect) {
            case 'pcre8':
                /**
Scott committed
1107
                 * Uses the same RFC5322 regex on which FILTER_VALIDATE_EMAIL is based, but allows dotless domains.
Scott committed
1108 1109 1110 1111
                 * @link http://squiloople.com/2009/12/20/email-address-validation/
                 * @copyright 2009-2010 Michael Rushton
                 * Feel free to use and redistribute this code. But please keep this copyright notice.
                 */
Scott committed
1112
                return (boolean)preg_match(
Scott committed
1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125
                    '/^(?!(?>(?1)"?(?>\\\[ -~]|[^"])"?(?1)){255,})(?!(?>(?1)"?(?>\\\[ -~]|[^"])"?(?1)){65,}@)' .
                    '((?>(?>(?>((?>(?>(?>\x0D\x0A)?[\t ])+|(?>[\t ]*\x0D\x0A)?[\t ]+)?)(\((?>(?2)' .
                    '(?>[\x01-\x08\x0B\x0C\x0E-\'*-\[\]-\x7F]|\\\[\x00-\x7F]|(?3)))*(?2)\)))+(?2))|(?2))?)' .
                    '([!#-\'*+\/-9=?^-~-]+|"(?>(?2)(?>[\x01-\x08\x0B\x0C\x0E-!#-\[\]-\x7F]|\\\[\x00-\x7F]))*' .
                    '(?2)")(?>(?1)\.(?1)(?4))*(?1)@(?!(?1)[a-z0-9-]{64,})(?1)(?>([a-z0-9](?>[a-z0-9-]*[a-z0-9])?)' .
                    '(?>(?1)\.(?!(?1)[a-z0-9-]{64,})(?1)(?5)){0,126}|\[(?:(?>IPv6:(?>([a-f0-9]{1,4})(?>:(?6)){7}' .
                    '|(?!(?:.*[a-f0-9][:\]]){8,})((?6)(?>:(?6)){0,6})?::(?7)?))|(?>(?>IPv6:(?>(?6)(?>:(?6)){5}:' .
                    '|(?!(?:.*[a-f0-9]:){6,})(?8)?::(?>((?6)(?>:(?6)){0,4}):)?))?(25[0-5]|2[0-4][0-9]|1[0-9]{2}' .
                    '|[1-9]?[0-9])(?>\.(?9)){3}))\])(?1)$/isD',
                    $address
                );
            case 'pcre':
                //An older regex that doesn't need a recent PCRE
Scott committed
1126
                return (boolean)preg_match(
Scott committed
1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138
                    '/^(?!(?>"?(?>\\\[ -~]|[^"])"?){255,})(?!(?>"?(?>\\\[ -~]|[^"])"?){65,}@)(?>' .
                    '[!#-\'*+\/-9=?^-~-]+|"(?>(?>[\x01-\x08\x0B\x0C\x0E-!#-\[\]-\x7F]|\\\[\x00-\xFF]))*")' .
                    '(?>\.(?>[!#-\'*+\/-9=?^-~-]+|"(?>(?>[\x01-\x08\x0B\x0C\x0E-!#-\[\]-\x7F]|\\\[\x00-\xFF]))*"))*' .
                    '@(?>(?![a-z0-9-]{64,})(?>[a-z0-9](?>[a-z0-9-]*[a-z0-9])?)(?>\.(?![a-z0-9-]{64,})' .
                    '(?>[a-z0-9](?>[a-z0-9-]*[a-z0-9])?)){0,126}|\[(?:(?>IPv6:(?>(?>[a-f0-9]{1,4})(?>:' .
                    '[a-f0-9]{1,4}){7}|(?!(?:.*[a-f0-9][:\]]){8,})(?>[a-f0-9]{1,4}(?>:[a-f0-9]{1,4}){0,6})?' .
                    '::(?>[a-f0-9]{1,4}(?>:[a-f0-9]{1,4}){0,6})?))|(?>(?>IPv6:(?>[a-f0-9]{1,4}(?>:' .
                    '[a-f0-9]{1,4}){5}:|(?!(?:.*[a-f0-9]:){6,})(?>[a-f0-9]{1,4}(?>:[a-f0-9]{1,4}){0,4})?' .
                    '::(?>(?:[a-f0-9]{1,4}(?>:[a-f0-9]{1,4}){0,4}):)?))?(?>25[0-5]|2[0-4][0-9]|1[0-9]{2}' .
                    '|[1-9]?[0-9])(?>\.(?>25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])){3}))\])$/isD',
                    $address
                );
Scott committed
1139 1140 1141 1142 1143 1144 1145 1146 1147 1148
            case 'html5':
                /**
                 * This is the pattern used in the HTML5 spec for validation of 'email' type form input elements.
                 * @link http://www.whatwg.org/specs/web-apps/current-work/#e-mail-state-(type=email)
                 */
                return (boolean)preg_match(
                    '/^[a-zA-Z0-9.!#$%&\'*+\/=?^_`{|}~-]+@[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}' .
                    '[a-zA-Z0-9])?(?:\.[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*$/sD',
                    $address
                );
Scott committed
1149 1150 1151 1152 1153 1154
            case 'noregex':
                //No PCRE! Do something _very_ approximate!
                //Check the address is 3 chars or longer and contains an @ that's not the first or last char
                return (strlen($address) >= 3
                    and strpos($address, '@') >= 1
                    and strpos($address, '@') != strlen($address) - 1);
Scott committed
1155 1156 1157
            case 'php':
            default:
                return (boolean)filter_var($address, FILTER_VALIDATE_EMAIL);
Scott committed
1158 1159 1160
        }
    }

Scott committed
1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202
    /**
     * Tells whether IDNs (Internationalized Domain Names) are supported or not. This requires the
     * "intl" and "mbstring" PHP extensions.
     * @return bool "true" if required functions for IDN support are present
     */
    public function idnSupported()
    {
        // @TODO: Write our own "idn_to_ascii" function for PHP <= 5.2.
        return function_exists('idn_to_ascii') and function_exists('mb_convert_encoding');
    }

    /**
     * Converts IDN in given email address to its ASCII form, also known as punycode, if possible.
     * Important: Address must be passed in same encoding as currently set in PHPMailer::$CharSet.
     * This function silently returns unmodified address if:
     * - No conversion is necessary (i.e. domain name is not an IDN, or is already in ASCII form)
     * - Conversion to punycode is impossible (e.g. required PHP functions are not available)
     *   or fails for any reason (e.g. domain has characters not allowed in an IDN)
     * @see PHPMailer::$CharSet
     * @param string $address The email address to convert
     * @return string The encoded address in ASCII form
     */
    public function punyencodeAddress($address)
    {
        // Verify we have required functions, CharSet, and at-sign.
        if ($this->idnSupported() and
            !empty($this->CharSet) and
            ($pos = strrpos($address, '@')) !== false) {
            $domain = substr($address, ++$pos);
            // Verify CharSet string is a valid one, and domain properly encoded in this CharSet.
            if ($this->has8bitChars($domain) and @mb_check_encoding($domain, $this->CharSet)) {
                $domain = mb_convert_encoding($domain, 'UTF-8', $this->CharSet);
                if (($punycode = defined('INTL_IDNA_VARIANT_UTS46') ?
                    idn_to_ascii($domain, 0, INTL_IDNA_VARIANT_UTS46) :
                    idn_to_ascii($domain)) !== false) {
                    return substr($address, 0, $pos) . $punycode;
                }
            }
        }
        return $address;
    }

Scott committed
1203 1204 1205 1206
    /**
     * Create a message and send it.
     * Uses the sending method specified by $Mailer.
     * @throws phpmailerException
Scott committed
1207
     * @return boolean false on error - See the ErrorInfo property for details of the error.
Scott committed
1208 1209 1210 1211 1212 1213 1214 1215
     */
    public function send()
    {
        try {
            if (!$this->preSend()) {
                return false;
            }
            return $this->postSend();
Scott committed
1216
        } catch (phpmailerException $exc) {
Scott committed
1217
            $this->mailHeader = '';
Scott committed
1218
            $this->setError($exc->getMessage());
Scott committed
1219
            if ($this->exceptions) {
Scott committed
1220
                throw $exc;
Scott committed
1221 1222 1223 1224 1225 1226 1227 1228
            }
            return false;
        }
    }

    /**
     * Prepare a message for sending.
     * @throws phpmailerException
Scott committed
1229
     * @return boolean
Scott committed
1230 1231 1232 1233
     */
    public function preSend()
    {
        try {
Scott committed
1234
            $this->error_count = 0; // Reset errors
Scott committed
1235
            $this->mailHeader = '';
Scott committed
1236 1237 1238 1239 1240 1241

            // Dequeue recipient and Reply-To addresses with IDN
            foreach (array_merge($this->RecipientsQueue, $this->ReplyToQueue) as $params) {
                $params[1] = $this->punyencodeAddress($params[1]);
                call_user_func_array(array($this, 'addAnAddress'), $params);
            }
Scott committed
1242 1243 1244 1245
            if ((count($this->to) + count($this->cc) + count($this->bcc)) < 1) {
                throw new phpmailerException($this->lang('provide_address'), self::STOP_CRITICAL);
            }

Scott committed
1246 1247 1248 1249 1250 1251 1252 1253
            // Validate From, Sender, and ConfirmReadingTo addresses
            foreach (array('From', 'Sender', 'ConfirmReadingTo') as $address_kind) {
                $this->$address_kind = trim($this->$address_kind);
                if (empty($this->$address_kind)) {
                    continue;
                }
                $this->$address_kind = $this->punyencodeAddress($this->$address_kind);
                if (!$this->validateAddress($this->$address_kind)) {
ProThoughts committed
1254
                    $error_message = $this->lang('invalid_address') . ' (punyEncode) ' . $this->$address_kind;
Scott committed
1255 1256 1257 1258 1259 1260 1261 1262 1263
                    $this->setError($error_message);
                    $this->edebug($error_message);
                    if ($this->exceptions) {
                        throw new phpmailerException($error_message);
                    }
                    return false;
                }
            }

Scott committed
1264
            // Set whether the message is multipart/alternative
ProThoughts committed
1265
            if ($this->alternativeExists()) {
Scott committed
1266 1267 1268 1269 1270 1271 1272 1273 1274
                $this->ContentType = 'multipart/alternative';
            }

            $this->setMessageType();
            // Refuse to send an empty message unless we are specifically allowing it
            if (!$this->AllowEmpty and empty($this->Body)) {
                throw new phpmailerException($this->lang('empty_message'), self::STOP_CRITICAL);
            }

Scott committed
1275 1276
            // Create body before headers in case body makes changes to headers (e.g. altering transfer encoding)
            $this->MIMEHeader = '';
Scott committed
1277
            $this->MIMEBody = $this->createBody();
Scott committed
1278 1279 1280 1281
            // createBody may have added some headers, so retain them
            $tempheaders = $this->MIMEHeader;
            $this->MIMEHeader = $this->createHeader();
            $this->MIMEHeader .= $tempheaders;
Scott committed
1282 1283 1284 1285 1286

            // To capture the complete message when using mail(), create
            // an extra header list which createHeader() doesn't fold in
            if ($this->Mailer == 'mail') {
                if (count($this->to) > 0) {
Scott committed
1287
                    $this->mailHeader .= $this->addrAppend('To', $this->to);
Scott committed
1288
                } else {
Scott committed
1289
                    $this->mailHeader .= $this->headerLine('To', 'undisclosed-recipients:;');
Scott committed
1290 1291 1292 1293 1294 1295 1296 1297 1298 1299
                }
                $this->mailHeader .= $this->headerLine(
                    'Subject',
                    $this->encodeHeader($this->secureHeader(trim($this->Subject)))
                );
            }

            // Sign with DKIM if enabled
            if (!empty($this->DKIM_domain)
                && !empty($this->DKIM_selector)
ProThoughts committed
1300 1301 1302 1303
                && (!empty($this->DKIM_private_string)
                   || (!empty($this->DKIM_private) && file_exists($this->DKIM_private))
                )
            ) {
Scott committed
1304 1305 1306 1307 1308 1309 1310 1311 1312
                $header_dkim = $this->DKIM_Add(
                    $this->MIMEHeader . $this->mailHeader,
                    $this->encodeHeader($this->secureHeader($this->Subject)),
                    $this->MIMEBody
                );
                $this->MIMEHeader = rtrim($this->MIMEHeader, "\r\n ") . self::CRLF .
                    str_replace("\r\n", "\n", $header_dkim) . self::CRLF;
            }
            return true;
Scott committed
1313 1314
        } catch (phpmailerException $exc) {
            $this->setError($exc->getMessage());
Scott committed
1315
            if ($this->exceptions) {
Scott committed
1316
                throw $exc;
Scott committed
1317 1318 1319 1320 1321 1322 1323 1324 1325
            }
            return false;
        }
    }

    /**
     * Actually send a message.
     * Send the email via the selected mechanism
     * @throws phpmailerException
Scott committed
1326
     * @return boolean
Scott committed
1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340
     */
    public function postSend()
    {
        try {
            // Choose the mailer and send through it
            switch ($this->Mailer) {
                case 'sendmail':
                case 'qmail':
                    return $this->sendmailSend($this->MIMEHeader, $this->MIMEBody);
                case 'smtp':
                    return $this->smtpSend($this->MIMEHeader, $this->MIMEBody);
                case 'mail':
                    return $this->mailSend($this->MIMEHeader, $this->MIMEBody);
                default:
Scott committed
1341 1342
                    $sendMethod = $this->Mailer.'Send';
                    if (method_exists($this, $sendMethod)) {
Scott committed
1343 1344
                        return $this->$sendMethod($this->MIMEHeader, $this->MIMEBody);
                    }
Scott committed
1345 1346

                    return $this->mailSend($this->MIMEHeader, $this->MIMEBody);
Scott committed
1347
            }
Scott committed
1348 1349 1350
        } catch (phpmailerException $exc) {
            $this->setError($exc->getMessage());
            $this->edebug($exc->getMessage());
Scott committed
1351
            if ($this->exceptions) {
Scott committed
1352
                throw $exc;
Scott committed
1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364
            }
        }
        return false;
    }

    /**
     * Send mail using the $Sendmail program.
     * @param string $header The message headers
     * @param string $body The message body
     * @see PHPMailer::$Sendmail
     * @throws phpmailerException
     * @access protected
Scott committed
1365
     * @return boolean
Scott committed
1366 1367 1368
     */
    protected function sendmailSend($header, $body)
    {
ProThoughts committed
1369 1370
        // CVE-2016-10033, CVE-2016-10045: Don't pass -f if characters will be escaped.
        if (!empty($this->Sender) and self::isShellSafe($this->Sender)) {
Scott committed
1371
            if ($this->Mailer == 'qmail') {
ProThoughts committed
1372
                $sendmailFmt = '%s -f%s';
Scott committed
1373
            } else {
ProThoughts committed
1374
                $sendmailFmt = '%s -oi -f%s -t';
Scott committed
1375 1376 1377
            }
        } else {
            if ($this->Mailer == 'qmail') {
ProThoughts committed
1378
                $sendmailFmt = '%s';
Scott committed
1379
            } else {
ProThoughts committed
1380
                $sendmailFmt = '%s -oi -t';
Scott committed
1381 1382
            }
        }
ProThoughts committed
1383 1384 1385 1386

        // TODO: If possible, this should be changed to escapeshellarg.  Needs thorough testing.
        $sendmail = sprintf($sendmailFmt, escapeshellcmd($this->Sendmail), $this->Sender);

Scott committed
1387 1388
        if ($this->SingleTo) {
            foreach ($this->SingleToArray as $toAddr) {
Scott committed
1389 1390 1391
                if (!@$mail = popen($sendmail, 'w')) {
                    throw new phpmailerException($this->lang('execute') . $this->Sendmail, self::STOP_CRITICAL);
                }
Scott committed
1392
                fputs($mail, 'To: ' . $toAddr . "\n");
Scott committed
1393 1394 1395
                fputs($mail, $header);
                fputs($mail, $body);
                $result = pclose($mail);
Scott committed
1396 1397 1398 1399 1400 1401 1402 1403 1404
                $this->doCallback(
                    ($result == 0),
                    array($toAddr),
                    $this->cc,
                    $this->bcc,
                    $this->Subject,
                    $body,
                    $this->From
                );
Scott committed
1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415
                if ($result != 0) {
                    throw new phpmailerException($this->lang('execute') . $this->Sendmail, self::STOP_CRITICAL);
                }
            }
        } else {
            if (!@$mail = popen($sendmail, 'w')) {
                throw new phpmailerException($this->lang('execute') . $this->Sendmail, self::STOP_CRITICAL);
            }
            fputs($mail, $header);
            fputs($mail, $body);
            $result = pclose($mail);
Scott committed
1416 1417 1418 1419 1420 1421 1422 1423 1424
            $this->doCallback(
                ($result == 0),
                $this->to,
                $this->cc,
                $this->bcc,
                $this->Subject,
                $body,
                $this->From
            );
Scott committed
1425 1426 1427 1428 1429 1430 1431
            if ($result != 0) {
                throw new phpmailerException($this->lang('execute') . $this->Sendmail, self::STOP_CRITICAL);
            }
        }
        return true;
    }

ProThoughts committed
1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465
    /**
     * Fix CVE-2016-10033 and CVE-2016-10045 by disallowing potentially unsafe shell characters.
     *
     * Note that escapeshellarg and escapeshellcmd are inadequate for our purposes, especially on Windows.
     * @param string $string The string to be validated
     * @see https://github.com/PHPMailer/PHPMailer/issues/924 CVE-2016-10045 bug report
     * @access protected
     * @return boolean
     */
    protected static function isShellSafe($string)
    {
        // Future-proof
        if (escapeshellcmd($string) !== $string
            or !in_array(escapeshellarg($string), array("'$string'", "\"$string\""))
        ) {
            return false;
        }

        $length = strlen($string);

        for ($i = 0; $i < $length; $i++) {
            $c = $string[$i];

            // All other characters have a special meaning in at least one common shell, including = and +.
            // Full stop (.) has a special meaning in cmd.exe, but its impact should be negligible here.
            // Note that this does permit non-Latin alphanumeric characters based on the current locale.
            if (!ctype_alnum($c) && strpos('@_-.', $c) === false) {
                return false;
            }
        }

        return true;
    }

Scott committed
1466 1467 1468 1469 1470 1471 1472
    /**
     * Send mail using the PHP mail() function.
     * @param string $header The message headers
     * @param string $body The message body
     * @link http://www.php.net/manual/en/book.mail.php
     * @throws phpmailerException
     * @access protected
Scott committed
1473
     * @return boolean
Scott committed
1474 1475 1476 1477
     */
    protected function mailSend($header, $body)
    {
        $toArr = array();
Scott committed
1478 1479
        foreach ($this->to as $toaddr) {
            $toArr[] = $this->addrFormat($toaddr);
Scott committed
1480 1481 1482
        }
        $to = implode(', ', $toArr);

ProThoughts committed
1483 1484 1485 1486 1487 1488 1489
        $params = null;
        //This sets the SMTP envelope sender which gets turned into a return-path header by the receiver
        if (!empty($this->Sender) and $this->validateAddress($this->Sender)) {
            // CVE-2016-10033, CVE-2016-10045: Don't pass -f if characters will be escaped.
            if (self::isShellSafe($this->Sender)) {
                $params = sprintf('-f%s', $this->Sender);
            }
Scott committed
1490
        }
ProThoughts committed
1491
        if (!empty($this->Sender) and !ini_get('safe_mode') and $this->validateAddress($this->Sender)) {
Scott committed
1492 1493 1494
            $old_from = ini_get('sendmail_from');
            ini_set('sendmail_from', $this->Sender);
        }
Scott committed
1495
        $result = false;
ProThoughts committed
1496
        if ($this->SingleTo and count($toArr) > 1) {
Scott committed
1497 1498 1499
            foreach ($toArr as $toAddr) {
                $result = $this->mailPassthru($toAddr, $this->Subject, $body, $header, $params);
                $this->doCallback($result, array($toAddr), $this->cc, $this->bcc, $this->Subject, $body, $this->From);
Scott committed
1500 1501
            }
        } else {
Scott committed
1502 1503
            $result = $this->mailPassthru($to, $this->Subject, $body, $header, $params);
            $this->doCallback($result, $this->to, $this->cc, $this->bcc, $this->Subject, $body, $this->From);
Scott committed
1504 1505 1506 1507
        }
        if (isset($old_from)) {
            ini_set('sendmail_from', $old_from);
        }
Scott committed
1508
        if (!$result) {
Scott committed
1509 1510 1511 1512 1513 1514 1515 1516 1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536
            throw new phpmailerException($this->lang('instantiate'), self::STOP_CRITICAL);
        }
        return true;
    }

    /**
     * Get an instance to use for SMTP operations.
     * Override this function to load your own SMTP implementation
     * @return SMTP
     */
    public function getSMTPInstance()
    {
        if (!is_object($this->smtp)) {
            $this->smtp = new SMTP;
        }
        return $this->smtp;
    }

    /**
     * Send mail via SMTP.
     * Returns false if there is a bad MAIL FROM, RCPT, or DATA input.
     * Uses the PHPMailerSMTP class by default.
     * @see PHPMailer::getSMTPInstance() to use a different class.
     * @param string $header The message headers
     * @param string $body The message body
     * @throws phpmailerException
     * @uses SMTP
     * @access protected
Scott committed
1537
     * @return boolean
Scott committed
1538 1539 1540 1541
     */
    protected function smtpSend($header, $body)
    {
        $bad_rcpt = array();
Scott committed
1542
        if (!$this->smtpConnect($this->SMTPOptions)) {
Scott committed
1543 1544
            throw new phpmailerException($this->lang('smtp_connect_failed'), self::STOP_CRITICAL);
        }
ProThoughts committed
1545
        if (!empty($this->Sender) and $this->validateAddress($this->Sender)) {
Scott committed
1546
            $smtp_from = $this->Sender;
ProThoughts committed
1547 1548
        } else {
            $smtp_from = $this->From;
Scott committed
1549
        }
Scott committed
1550 1551 1552 1553 1554 1555
        if (!$this->smtp->mail($smtp_from)) {
            $this->setError($this->lang('from_failed') . $smtp_from . ' : ' . implode(',', $this->smtp->getError()));
            throw new phpmailerException($this->ErrorInfo, self::STOP_CRITICAL);
        }

        // Attempt to send to all recipients
Scott committed
1556 1557 1558 1559 1560 1561 1562 1563 1564 1565
        foreach (array($this->to, $this->cc, $this->bcc) as $togroup) {
            foreach ($togroup as $to) {
                if (!$this->smtp->recipient($to[0])) {
                    $error = $this->smtp->getError();
                    $bad_rcpt[] = array('to' => $to[0], 'error' => $error['detail']);
                    $isSent = false;
                } else {
                    $isSent = true;
                }
                $this->doCallback($isSent, array($to[0]), array(), array(), $this->Subject, $body, $this->From);
Scott committed
1566 1567 1568
            }
        }

Scott committed
1569
        // Only send the DATA command if we have viable recipients
Scott committed
1570 1571 1572
        if ((count($this->all_recipients) > count($bad_rcpt)) and !$this->smtp->data($header . $body)) {
            throw new phpmailerException($this->lang('data_not_accepted'), self::STOP_CRITICAL);
        }
Scott committed
1573
        if ($this->SMTPKeepAlive) {
Scott committed
1574 1575 1576 1577 1578
            $this->smtp->reset();
        } else {
            $this->smtp->quit();
            $this->smtp->close();
        }
Scott committed
1579 1580 1581 1582 1583 1584
        //Create error message for any bad addresses
        if (count($bad_rcpt) > 0) {
            $errstr = '';
            foreach ($bad_rcpt as $bad) {
                $errstr .= $bad['to'] . ': ' . $bad['error'];
            }
Scott committed
1585
            throw new phpmailerException(
Scott committed
1586
                $this->lang('recipients_failed') . $errstr,
Scott committed
1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599
                self::STOP_CONTINUE
            );
        }
        return true;
    }

    /**
     * Initiate a connection to an SMTP server.
     * Returns false if the operation failed.
     * @param array $options An array of options compatible with stream_context_create()
     * @uses SMTP
     * @access public
     * @throws phpmailerException
Scott committed
1600
     * @return boolean
Scott committed
1601
     */
ProThoughts committed
1602
    public function smtpConnect($options = null)
Scott committed
1603 1604 1605 1606
    {
        if (is_null($this->smtp)) {
            $this->smtp = $this->getSMTPInstance();
        }
Scott committed
1607

ProThoughts committed
1608 1609 1610 1611 1612
        //If no options are provided, use whatever is set in the instance
        if (is_null($options)) {
            $options = $this->SMTPOptions;
        }

Scott committed
1613
        // Already connected?
Scott committed
1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626
        if ($this->smtp->connected()) {
            return true;
        }

        $this->smtp->setTimeout($this->Timeout);
        $this->smtp->setDebugLevel($this->SMTPDebug);
        $this->smtp->setDebugOutput($this->Debugoutput);
        $this->smtp->setVerp($this->do_verp);
        $hosts = explode(';', $this->Host);
        $lastexception = null;

        foreach ($hosts as $hostentry) {
            $hostinfo = array();
1627 1628 1629 1630 1631
            if (!preg_match(
                '/^((ssl|tls):\/\/)*([a-zA-Z0-9\.-]*|\[[a-fA-F0-9:]+\]):?([0-9]*)$/',
                trim($hostentry),
                $hostinfo
            )) {
Scott committed
1632
                // Not a valid host entry
1633
                $this->edebug('Ignoring invalid host: ' . $hostentry);
Scott committed
1634 1635
                continue;
            }
Scott committed
1636 1637 1638 1639 1640
            // $hostinfo[2]: optional ssl or tls prefix
            // $hostinfo[3]: the hostname
            // $hostinfo[4]: optional port number
            // The host string prefix can temporarily override the current setting for SMTPSecure
            // If it's not specified, the default value is used
Scott committed
1641
            $prefix = '';
Scott committed
1642
            $secure = $this->SMTPSecure;
Scott committed
1643
            $tls = ($this->SMTPSecure == 'tls');
Scott committed
1644
            if ('ssl' == $hostinfo[2] or ('' == $hostinfo[2] and 'ssl' == $this->SMTPSecure)) {
Scott committed
1645
                $prefix = 'ssl://';
Scott committed
1646 1647
                $tls = false; // Can't have SSL and TLS at the same time
                $secure = 'ssl';
Scott committed
1648 1649
            } elseif ($hostinfo[2] == 'tls') {
                $tls = true;
Scott committed
1650 1651 1652 1653 1654 1655 1656 1657 1658 1659
                // tls doesn't use a prefix
                $secure = 'tls';
            }
            //Do we need the OpenSSL extension?
            $sslext = defined('OPENSSL_ALGO_SHA1');
            if ('tls' === $secure or 'ssl' === $secure) {
                //Check for an OpenSSL constant rather than using extension_loaded, which is sometimes disabled
                if (!$sslext) {
                    throw new phpmailerException($this->lang('extension_missing').'openssl', self::STOP_CRITICAL);
                }
Scott committed
1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674
            }
            $host = $hostinfo[3];
            $port = $this->Port;
            $tport = (integer)$hostinfo[4];
            if ($tport > 0 and $tport < 65536) {
                $port = $tport;
            }
            if ($this->smtp->connect($prefix . $host, $port, $this->Timeout, $options)) {
                try {
                    if ($this->Helo) {
                        $hello = $this->Helo;
                    } else {
                        $hello = $this->serverHostname();
                    }
                    $this->smtp->hello($hello);
Scott committed
1675 1676 1677 1678 1679 1680 1681 1682
                    //Automatically enable TLS encryption if:
                    // * it's not disabled
                    // * we have openssl extension
                    // * we are not already using SSL
                    // * the server offers STARTTLS
                    if ($this->SMTPAutoTLS and $sslext and $secure != 'ssl' and $this->smtp->getServerExt('STARTTLS')) {
                        $tls = true;
                    }
Scott committed
1683 1684 1685 1686
                    if ($tls) {
                        if (!$this->smtp->startTLS()) {
                            throw new phpmailerException($this->lang('connect_host'));
                        }
ProThoughts committed
1687
                        // We must resend EHLO after TLS negotiation
Scott committed
1688 1689 1690 1691
                        $this->smtp->hello($hello);
                    }
                    if ($this->SMTPAuth) {
                        if (!$this->smtp->authenticate(
Scott committed
1692 1693 1694 1695
                            $this->Username,
                            $this->Password,
                            $this->AuthType,
                            $this->Realm,
Scott committed
1696 1697 1698 1699 1700 1701 1702
                            $this->Workstation
                        )
                        ) {
                            throw new phpmailerException($this->lang('authenticate'));
                        }
                    }
                    return true;
Scott committed
1703 1704 1705 1706
                } catch (phpmailerException $exc) {
                    $lastexception = $exc;
                    $this->edebug($exc->getMessage());
                    // We must have connected, but then failed TLS or Auth, so close connection nicely
Scott committed
1707 1708 1709 1710
                    $this->smtp->quit();
                }
            }
        }
Scott committed
1711
        // If we get here, all connection attempts have failed, so close connection hard
Scott committed
1712
        $this->smtp->close();
Scott committed
1713
        // As we've caught all exceptions, just report whatever the last one was
Scott committed
1714 1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725
        if ($this->exceptions and !is_null($lastexception)) {
            throw $lastexception;
        }
        return false;
    }

    /**
     * Close the active SMTP session if one exists.
     * @return void
     */
    public function smtpClose()
    {
ProThoughts committed
1726
        if (is_a($this->smtp, 'SMTP')) {
Scott committed
1727 1728 1729 1730 1731 1732 1733 1734 1735 1736 1737 1738 1739
            if ($this->smtp->connected()) {
                $this->smtp->quit();
                $this->smtp->close();
            }
        }
    }

    /**
     * Set the language for error messages.
     * Returns false if it cannot load the language file.
     * The default language is English.
     * @param string $langcode ISO 639-1 2-character language code (e.g. French is "fr")
     * @param string $lang_path Path to the language file directory, with trailing separator (slash)
Scott committed
1740
     * @return boolean
Scott committed
1741 1742
     * @access public
     */
Scott committed
1743
    public function setLanguage($langcode = 'en', $lang_path = '')
Scott committed
1744
    {
ProThoughts committed
1745 1746 1747 1748 1749 1750 1751
        // Backwards compatibility for renamed language codes
        $renamed_langcodes = array(
            'br' => 'pt_br',
            'cz' => 'cs',
            'dk' => 'da',
            'no' => 'nb',
            'se' => 'sv',
1752
            'sr' => 'rs'
ProThoughts committed
1753 1754 1755 1756 1757 1758
        );

        if (isset($renamed_langcodes[$langcode])) {
            $langcode = $renamed_langcodes[$langcode];
        }

Scott committed
1759
        // Define full set of translatable strings in English
Scott committed
1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770
        $PHPMAILER_LANG = array(
            'authenticate' => 'SMTP Error: Could not authenticate.',
            'connect_host' => 'SMTP Error: Could not connect to SMTP host.',
            'data_not_accepted' => 'SMTP Error: data not accepted.',
            'empty_message' => 'Message body empty',
            'encoding' => 'Unknown encoding: ',
            'execute' => 'Could not execute: ',
            'file_access' => 'Could not access file: ',
            'file_open' => 'File Error: Could not open file: ',
            'from_failed' => 'The following From address failed: ',
            'instantiate' => 'Could not instantiate mail function.',
Scott committed
1771
            'invalid_address' => 'Invalid address: ',
Scott committed
1772 1773 1774 1775 1776 1777
            'mailer_not_supported' => ' mailer is not supported.',
            'provide_address' => 'You must provide at least one recipient email address.',
            'recipients_failed' => 'SMTP Error: The following recipients failed: ',
            'signing' => 'Signing Error: ',
            'smtp_connect_failed' => 'SMTP connect() failed.',
            'smtp_error' => 'SMTP server error: ',
Scott committed
1778 1779
            'variable_set' => 'Cannot set or reset variable: ',
            'extension_missing' => 'Extension missing: '
Scott committed
1780
        );
Scott committed
1781 1782 1783 1784
        if (empty($lang_path)) {
            // Calculate an absolute path so it can work if CWD is not here
            $lang_path = dirname(__FILE__). DIRECTORY_SEPARATOR . 'language'. DIRECTORY_SEPARATOR;
        }
ProThoughts committed
1785 1786 1787 1788
        //Validate $langcode
        if (!preg_match('/^[a-z]{2}(?:_[a-zA-Z]{2})?$/', $langcode)) {
            $langcode = 'en';
        }
Scott committed
1789
        $foundlang = true;
Scott committed
1790
        $lang_file = $lang_path . 'phpmailer.lang-' . $langcode . '.php';
Scott committed
1791 1792 1793
        // There is no English translation file
        if ($langcode != 'en') {
            // Make sure language file path is readable
Scott committed
1794
            if (!is_readable($lang_file)) {
Scott committed
1795
                $foundlang = false;
Scott committed
1796
            } else {
Scott committed
1797 1798 1799
                // Overwrite language-specific strings.
                // This way we'll never have missing translation keys.
                $foundlang = include $lang_file;
Scott committed
1800 1801 1802
            }
        }
        $this->language = $PHPMAILER_LANG;
Scott committed
1803
        return (boolean)$foundlang; // Returns false if language not found
Scott committed
1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824 1825 1826 1827
    }

    /**
     * Get the array of strings for the current language.
     * @return array
     */
    public function getTranslations()
    {
        return $this->language;
    }

    /**
     * Create recipient headers.
     * @access public
     * @param string $type
     * @param array $addr An array of recipient,
     * where each recipient is a 2-element indexed array with element 0 containing an address
     * and element 1 containing a name, like:
     * array(array('joe@example.com', 'Joe User'), array('zoe@example.com', 'Zoe User'))
     * @return string
     */
    public function addrAppend($type, $addr)
    {
        $addresses = array();
Scott committed
1828 1829
        foreach ($addr as $address) {
            $addresses[] = $this->addrFormat($address);
Scott committed
1830 1831 1832 1833 1834 1835 1836 1837 1838 1839 1840 1841 1842 1843 1844 1845
        }
        return $type . ': ' . implode(', ', $addresses) . $this->LE;
    }

    /**
     * Format an address for use in a message header.
     * @access public
     * @param array $addr A 2-element indexed array, element 0 containing an address, element 1 containing a name
     *      like array('joe@example.com', 'Joe User')
     * @return string
     */
    public function addrFormat($addr)
    {
        if (empty($addr[1])) { // No name provided
            return $this->secureHeader($addr[0]);
        } else {
Scott committed
1846
            return $this->encodeHeader($this->secureHeader($addr[1]), 'phrase') . ' <' . $this->secureHeader(
Scott committed
1847
                $addr[0]
Scott committed
1848
            ) . '>';
Scott committed
1849 1850 1851 1852 1853 1854 1855 1856 1857 1858
        }
    }

    /**
     * Word-wrap message.
     * For use with mailers that do not automatically perform wrapping
     * and for quoted-printable encoded messages.
     * Original written by philippe.
     * @param string $message The message to wrap
     * @param integer $length The line length to wrap to
Scott committed
1859
     * @param boolean $qp_mode Whether to run in Quoted-Printable mode
Scott committed
1860 1861 1862 1863 1864
     * @access public
     * @return string
     */
    public function wrapText($message, $length, $qp_mode = false)
    {
Scott committed
1865 1866 1867 1868 1869
        if ($qp_mode) {
            $soft_break = sprintf(' =%s', $this->LE);
        } else {
            $soft_break = $this->LE;
        }
Scott committed
1870 1871
        // If utf-8 encoding is used, we will need to make sure we don't
        // split multibyte characters when we wrap
Scott committed
1872
        $is_utf8 = (strtolower($this->CharSet) == 'utf-8');
Scott committed
1873 1874 1875 1876
        $lelen = strlen($this->LE);
        $crlflen = strlen(self::CRLF);

        $message = $this->fixEOL($message);
Scott committed
1877
        //Remove a trailing line break
Scott committed
1878 1879 1880 1881
        if (substr($message, -$lelen) == $this->LE) {
            $message = substr($message, 0, -$lelen);
        }

Scott committed
1882 1883 1884
        //Split message into lines
        $lines = explode($this->LE, $message);
        //Message will be rebuilt in here
Scott committed
1885
        $message = '';
Scott committed
1886 1887
        foreach ($lines as $line) {
            $words = explode(' ', $line);
Scott committed
1888
            $buf = '';
Scott committed
1889 1890
            $firstword = true;
            foreach ($words as $word) {
Scott committed
1891 1892
                if ($qp_mode and (strlen($word) > $length)) {
                    $space_left = $length - strlen($buf) - $crlflen;
Scott committed
1893
                    if (!$firstword) {
Scott committed
1894 1895 1896 1897
                        if ($space_left > 20) {
                            $len = $space_left;
                            if ($is_utf8) {
                                $len = $this->utf8CharBoundary($word, $len);
Scott committed
1898
                            } elseif (substr($word, $len - 1, 1) == '=') {
Scott committed
1899
                                $len--;
Scott committed
1900
                            } elseif (substr($word, $len - 2, 1) == '=') {
Scott committed
1901 1902 1903 1904 1905
                                $len -= 2;
                            }
                            $part = substr($word, 0, $len);
                            $word = substr($word, $len);
                            $buf .= ' ' . $part;
Scott committed
1906
                            $message .= $buf . sprintf('=%s', self::CRLF);
Scott committed
1907 1908 1909 1910 1911 1912 1913 1914 1915 1916 1917 1918
                        } else {
                            $message .= $buf . $soft_break;
                        }
                        $buf = '';
                    }
                    while (strlen($word) > 0) {
                        if ($length <= 0) {
                            break;
                        }
                        $len = $length;
                        if ($is_utf8) {
                            $len = $this->utf8CharBoundary($word, $len);
Scott committed
1919
                        } elseif (substr($word, $len - 1, 1) == '=') {
Scott committed
1920
                            $len--;
Scott committed
1921
                        } elseif (substr($word, $len - 2, 1) == '=') {
Scott committed
1922 1923 1924 1925 1926 1927
                            $len -= 2;
                        }
                        $part = substr($word, 0, $len);
                        $word = substr($word, $len);

                        if (strlen($word) > 0) {
Scott committed
1928
                            $message .= $part . sprintf('=%s', self::CRLF);
Scott committed
1929 1930 1931 1932 1933 1934
                        } else {
                            $buf = $part;
                        }
                    }
                } else {
                    $buf_o = $buf;
Scott committed
1935 1936 1937 1938
                    if (!$firstword) {
                        $buf .= ' ';
                    }
                    $buf .= $word;
Scott committed
1939 1940 1941 1942 1943 1944

                    if (strlen($buf) > $length and $buf_o != '') {
                        $message .= $buf_o . $soft_break;
                        $buf = $word;
                    }
                }
Scott committed
1945
                $firstword = false;
Scott committed
1946 1947 1948 1949 1950 1951 1952 1953 1954
            }
            $message .= $buf . self::CRLF;
        }

        return $message;
    }

    /**
     * Find the last character boundary prior to $maxLength in a utf-8
Scott committed
1955
     * quoted-printable encoded string.
Scott committed
1956 1957 1958
     * Original written by Colin Brown.
     * @access public
     * @param string $encodedText utf-8 QP text
Scott committed
1959 1960
     * @param integer $maxLength Find the last character boundary prior to this length
     * @return integer
Scott committed
1961 1962 1963 1964 1965 1966 1967
     */
    public function utf8CharBoundary($encodedText, $maxLength)
    {
        $foundSplitPos = false;
        $lookBack = 3;
        while (!$foundSplitPos) {
            $lastChunk = substr($encodedText, $maxLength - $lookBack, $lookBack);
Scott committed
1968 1969
            $encodedCharPos = strpos($lastChunk, '=');
            if (false !== $encodedCharPos) {
Scott committed
1970 1971 1972 1973
                // Found start of encoded character byte within $lookBack block.
                // Check the encoded byte value (the 2 chars after the '=')
                $hex = substr($encodedText, $maxLength - $lookBack + $encodedCharPos + 1, 2);
                $dec = hexdec($hex);
Scott committed
1974 1975
                if ($dec < 128) {
                    // Single byte character.
Scott committed
1976 1977
                    // If the encoded char was found at pos 0, it will fit
                    // otherwise reduce maxLength to start of the encoded char
Scott committed
1978 1979 1980
                    if ($encodedCharPos > 0) {
                        $maxLength = $maxLength - ($lookBack - $encodedCharPos);
                    }
Scott committed
1981
                    $foundSplitPos = true;
Scott committed
1982 1983
                } elseif ($dec >= 192) {
                    // First byte of a multi byte character
Scott committed
1984 1985 1986
                    // Reduce maxLength to split at start of character
                    $maxLength = $maxLength - ($lookBack - $encodedCharPos);
                    $foundSplitPos = true;
Scott committed
1987 1988
                } elseif ($dec < 192) {
                    // Middle byte of a multi byte character, look further back
Scott committed
1989 1990 1991 1992 1993 1994 1995 1996 1997 1998 1999
                    $lookBack += 3;
                }
            } else {
                // No encoded character found
                $foundSplitPos = true;
            }
        }
        return $maxLength;
    }

    /**
Scott committed
2000 2001 2002 2003
     * Apply word wrapping to the message body.
     * Wraps the message body to the number of chars set in the WordWrap property.
     * You should only do this to plain-text bodies as wrapping HTML tags may break them.
     * This is called automatically by createBody(), so you don't need to call it yourself.
Scott committed
2004 2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 2028 2029 2030 2031 2032 2033 2034
     * @access public
     * @return void
     */
    public function setWordWrap()
    {
        if ($this->WordWrap < 1) {
            return;
        }

        switch ($this->message_type) {
            case 'alt':
            case 'alt_inline':
            case 'alt_attach':
            case 'alt_inline_attach':
                $this->AltBody = $this->wrapText($this->AltBody, $this->WordWrap);
                break;
            default:
                $this->Body = $this->wrapText($this->Body, $this->WordWrap);
                break;
        }
    }

    /**
     * Assemble message headers.
     * @access public
     * @return string The assembled headers
     */
    public function createHeader()
    {
        $result = '';

2035
        $result .= $this->headerLine('Date', $this->MessageDate == '' ? self::rfcDate() : $this->MessageDate);
Scott committed
2036 2037

        // To be created automatically by mail()
Scott committed
2038 2039 2040 2041
        if ($this->SingleTo) {
            if ($this->Mailer != 'mail') {
                foreach ($this->to as $toaddr) {
                    $this->SingleToArray[] = $this->addrFormat($toaddr);
Scott committed
2042
                }
Scott committed
2043 2044 2045 2046
            }
        } else {
            if (count($this->to) > 0) {
                if ($this->Mailer != 'mail') {
Scott committed
2047 2048
                    $result .= $this->addrAppend('To', $this->to);
                }
Scott committed
2049 2050
            } elseif (count($this->cc) == 0) {
                $result .= $this->headerLine('To', 'undisclosed-recipients:;');
Scott committed
2051 2052 2053 2054 2055 2056 2057 2058 2059 2060 2061 2062 2063 2064 2065 2066 2067 2068 2069 2070 2071 2072 2073 2074 2075 2076 2077 2078
            }
        }

        $result .= $this->addrAppend('From', array(array(trim($this->From), $this->FromName)));

        // sendmail and mail() extract Cc from the header before sending
        if (count($this->cc) > 0) {
            $result .= $this->addrAppend('Cc', $this->cc);
        }

        // sendmail and mail() extract Bcc from the header before sending
        if ((
                $this->Mailer == 'sendmail' or $this->Mailer == 'qmail' or $this->Mailer == 'mail'
            )
            and count($this->bcc) > 0
        ) {
            $result .= $this->addrAppend('Bcc', $this->bcc);
        }

        if (count($this->ReplyTo) > 0) {
            $result .= $this->addrAppend('Reply-To', $this->ReplyTo);
        }

        // mail() sets the subject itself
        if ($this->Mailer != 'mail') {
            $result .= $this->headerLine('Subject', $this->encodeHeader($this->secureHeader($this->Subject)));
        }

ProThoughts committed
2079 2080 2081
        // Only allow a custom message ID if it conforms to RFC 5322 section 3.6.4
        // https://tools.ietf.org/html/rfc5322#section-3.6.4
        if ('' != $this->MessageID and preg_match('/^<.*@.*>$/', $this->MessageID)) {
Scott committed
2082 2083
            $this->lastMessageID = $this->MessageID;
        } else {
Scott committed
2084
            $this->lastMessageID = sprintf('<%s@%s>', $this->uniqueid, $this->serverHostname());
Scott committed
2085 2086 2087 2088
        }
        $result .= $this->headerLine('Message-ID', $this->lastMessageID);
        if (!is_null($this->Priority)) {
            $result .= $this->headerLine('X-Priority', $this->Priority);
Scott committed
2089 2090 2091 2092
        }
        if ($this->XMailer == '') {
            $result .= $this->headerLine(
                'X-Mailer',
Scott committed
2093
                'PHPMailer ' . $this->Version . ' (https://github.com/PHPMailer/PHPMailer)'
Scott committed
2094 2095 2096 2097 2098 2099 2100 2101 2102
            );
        } else {
            $myXmailer = trim($this->XMailer);
            if ($myXmailer) {
                $result .= $this->headerLine('X-Mailer', $myXmailer);
            }
        }

        if ($this->ConfirmReadingTo != '') {
Scott committed
2103
            $result .= $this->headerLine('Disposition-Notification-To', '<' . $this->ConfirmReadingTo . '>');
Scott committed
2104 2105 2106
        }

        // Add custom headers
Scott committed
2107
        foreach ($this->CustomHeader as $header) {
Scott committed
2108
            $result .= $this->headerLine(
Scott committed
2109 2110
                trim($header[0]),
                $this->encodeHeader(trim($header[1]))
Scott committed
2111 2112 2113 2114 2115 2116 2117 2118 2119 2120 2121 2122 2123 2124 2125 2126 2127 2128
            );
        }
        if (!$this->sign_key_file) {
            $result .= $this->headerLine('MIME-Version', '1.0');
            $result .= $this->getMailMIME();
        }

        return $result;
    }

    /**
     * Get the message MIME type headers.
     * @access public
     * @return string
     */
    public function getMailMIME()
    {
        $result = '';
Scott committed
2129
        $ismultipart = true;
Scott committed
2130 2131 2132 2133 2134 2135 2136 2137 2138 2139 2140 2141 2142 2143 2144 2145 2146 2147 2148 2149
        switch ($this->message_type) {
            case 'inline':
                $result .= $this->headerLine('Content-Type', 'multipart/related;');
                $result .= $this->textLine("\tboundary=\"" . $this->boundary[1] . '"');
                break;
            case 'attach':
            case 'inline_attach':
            case 'alt_attach':
            case 'alt_inline_attach':
                $result .= $this->headerLine('Content-Type', 'multipart/mixed;');
                $result .= $this->textLine("\tboundary=\"" . $this->boundary[1] . '"');
                break;
            case 'alt':
            case 'alt_inline':
                $result .= $this->headerLine('Content-Type', 'multipart/alternative;');
                $result .= $this->textLine("\tboundary=\"" . $this->boundary[1] . '"');
                break;
            default:
                // Catches case 'plain': and case '':
                $result .= $this->textLine('Content-Type: ' . $this->ContentType . '; charset=' . $this->CharSet);
Scott committed
2150
                $ismultipart = false;
Scott committed
2151 2152
                break;
        }
Scott committed
2153
        // RFC1341 part 5 says 7bit is assumed if not specified
Scott committed
2154
        if ($this->Encoding != '7bit') {
Scott committed
2155 2156 2157 2158 2159 2160 2161 2162 2163
            // RFC 2045 section 6.4 says multipart MIME parts may only use 7bit, 8bit or binary CTE
            if ($ismultipart) {
                if ($this->Encoding == '8bit') {
                    $result .= $this->headerLine('Content-Transfer-Encoding', '8bit');
                }
                // The only remaining alternatives are quoted-printable and base64, which are both 7bit compatible
            } else {
                $result .= $this->headerLine('Content-Transfer-Encoding', $this->Encoding);
            }
Scott committed
2164 2165 2166 2167 2168 2169 2170 2171 2172 2173 2174 2175
        }

        if ($this->Mailer != 'mail') {
            $result .= $this->LE;
        }

        return $result;
    }

    /**
     * Returns the whole MIME message.
     * Includes complete headers and body.
Scott committed
2176 2177
     * Only valid post preSend().
     * @see PHPMailer::preSend()
Scott committed
2178 2179 2180 2181 2182
     * @access public
     * @return string
     */
    public function getSentMIMEMessage()
    {
ProThoughts committed
2183 2184 2185 2186 2187 2188 2189 2190 2191
        return rtrim($this->MIMEHeader . $this->mailHeader, "\n\r") . self::CRLF . self::CRLF . $this->MIMEBody;
    }

    /**
     * Create unique ID
     * @return string
     */
    protected function generateId() {
        return md5(uniqid(time()));
Scott committed
2192 2193 2194 2195 2196 2197 2198 2199 2200 2201 2202 2203
    }

    /**
     * Assemble the message body.
     * Returns an empty string on failure.
     * @access public
     * @throws phpmailerException
     * @return string The assembled message body
     */
    public function createBody()
    {
        $body = '';
Scott committed
2204
        //Create unique IDs and preset boundaries
ProThoughts committed
2205
        $this->uniqueid = $this->generateId();
Scott committed
2206 2207 2208
        $this->boundary[1] = 'b1_' . $this->uniqueid;
        $this->boundary[2] = 'b2_' . $this->uniqueid;
        $this->boundary[3] = 'b3_' . $this->uniqueid;
Scott committed
2209 2210 2211 2212 2213 2214 2215 2216 2217

        if ($this->sign_key_file) {
            $body .= $this->getMailMIME() . $this->LE;
        }

        $this->setWordWrap();

        $bodyEncoding = $this->Encoding;
        $bodyCharSet = $this->CharSet;
Scott committed
2218 2219
        //Can we do a 7-bit downgrade?
        if ($bodyEncoding == '8bit' and !$this->has8bitChars($this->Body)) {
Scott committed
2220
            $bodyEncoding = '7bit';
ProThoughts committed
2221
            //All ISO 8859, Windows codepage and UTF-8 charsets are ascii compatible up to 7-bit
Scott committed
2222 2223
            $bodyCharSet = 'us-ascii';
        }
Scott committed
2224
        //If lines are too long, and we're not already using an encoding that will shorten them,
ProThoughts committed
2225
        //change to quoted-printable transfer encoding for the body part only
Scott committed
2226 2227 2228 2229
        if ('base64' != $this->Encoding and self::hasLineLongerThanMax($this->Body)) {
            $bodyEncoding = 'quoted-printable';
        }

Scott committed
2230 2231
        $altBodyEncoding = $this->Encoding;
        $altBodyCharSet = $this->CharSet;
Scott committed
2232 2233
        //Can we do a 7-bit downgrade?
        if ($altBodyEncoding == '8bit' and !$this->has8bitChars($this->AltBody)) {
Scott committed
2234
            $altBodyEncoding = '7bit';
ProThoughts committed
2235
            //All ISO 8859, Windows codepage and UTF-8 charsets are ascii compatible up to 7-bit
Scott committed
2236 2237
            $altBodyCharSet = 'us-ascii';
        }
ProThoughts committed
2238 2239 2240
        //If lines are too long, and we're not already using an encoding that will shorten them,
        //change to quoted-printable transfer encoding for the alt body part only
        if ('base64' != $altBodyEncoding and self::hasLineLongerThanMax($this->AltBody)) {
Scott committed
2241 2242 2243 2244
            $altBodyEncoding = 'quoted-printable';
        }
        //Use this as a preamble in all multipart message types
        $mimepre = "This is a multi-part message in MIME format." . $this->LE . $this->LE;
Scott committed
2245 2246
        switch ($this->message_type) {
            case 'inline':
Scott committed
2247
                $body .= $mimepre;
Scott committed
2248 2249 2250 2251 2252 2253
                $body .= $this->getBoundary($this->boundary[1], $bodyCharSet, '', $bodyEncoding);
                $body .= $this->encodeString($this->Body, $bodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->attachAll('inline', $this->boundary[1]);
                break;
            case 'attach':
Scott committed
2254
                $body .= $mimepre;
Scott committed
2255 2256 2257 2258 2259 2260
                $body .= $this->getBoundary($this->boundary[1], $bodyCharSet, '', $bodyEncoding);
                $body .= $this->encodeString($this->Body, $bodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->attachAll('attachment', $this->boundary[1]);
                break;
            case 'inline_attach':
Scott committed
2261
                $body .= $mimepre;
Scott committed
2262 2263 2264 2265 2266 2267 2268 2269 2270 2271 2272 2273
                $body .= $this->textLine('--' . $this->boundary[1]);
                $body .= $this->headerLine('Content-Type', 'multipart/related;');
                $body .= $this->textLine("\tboundary=\"" . $this->boundary[2] . '"');
                $body .= $this->LE;
                $body .= $this->getBoundary($this->boundary[2], $bodyCharSet, '', $bodyEncoding);
                $body .= $this->encodeString($this->Body, $bodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->attachAll('inline', $this->boundary[2]);
                $body .= $this->LE;
                $body .= $this->attachAll('attachment', $this->boundary[1]);
                break;
            case 'alt':
Scott committed
2274
                $body .= $mimepre;
Scott committed
2275 2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288
                $body .= $this->getBoundary($this->boundary[1], $altBodyCharSet, 'text/plain', $altBodyEncoding);
                $body .= $this->encodeString($this->AltBody, $altBodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->getBoundary($this->boundary[1], $bodyCharSet, 'text/html', $bodyEncoding);
                $body .= $this->encodeString($this->Body, $bodyEncoding);
                $body .= $this->LE . $this->LE;
                if (!empty($this->Ical)) {
                    $body .= $this->getBoundary($this->boundary[1], '', 'text/calendar; method=REQUEST', '');
                    $body .= $this->encodeString($this->Ical, $this->Encoding);
                    $body .= $this->LE . $this->LE;
                }
                $body .= $this->endBoundary($this->boundary[1]);
                break;
            case 'alt_inline':
Scott committed
2289
                $body .= $mimepre;
Scott committed
2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301 2302 2303 2304
                $body .= $this->getBoundary($this->boundary[1], $altBodyCharSet, 'text/plain', $altBodyEncoding);
                $body .= $this->encodeString($this->AltBody, $altBodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->textLine('--' . $this->boundary[1]);
                $body .= $this->headerLine('Content-Type', 'multipart/related;');
                $body .= $this->textLine("\tboundary=\"" . $this->boundary[2] . '"');
                $body .= $this->LE;
                $body .= $this->getBoundary($this->boundary[2], $bodyCharSet, 'text/html', $bodyEncoding);
                $body .= $this->encodeString($this->Body, $bodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->attachAll('inline', $this->boundary[2]);
                $body .= $this->LE;
                $body .= $this->endBoundary($this->boundary[1]);
                break;
            case 'alt_attach':
Scott committed
2305
                $body .= $mimepre;
Scott committed
2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320
                $body .= $this->textLine('--' . $this->boundary[1]);
                $body .= $this->headerLine('Content-Type', 'multipart/alternative;');
                $body .= $this->textLine("\tboundary=\"" . $this->boundary[2] . '"');
                $body .= $this->LE;
                $body .= $this->getBoundary($this->boundary[2], $altBodyCharSet, 'text/plain', $altBodyEncoding);
                $body .= $this->encodeString($this->AltBody, $altBodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->getBoundary($this->boundary[2], $bodyCharSet, 'text/html', $bodyEncoding);
                $body .= $this->encodeString($this->Body, $bodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->endBoundary($this->boundary[2]);
                $body .= $this->LE;
                $body .= $this->attachAll('attachment', $this->boundary[1]);
                break;
            case 'alt_inline_attach':
Scott committed
2321
                $body .= $mimepre;
Scott committed
2322 2323 2324 2325 2326 2327 2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338 2339 2340 2341 2342
                $body .= $this->textLine('--' . $this->boundary[1]);
                $body .= $this->headerLine('Content-Type', 'multipart/alternative;');
                $body .= $this->textLine("\tboundary=\"" . $this->boundary[2] . '"');
                $body .= $this->LE;
                $body .= $this->getBoundary($this->boundary[2], $altBodyCharSet, 'text/plain', $altBodyEncoding);
                $body .= $this->encodeString($this->AltBody, $altBodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->textLine('--' . $this->boundary[2]);
                $body .= $this->headerLine('Content-Type', 'multipart/related;');
                $body .= $this->textLine("\tboundary=\"" . $this->boundary[3] . '"');
                $body .= $this->LE;
                $body .= $this->getBoundary($this->boundary[3], $bodyCharSet, 'text/html', $bodyEncoding);
                $body .= $this->encodeString($this->Body, $bodyEncoding);
                $body .= $this->LE . $this->LE;
                $body .= $this->attachAll('inline', $this->boundary[3]);
                $body .= $this->LE;
                $body .= $this->endBoundary($this->boundary[2]);
                $body .= $this->LE;
                $body .= $this->attachAll('attachment', $this->boundary[1]);
                break;
            default:
ProThoughts committed
2343 2344 2345 2346
                // Catch case 'plain' and case '', applies to simple `text/plain` and `text/html` body content types
                //Reset the `Encoding` property in case we changed it for line length reasons
                $this->Encoding = $bodyEncoding;
                $body .= $this->encodeString($this->Body, $this->Encoding);
Scott committed
2347 2348 2349 2350 2351 2352 2353 2354
                break;
        }

        if ($this->isError()) {
            $body = '';
        } elseif ($this->sign_key_file) {
            try {
                if (!defined('PKCS7_TEXT')) {
Scott committed
2355
                    throw new phpmailerException($this->lang('extension_missing') . 'openssl');
Scott committed
2356
                }
Scott committed
2357
                // @TODO would be nice to use php://temp streams here, but need to wrap for PHP < 5.1
Scott committed
2358
                $file = tempnam(sys_get_temp_dir(), 'mail');
Scott committed
2359 2360 2361
                if (false === file_put_contents($file, $body)) {
                    throw new phpmailerException($this->lang('signing') . ' Could not write temp file');
                }
Scott committed
2362
                $signed = tempnam(sys_get_temp_dir(), 'signed');
Scott committed
2363 2364 2365 2366 2367 2368 2369 2370 2371 2372 2373 2374 2375 2376 2377 2378 2379 2380 2381 2382 2383
                //Workaround for PHP bug https://bugs.php.net/bug.php?id=69197
                if (empty($this->sign_extracerts_file)) {
                    $sign = @openssl_pkcs7_sign(
                        $file,
                        $signed,
                        'file://' . realpath($this->sign_cert_file),
                        array('file://' . realpath($this->sign_key_file), $this->sign_key_pass),
                        null
                    );
                } else {
                    $sign = @openssl_pkcs7_sign(
                        $file,
                        $signed,
                        'file://' . realpath($this->sign_cert_file),
                        array('file://' . realpath($this->sign_key_file), $this->sign_key_pass),
                        null,
                        PKCS7_DETACHED,
                        $this->sign_extracerts_file
                    );
                }
                if ($sign) {
Scott committed
2384 2385 2386
                    @unlink($file);
                    $body = file_get_contents($signed);
                    @unlink($signed);
Scott committed
2387 2388 2389 2390
                    //The message returned by openssl contains both headers and body, so need to split them up
                    $parts = explode("\n\n", $body, 2);
                    $this->MIMEHeader .= $parts[0] . $this->LE . $this->LE;
                    $body = $parts[1];
Scott committed
2391 2392 2393 2394 2395
                } else {
                    @unlink($file);
                    @unlink($signed);
                    throw new phpmailerException($this->lang('signing') . openssl_error_string());
                }
Scott committed
2396
            } catch (phpmailerException $exc) {
Scott committed
2397 2398
                $body = '';
                if ($this->exceptions) {
Scott committed
2399
                    throw $exc;
Scott committed
2400 2401 2402 2403 2404 2405 2406 2407 2408 2409 2410 2411 2412 2413 2414 2415 2416 2417 2418 2419 2420 2421 2422 2423 2424 2425 2426 2427
                }
            }
        }
        return $body;
    }

    /**
     * Return the start of a message boundary.
     * @access protected
     * @param string $boundary
     * @param string $charSet
     * @param string $contentType
     * @param string $encoding
     * @return string
     */
    protected function getBoundary($boundary, $charSet, $contentType, $encoding)
    {
        $result = '';
        if ($charSet == '') {
            $charSet = $this->CharSet;
        }
        if ($contentType == '') {
            $contentType = $this->ContentType;
        }
        if ($encoding == '') {
            $encoding = $this->Encoding;
        }
        $result .= $this->textLine('--' . $boundary);
Scott committed
2428
        $result .= sprintf('Content-Type: %s; charset=%s', $contentType, $charSet);
Scott committed
2429
        $result .= $this->LE;
Scott committed
2430
        // RFC1341 part 5 says 7bit is assumed if not specified
Scott committed
2431 2432 2433 2434 2435 2436 2437 2438 2439 2440 2441 2442 2443 2444 2445 2446 2447 2448 2449 2450 2451
        if ($encoding != '7bit') {
            $result .= $this->headerLine('Content-Transfer-Encoding', $encoding);
        }
        $result .= $this->LE;

        return $result;
    }

    /**
     * Return the end of a message boundary.
     * @access protected
     * @param string $boundary
     * @return string
     */
    protected function endBoundary($boundary)
    {
        return $this->LE . '--' . $boundary . '--' . $this->LE;
    }

    /**
     * Set the message type.
ProThoughts committed
2452
     * PHPMailer only supports some preset message types, not arbitrary MIME structures.
Scott committed
2453 2454 2455 2456 2457
     * @access protected
     * @return void
     */
    protected function setMessageType()
    {
Scott committed
2458
        $type = array();
Scott committed
2459
        if ($this->alternativeExists()) {
Scott committed
2460
            $type[] = 'alt';
Scott committed
2461 2462
        }
        if ($this->inlineImageExists()) {
Scott committed
2463
            $type[] = 'inline';
Scott committed
2464 2465
        }
        if ($this->attachmentExists()) {
Scott committed
2466
            $type[] = 'attach';
Scott committed
2467
        }
Scott committed
2468 2469
        $this->message_type = implode('_', $type);
        if ($this->message_type == '') {
ProThoughts committed
2470
            //The 'plain' message_type refers to the message having a single body element, not that it is plain-text
Scott committed
2471
            $this->message_type = 'plain';
Scott committed
2472 2473 2474 2475 2476 2477 2478 2479 2480 2481 2482 2483 2484 2485 2486 2487 2488 2489 2490 2491 2492 2493 2494 2495 2496 2497 2498 2499
        }
    }

    /**
     * Format a header line.
     * @access public
     * @param string $name
     * @param string $value
     * @return string
     */
    public function headerLine($name, $value)
    {
        return $name . ': ' . $value . $this->LE;
    }

    /**
     * Return a formatted mail line.
     * @access public
     * @param string $value
     * @return string
     */
    public function textLine($value)
    {
        return $value . $this->LE;
    }

    /**
     * Add an attachment from a path on the filesystem.
ProThoughts committed
2500
     * Never use a user-supplied path to a file!
Scott committed
2501 2502 2503 2504 2505 2506 2507
     * Returns false if the file could not be found or read.
     * @param string $path Path to the attachment.
     * @param string $name Overrides the attachment name.
     * @param string $encoding File encoding (see $Encoding).
     * @param string $type File extension (MIME) type.
     * @param string $disposition Disposition to use
     * @throws phpmailerException
Scott committed
2508
     * @return boolean
Scott committed
2509 2510 2511 2512 2513 2514 2515 2516
     */
    public function addAttachment($path, $name = '', $encoding = 'base64', $type = '', $disposition = 'attachment')
    {
        try {
            if (!@is_file($path)) {
                throw new phpmailerException($this->lang('file_access') . $path, self::STOP_CONTINUE);
            }

Scott committed
2517
            // If a MIME type is not specified, try to work it out from the file name
Scott committed
2518 2519 2520 2521 2522 2523 2524 2525 2526 2527 2528 2529 2530 2531 2532 2533 2534 2535 2536 2537
            if ($type == '') {
                $type = self::filenameToType($path);
            }

            $filename = basename($path);
            if ($name == '') {
                $name = $filename;
            }

            $this->attachment[] = array(
                0 => $path,
                1 => $filename,
                2 => $name,
                3 => $encoding,
                4 => $type,
                5 => false, // isStringAttachment
                6 => $disposition,
                7 => 0
            );

Scott committed
2538 2539 2540
        } catch (phpmailerException $exc) {
            $this->setError($exc->getMessage());
            $this->edebug($exc->getMessage());
Scott committed
2541
            if ($this->exceptions) {
Scott committed
2542
                throw $exc;
Scott committed
2543 2544 2545 2546 2547 2548 2549 2550 2551 2552 2553 2554 2555 2556 2557 2558 2559 2560 2561 2562 2563 2564 2565 2566 2567 2568 2569 2570 2571 2572 2573 2574 2575 2576 2577 2578 2579 2580 2581 2582 2583 2584 2585 2586 2587 2588 2589 2590 2591 2592 2593 2594 2595 2596
            }
            return false;
        }
        return true;
    }

    /**
     * Return the array of attachments.
     * @return array
     */
    public function getAttachments()
    {
        return $this->attachment;
    }

    /**
     * Attach all file, string, and binary attachments to the message.
     * Returns an empty string on failure.
     * @access protected
     * @param string $disposition_type
     * @param string $boundary
     * @return string
     */
    protected function attachAll($disposition_type, $boundary)
    {
        // Return text of body
        $mime = array();
        $cidUniq = array();
        $incl = array();

        // Add all attachments
        foreach ($this->attachment as $attachment) {
            // Check if it is a valid disposition_filter
            if ($attachment[6] == $disposition_type) {
                // Check for string attachment
                $string = '';
                $path = '';
                $bString = $attachment[5];
                if ($bString) {
                    $string = $attachment[0];
                } else {
                    $path = $attachment[0];
                }

                $inclhash = md5(serialize($attachment));
                if (in_array($inclhash, $incl)) {
                    continue;
                }
                $incl[] = $inclhash;
                $name = $attachment[2];
                $encoding = $attachment[3];
                $type = $attachment[4];
                $disposition = $attachment[6];
                $cid = $attachment[7];
Scott committed
2597
                if ($disposition == 'inline' && array_key_exists($cid, $cidUniq)) {
Scott committed
2598 2599 2600 2601
                    continue;
                }
                $cidUniq[$cid] = true;

Scott committed
2602 2603 2604 2605 2606 2607 2608 2609 2610 2611 2612 2613 2614 2615 2616 2617 2618
                $mime[] = sprintf('--%s%s', $boundary, $this->LE);
                //Only include a filename property if we have one
                if (!empty($name)) {
                    $mime[] = sprintf(
                        'Content-Type: %s; name="%s"%s',
                        $type,
                        $this->encodeHeader($this->secureHeader($name)),
                        $this->LE
                    );
                } else {
                    $mime[] = sprintf(
                        'Content-Type: %s%s',
                        $type,
                        $this->LE
                    );
                }
                // RFC1341 part 5 says 7bit is assumed if not specified
Scott committed
2619
                if ($encoding != '7bit') {
Scott committed
2620
                    $mime[] = sprintf('Content-Transfer-Encoding: %s%s', $encoding, $this->LE);
Scott committed
2621 2622 2623
                }

                if ($disposition == 'inline') {
Scott committed
2624
                    $mime[] = sprintf('Content-ID: <%s>%s', $cid, $this->LE);
Scott committed
2625 2626 2627 2628 2629 2630 2631
                }

                // If a filename contains any of these chars, it should be quoted,
                // but not otherwise: RFC2183 & RFC2045 5.1
                // Fixes a warning in IETF's msglint MIME checker
                // Allow for bypassing the Content-Disposition header totally
                if (!(empty($disposition))) {
Scott committed
2632 2633
                    $encoded_name = $this->encodeHeader($this->secureHeader($name));
                    if (preg_match('/[ \(\)<>@,;:\\"\/\[\]\?=]/', $encoded_name)) {
Scott committed
2634
                        $mime[] = sprintf(
Scott committed
2635
                            'Content-Disposition: %s; filename="%s"%s',
Scott committed
2636
                            $disposition,
Scott committed
2637
                            $encoded_name,
Scott committed
2638 2639 2640
                            $this->LE . $this->LE
                        );
                    } else {
Scott committed
2641 2642 2643 2644 2645 2646 2647 2648 2649 2650 2651 2652 2653 2654
                        if (!empty($encoded_name)) {
                            $mime[] = sprintf(
                                'Content-Disposition: %s; filename=%s%s',
                                $disposition,
                                $encoded_name,
                                $this->LE . $this->LE
                            );
                        } else {
                            $mime[] = sprintf(
                                'Content-Disposition: %s%s',
                                $disposition,
                                $this->LE . $this->LE
                            );
                        }
Scott committed
2655 2656 2657 2658 2659 2660 2661 2662 2663 2664 2665 2666 2667 2668 2669 2670 2671 2672 2673 2674 2675 2676
                    }
                } else {
                    $mime[] = $this->LE;
                }

                // Encode as string attachment
                if ($bString) {
                    $mime[] = $this->encodeString($string, $encoding);
                    if ($this->isError()) {
                        return '';
                    }
                    $mime[] = $this->LE . $this->LE;
                } else {
                    $mime[] = $this->encodeFile($path, $encoding);
                    if ($this->isError()) {
                        return '';
                    }
                    $mime[] = $this->LE . $this->LE;
                }
            }
        }

Scott committed
2677
        $mime[] = sprintf('--%s--%s', $boundary, $this->LE);
Scott committed
2678

Scott committed
2679
        return implode('', $mime);
Scott committed
2680 2681 2682 2683 2684 2685 2686 2687 2688 2689 2690 2691 2692 2693 2694 2695 2696 2697 2698 2699
    }

    /**
     * Encode a file attachment in requested format.
     * Returns an empty string on failure.
     * @param string $path The full path to the file
     * @param string $encoding The encoding to use; one of 'base64', '7bit', '8bit', 'binary', 'quoted-printable'
     * @throws phpmailerException
     * @access protected
     * @return string
     */
    protected function encodeFile($path, $encoding = 'base64')
    {
        try {
            if (!is_readable($path)) {
                throw new phpmailerException($this->lang('file_open') . $path, self::STOP_CONTINUE);
            }
            $magic_quotes = get_magic_quotes_runtime();
            if ($magic_quotes) {
                if (version_compare(PHP_VERSION, '5.3.0', '<')) {
Scott committed
2700
                    set_magic_quotes_runtime(false);
Scott committed
2701
                } else {
Scott committed
2702 2703 2704 2705
                    //Doesn't exist in PHP 5.4, but we don't need to check because
                    //get_magic_quotes_runtime always returns false in 5.4+
                    //so it will never get here
                    ini_set('magic_quotes_runtime', false);
Scott committed
2706 2707 2708 2709 2710 2711 2712 2713 2714 2715 2716 2717
                }
            }
            $file_buffer = file_get_contents($path);
            $file_buffer = $this->encodeString($file_buffer, $encoding);
            if ($magic_quotes) {
                if (version_compare(PHP_VERSION, '5.3.0', '<')) {
                    set_magic_quotes_runtime($magic_quotes);
                } else {
                    ini_set('magic_quotes_runtime', $magic_quotes);
                }
            }
            return $file_buffer;
Scott committed
2718 2719
        } catch (Exception $exc) {
            $this->setError($exc->getMessage());
Scott committed
2720 2721 2722 2723 2724 2725 2726 2727 2728 2729 2730 2731 2732 2733 2734 2735 2736 2737 2738 2739 2740 2741
            return '';
        }
    }

    /**
     * Encode a string in requested format.
     * Returns an empty string on failure.
     * @param string $str The text to encode
     * @param string $encoding The encoding to use; one of 'base64', '7bit', '8bit', 'binary', 'quoted-printable'
     * @access public
     * @return string
     */
    public function encodeString($str, $encoding = 'base64')
    {
        $encoded = '';
        switch (strtolower($encoding)) {
            case 'base64':
                $encoded = chunk_split(base64_encode($str), 76, $this->LE);
                break;
            case '7bit':
            case '8bit':
                $encoded = $this->fixEOL($str);
Scott committed
2742
                // Make sure it ends with a line break
Scott committed
2743 2744 2745 2746 2747 2748 2749 2750 2751 2752 2753 2754 2755 2756 2757 2758 2759 2760 2761 2762 2763 2764 2765 2766 2767 2768 2769
                if (substr($encoded, -(strlen($this->LE))) != $this->LE) {
                    $encoded .= $this->LE;
                }
                break;
            case 'binary':
                $encoded = $str;
                break;
            case 'quoted-printable':
                $encoded = $this->encodeQP($str);
                break;
            default:
                $this->setError($this->lang('encoding') . $encoding);
                break;
        }
        return $encoded;
    }

    /**
     * Encode a header string optimally.
     * Picks shortest of Q, B, quoted-printable or none.
     * @access public
     * @param string $str
     * @param string $position
     * @return string
     */
    public function encodeHeader($str, $position = 'text')
    {
Scott committed
2770
        $matchcount = 0;
Scott committed
2771 2772 2773 2774 2775 2776 2777 2778 2779 2780 2781
        switch (strtolower($position)) {
            case 'phrase':
                if (!preg_match('/[\200-\377]/', $str)) {
                    // Can't use addslashes as we don't know the value of magic_quotes_sybase
                    $encoded = addcslashes($str, "\0..\37\177\\\"");
                    if (($str == $encoded) && !preg_match('/[^A-Za-z0-9!#$%&\'*+\/=?^_`{|}~ -]/', $str)) {
                        return ($encoded);
                    } else {
                        return ("\"$encoded\"");
                    }
                }
Scott committed
2782
                $matchcount = preg_match_all('/[^\040\041\043-\133\135-\176]/', $str, $matches);
Scott committed
2783 2784 2785
                break;
            /** @noinspection PhpMissingBreakStatementInspection */
            case 'comment':
Scott committed
2786
                $matchcount = preg_match_all('/[()"]/', $str, $matches);
Scott committed
2787 2788 2789
                // Intentional fall-through
            case 'text':
            default:
Scott committed
2790
                $matchcount += preg_match_all('/[\000-\010\013\014\016-\037\177-\377]/', $str, $matches);
Scott committed
2791 2792 2793
                break;
        }

Scott committed
2794 2795
        //There are no chars that need encoding
        if ($matchcount == 0) {
Scott committed
2796 2797 2798 2799 2800
            return ($str);
        }

        $maxlen = 75 - 7 - strlen($this->CharSet);
        // Try to select the encoding which should produce the shortest output
Scott committed
2801 2802
        if ($matchcount > strlen($str) / 3) {
            // More than a third of the content will need encoding, so B encoding will be most efficient
Scott committed
2803 2804 2805 2806 2807 2808 2809 2810 2811 2812 2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826 2827 2828 2829
            $encoding = 'B';
            if (function_exists('mb_strlen') && $this->hasMultiBytes($str)) {
                // Use a custom function which correctly encodes and wraps long
                // multibyte strings without breaking lines within a character
                $encoded = $this->base64EncodeWrapMB($str, "\n");
            } else {
                $encoded = base64_encode($str);
                $maxlen -= $maxlen % 4;
                $encoded = trim(chunk_split($encoded, $maxlen, "\n"));
            }
        } else {
            $encoding = 'Q';
            $encoded = $this->encodeQ($str, $position);
            $encoded = $this->wrapText($encoded, $maxlen, true);
            $encoded = str_replace('=' . self::CRLF, "\n", trim($encoded));
        }

        $encoded = preg_replace('/^(.*)$/m', ' =?' . $this->CharSet . "?$encoding?\\1?=", $encoded);
        $encoded = trim(str_replace("\n", $this->LE, $encoded));

        return $encoded;
    }

    /**
     * Check if a string contains multi-byte characters.
     * @access public
     * @param string $str multi-byte text to wrap encode
Scott committed
2830
     * @return boolean
Scott committed
2831 2832 2833 2834 2835 2836 2837 2838 2839 2840 2841 2842 2843
     */
    public function hasMultiBytes($str)
    {
        if (function_exists('mb_strlen')) {
            return (strlen($str) > mb_strlen($str, $this->CharSet));
        } else { // Assume no multibytes (we can't handle without mbstring functions anyway)
            return false;
        }
    }

    /**
     * Does a string contain any 8-bit chars (in any charset)?
     * @param string $text
Scott committed
2844
     * @return boolean
Scott committed
2845 2846 2847
     */
    public function has8bitChars($text)
    {
Scott committed
2848
        return (boolean)preg_match('/[\x80-\xFF]/', $text);
Scott committed
2849 2850 2851 2852 2853 2854 2855 2856 2857
    }

    /**
     * Encode and wrap long multibyte strings for mail headers
     * without breaking lines within a character.
     * Adapted from a function by paravoid
     * @link http://www.php.net/manual/en/function.mb-encode-mimeheader.php#60283
     * @access public
     * @param string $str multi-byte text to wrap encode
Scott committed
2858
     * @param string $linebreak string to use as linefeed/end-of-line
Scott committed
2859 2860
     * @return string
     */
Scott committed
2861
    public function base64EncodeWrapMB($str, $linebreak = null)
Scott committed
2862
    {
Scott committed
2863 2864 2865 2866 2867
        $start = '=?' . $this->CharSet . '?B?';
        $end = '?=';
        $encoded = '';
        if ($linebreak === null) {
            $linebreak = $this->LE;
Scott committed
2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882 2883 2884 2885
        }

        $mb_length = mb_strlen($str, $this->CharSet);
        // Each line must have length <= 75, including $start and $end
        $length = 75 - strlen($start) - strlen($end);
        // Average multi-byte ratio
        $ratio = $mb_length / strlen($str);
        // Base64 has a 4:3 ratio
        $avgLength = floor($length * $ratio * .75);

        for ($i = 0; $i < $mb_length; $i += $offset) {
            $lookBack = 0;
            do {
                $offset = $avgLength - $lookBack;
                $chunk = mb_substr($str, $i, $offset, $this->CharSet);
                $chunk = base64_encode($chunk);
                $lookBack++;
            } while (strlen($chunk) > $length);
Scott committed
2886
            $encoded .= $chunk . $linebreak;
Scott committed
2887 2888 2889
        }

        // Chomp the last linefeed
Scott committed
2890
        $encoded = substr($encoded, 0, -strlen($linebreak));
Scott committed
2891 2892 2893 2894 2895 2896 2897 2898 2899 2900
        return $encoded;
    }

    /**
     * Encode a string in quoted-printable format.
     * According to RFC2045 section 6.7.
     * @access public
     * @param string $string The text to encode
     * @param integer $line_max Number of chars allowed on a line before wrapping
     * @return string
Scott committed
2901
     * @link http://www.php.net/manual/en/function.quoted-printable-decode.php#89417 Adapted from this comment
Scott committed
2902 2903 2904
     */
    public function encodeQP($string, $line_max = 76)
    {
Scott committed
2905 2906 2907
        // Use native function if it's available (>= PHP5.3)
        if (function_exists('quoted_printable_encode')) {
            return quoted_printable_encode($string);
Scott committed
2908
        }
Scott committed
2909
        // Fall back to a pure PHP implementation
Scott committed
2910 2911 2912 2913 2914
        $string = str_replace(
            array('%20', '%0D%0A.', '%0D%0A', '%'),
            array(' ', "\r\n=2E", "\r\n", '='),
            rawurlencode($string)
        );
Scott committed
2915
        return preg_replace('/[^\r\n]{' . ($line_max - 3) . '}[^=\r\n]{2}/', "$0=\r\n", $string);
Scott committed
2916 2917 2918 2919 2920 2921 2922 2923
    }

    /**
     * Backward compatibility wrapper for an old QP encoding function that was removed.
     * @see PHPMailer::encodeQP()
     * @access public
     * @param string $string
     * @param integer $line_max
Scott committed
2924
     * @param boolean $space_conv
Scott committed
2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945
     * @return string
     * @deprecated Use encodeQP instead.
     */
    public function encodeQPphp(
        $string,
        $line_max = 76,
        /** @noinspection PhpUnusedParameterInspection */ $space_conv = false
    ) {
        return $this->encodeQP($string, $line_max);
    }

    /**
     * Encode a string using Q encoding.
     * @link http://tools.ietf.org/html/rfc2047
     * @param string $str the text to encode
     * @param string $position Where the text is going to be used, see the RFC for what that means
     * @access public
     * @return string
     */
    public function encodeQ($str, $position = 'text')
    {
Scott committed
2946
        // There should not be any EOL in the string
Scott committed
2947 2948 2949 2950
        $pattern = '';
        $encoded = str_replace(array("\r", "\n"), '', $str);
        switch (strtolower($position)) {
            case 'phrase':
Scott committed
2951
                // RFC 2047 section 5.3
Scott committed
2952 2953 2954 2955
                $pattern = '^A-Za-z0-9!*+\/ -';
                break;
            /** @noinspection PhpMissingBreakStatementInspection */
            case 'comment':
Scott committed
2956
                // RFC 2047 section 5.2
Scott committed
2957
                $pattern = '\(\)"';
Scott committed
2958 2959
                // intentional fall-through
                // for this reason we build the $pattern without including delimiters and []
Scott committed
2960 2961
            case 'text':
            default:
Scott committed
2962 2963
                // RFC 2047 section 5.1
                // Replace every high ascii, control, =, ? and _ characters
Scott committed
2964 2965 2966 2967 2968
                $pattern = '\000-\011\013\014\016-\037\075\077\137\177-\377' . $pattern;
                break;
        }
        $matches = array();
        if (preg_match_all("/[{$pattern}]/", $encoded, $matches)) {
Scott committed
2969 2970 2971 2972 2973
            // If the string contains an '=', make sure it's the first thing we replace
            // so as to avoid double-encoding
            $eqkey = array_search('=', $matches[0]);
            if (false !== $eqkey) {
                unset($matches[0][$eqkey]);
Scott committed
2974 2975 2976 2977 2978 2979
                array_unshift($matches[0], '=');
            }
            foreach (array_unique($matches[0]) as $char) {
                $encoded = str_replace($char, '=' . sprintf('%02X', ord($char)), $encoded);
            }
        }
Scott committed
2980
        // Replace every spaces to _ (more readable than =20)
Scott committed
2981 2982 2983 2984 2985 2986 2987 2988 2989 2990 2991 2992 2993 2994 2995 2996 2997 2998 2999 3000 3001
        return str_replace(' ', '_', $encoded);
    }

    /**
     * Add a string or binary attachment (non-filesystem).
     * This method can be used to attach ascii or binary data,
     * such as a BLOB record from a database.
     * @param string $string String attachment data.
     * @param string $filename Name of the attachment.
     * @param string $encoding File encoding (see $Encoding).
     * @param string $type File extension (MIME) type.
     * @param string $disposition Disposition to use
     * @return void
     */
    public function addStringAttachment(
        $string,
        $filename,
        $encoding = 'base64',
        $type = '',
        $disposition = 'attachment'
    ) {
Scott committed
3002
        // If a MIME type is not specified, try to work it out from the file name
Scott committed
3003 3004 3005 3006 3007 3008 3009 3010 3011 3012 3013 3014 3015 3016 3017 3018 3019 3020 3021
        if ($type == '') {
            $type = self::filenameToType($filename);
        }
        // Append to $attachment array
        $this->attachment[] = array(
            0 => $string,
            1 => $filename,
            2 => basename($filename),
            3 => $encoding,
            4 => $type,
            5 => true, // isStringAttachment
            6 => $disposition,
            7 => 0
        );
    }

    /**
     * Add an embedded (inline) attachment from a file.
     * This can include images, sounds, and just about any other document type.
Scott committed
3022
     * These differ from 'regular' attachments in that they are intended to be
Scott committed
3023 3024 3025
     * displayed inline with the message, not just attached for download.
     * This is used in HTML messages that embed the images
     * the HTML refers to using the $cid value.
ProThoughts committed
3026
     * Never use a user-supplied path to a file!
Scott committed
3027 3028 3029 3030 3031 3032 3033
     * @param string $path Path to the attachment.
     * @param string $cid Content ID of the attachment; Use this to reference
     *        the content when using an embedded image in HTML.
     * @param string $name Overrides the attachment name.
     * @param string $encoding File encoding (see $Encoding).
     * @param string $type File MIME type.
     * @param string $disposition Disposition to use
Scott committed
3034
     * @return boolean True on successfully adding an attachment
Scott committed
3035 3036 3037 3038 3039 3040 3041 3042
     */
    public function addEmbeddedImage($path, $cid, $name = '', $encoding = 'base64', $type = '', $disposition = 'inline')
    {
        if (!@is_file($path)) {
            $this->setError($this->lang('file_access') . $path);
            return false;
        }

Scott committed
3043
        // If a MIME type is not specified, try to work it out from the file name
Scott committed
3044 3045 3046 3047 3048 3049 3050 3051 3052 3053 3054 3055 3056 3057 3058 3059 3060 3061 3062 3063 3064 3065 3066 3067 3068 3069 3070 3071 3072 3073 3074 3075 3076 3077 3078
        if ($type == '') {
            $type = self::filenameToType($path);
        }

        $filename = basename($path);
        if ($name == '') {
            $name = $filename;
        }

        // Append to $attachment array
        $this->attachment[] = array(
            0 => $path,
            1 => $filename,
            2 => $name,
            3 => $encoding,
            4 => $type,
            5 => false, // isStringAttachment
            6 => $disposition,
            7 => $cid
        );
        return true;
    }

    /**
     * Add an embedded stringified attachment.
     * This can include images, sounds, and just about any other document type.
     * Be sure to set the $type to an image type for images:
     * JPEG images use 'image/jpeg', GIF uses 'image/gif', PNG uses 'image/png'.
     * @param string $string The attachment binary data.
     * @param string $cid Content ID of the attachment; Use this to reference
     *        the content when using an embedded image in HTML.
     * @param string $name
     * @param string $encoding File encoding (see $Encoding).
     * @param string $type MIME type.
     * @param string $disposition Disposition to use
Scott committed
3079
     * @return boolean True on successfully adding an attachment
Scott committed
3080 3081 3082 3083 3084 3085 3086 3087 3088
     */
    public function addStringEmbeddedImage(
        $string,
        $cid,
        $name = '',
        $encoding = 'base64',
        $type = '',
        $disposition = 'inline'
    ) {
Scott committed
3089 3090
        // If a MIME type is not specified, try to work it out from the name
        if ($type == '' and !empty($name)) {
Scott committed
3091 3092 3093 3094 3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105 3106 3107 3108 3109 3110
            $type = self::filenameToType($name);
        }

        // Append to $attachment array
        $this->attachment[] = array(
            0 => $string,
            1 => $name,
            2 => $name,
            3 => $encoding,
            4 => $type,
            5 => true, // isStringAttachment
            6 => $disposition,
            7 => $cid
        );
        return true;
    }

    /**
     * Check if an inline attachment is present.
     * @access public
Scott committed
3111
     * @return boolean
Scott committed
3112 3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123 3124
     */
    public function inlineImageExists()
    {
        foreach ($this->attachment as $attachment) {
            if ($attachment[6] == 'inline') {
                return true;
            }
        }
        return false;
    }

    /**
     * Check if an attachment (non-inline) is present.
Scott committed
3125
     * @return boolean
Scott committed
3126 3127 3128 3129 3130 3131 3132 3133 3134 3135 3136 3137 3138
     */
    public function attachmentExists()
    {
        foreach ($this->attachment as $attachment) {
            if ($attachment[6] == 'attachment') {
                return true;
            }
        }
        return false;
    }

    /**
     * Check if this message has an alternative body set.
Scott committed
3139
     * @return boolean
Scott committed
3140 3141 3142 3143 3144 3145
     */
    public function alternativeExists()
    {
        return !empty($this->AltBody);
    }

Scott committed
3146 3147 3148 3149 3150 3151 3152 3153 3154 3155 3156 3157 3158 3159 3160 3161
    /**
     * Clear queued addresses of given kind.
     * @access protected
     * @param string $kind 'to', 'cc', or 'bcc'
     * @return void
     */
    public function clearQueuedAddresses($kind)
    {
        $RecipientsQueue = $this->RecipientsQueue;
        foreach ($RecipientsQueue as $address => $params) {
            if ($params[0] == $kind) {
                unset($this->RecipientsQueue[$address]);
            }
        }
    }

Scott committed
3162 3163 3164 3165 3166 3167 3168 3169 3170 3171
    /**
     * Clear all To recipients.
     * @return void
     */
    public function clearAddresses()
    {
        foreach ($this->to as $to) {
            unset($this->all_recipients[strtolower($to[0])]);
        }
        $this->to = array();
Scott committed
3172
        $this->clearQueuedAddresses('to');
Scott committed
3173 3174 3175 3176 3177 3178 3179 3180 3181 3182 3183 3184
    }

    /**
     * Clear all CC recipients.
     * @return void
     */
    public function clearCCs()
    {
        foreach ($this->cc as $cc) {
            unset($this->all_recipients[strtolower($cc[0])]);
        }
        $this->cc = array();
Scott committed
3185
        $this->clearQueuedAddresses('cc');
Scott committed
3186 3187 3188 3189 3190 3191 3192 3193 3194 3195 3196 3197
    }

    /**
     * Clear all BCC recipients.
     * @return void
     */
    public function clearBCCs()
    {
        foreach ($this->bcc as $bcc) {
            unset($this->all_recipients[strtolower($bcc[0])]);
        }
        $this->bcc = array();
Scott committed
3198
        $this->clearQueuedAddresses('bcc');
Scott committed
3199 3200 3201 3202 3203 3204 3205 3206 3207
    }

    /**
     * Clear all ReplyTo recipients.
     * @return void
     */
    public function clearReplyTos()
    {
        $this->ReplyTo = array();
Scott committed
3208
        $this->ReplyToQueue = array();
Scott committed
3209 3210 3211 3212 3213 3214 3215 3216 3217 3218 3219 3220
    }

    /**
     * Clear all recipient types.
     * @return void
     */
    public function clearAllRecipients()
    {
        $this->to = array();
        $this->cc = array();
        $this->bcc = array();
        $this->all_recipients = array();
Scott committed
3221
        $this->RecipientsQueue = array();
Scott committed
3222 3223 3224 3225 3226 3227 3228 3229 3230 3231 3232 3233 3234 3235 3236 3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252
    }

    /**
     * Clear all filesystem, string, and binary attachments.
     * @return void
     */
    public function clearAttachments()
    {
        $this->attachment = array();
    }

    /**
     * Clear all custom headers.
     * @return void
     */
    public function clearCustomHeaders()
    {
        $this->CustomHeader = array();
    }

    /**
     * Add an error message to the error container.
     * @access protected
     * @param string $msg
     * @return void
     */
    protected function setError($msg)
    {
        $this->error_count++;
        if ($this->Mailer == 'smtp' and !is_null($this->smtp)) {
            $lasterror = $this->smtp->getError();
Scott committed
3253 3254 3255 3256 3257 3258 3259 3260 3261 3262 3263
            if (!empty($lasterror['error'])) {
                $msg .= $this->lang('smtp_error') . $lasterror['error'];
                if (!empty($lasterror['detail'])) {
                    $msg .= ' Detail: '. $lasterror['detail'];
                }
                if (!empty($lasterror['smtp_code'])) {
                    $msg .= ' SMTP code: ' . $lasterror['smtp_code'];
                }
                if (!empty($lasterror['smtp_code_ex'])) {
                    $msg .= ' Additional SMTP info: ' . $lasterror['smtp_code_ex'];
                }
Scott committed
3264 3265 3266 3267 3268 3269 3270 3271 3272 3273 3274 3275 3276
            }
        }
        $this->ErrorInfo = $msg;
    }

    /**
     * Return an RFC 822 formatted date.
     * @access public
     * @return string
     * @static
     */
    public static function rfcDate()
    {
Scott committed
3277 3278
        // Set the time zone to whatever the default is to avoid 500 errors
        // Will default to UTC if it's not set properly in php.ini
Scott committed
3279 3280 3281 3282 3283 3284 3285 3286 3287 3288 3289 3290 3291 3292 3293 3294 3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305 3306 3307 3308 3309 3310 3311 3312 3313 3314 3315
        date_default_timezone_set(@date_default_timezone_get());
        return date('D, j M Y H:i:s O');
    }

    /**
     * Get the server hostname.
     * Returns 'localhost.localdomain' if unknown.
     * @access protected
     * @return string
     */
    protected function serverHostname()
    {
        $result = 'localhost.localdomain';
        if (!empty($this->Hostname)) {
            $result = $this->Hostname;
        } elseif (isset($_SERVER) and array_key_exists('SERVER_NAME', $_SERVER) and !empty($_SERVER['SERVER_NAME'])) {
            $result = $_SERVER['SERVER_NAME'];
        } elseif (function_exists('gethostname') && gethostname() !== false) {
            $result = gethostname();
        } elseif (php_uname('n') !== false) {
            $result = php_uname('n');
        }
        return $result;
    }

    /**
     * Get an error message in the current language.
     * @access protected
     * @param string $key
     * @return string
     */
    protected function lang($key)
    {
        if (count($this->language) < 1) {
            $this->setLanguage('en'); // set the default language
        }

Scott committed
3316 3317 3318 3319 3320 3321 3322
        if (array_key_exists($key, $this->language)) {
            if ($key == 'smtp_connect_failed') {
                //Include a link to troubleshooting docs on SMTP connection failure
                //this is by far the biggest cause of support questions
                //but it's usually not PHPMailer's fault.
                return $this->language[$key] . ' https://github.com/PHPMailer/PHPMailer/wiki/Troubleshooting';
            }
Scott committed
3323 3324
            return $this->language[$key];
        } else {
Scott committed
3325 3326
            //Return the key as a fallback
            return $key;
Scott committed
3327 3328 3329 3330 3331 3332
        }
    }

    /**
     * Check if an error occurred.
     * @access public
Scott committed
3333
     * @return boolean True if an error did occur.
Scott committed
3334 3335 3336 3337 3338 3339 3340 3341 3342 3343 3344 3345 3346 3347 3348 3349 3350 3351 3352 3353 3354 3355 3356 3357 3358 3359 3360 3361 3362 3363 3364 3365 3366 3367 3368 3369 3370 3371 3372 3373 3374 3375 3376
     */
    public function isError()
    {
        return ($this->error_count > 0);
    }

    /**
     * Ensure consistent line endings in a string.
     * Changes every end of line from CRLF, CR or LF to $this->LE.
     * @access public
     * @param string $str String to fixEOL
     * @return string
     */
    public function fixEOL($str)
    {
        // Normalise to \n
        $nstr = str_replace(array("\r\n", "\r"), "\n", $str);
        // Now convert LE as needed
        if ($this->LE !== "\n") {
            $nstr = str_replace("\n", $this->LE, $nstr);
        }
        return $nstr;
    }

    /**
     * Add a custom header.
     * $name value can be overloaded to contain
     * both header name and value (name:value)
     * @access public
     * @param string $name Custom header name
     * @param string $value Header value
     * @return void
     */
    public function addCustomHeader($name, $value = null)
    {
        if ($value === null) {
            // Value passed in as name:value
            $this->CustomHeader[] = explode(':', $name, 2);
        } else {
            $this->CustomHeader[] = array($name, $value);
        }
    }

Scott committed
3377
    /**
Scott committed
3378
     * Returns all custom headers.
Scott committed
3379 3380 3381 3382 3383 3384 3385
     * @return array
     */
    public function getCustomHeaders()
    {
        return $this->CustomHeader;
    }

Scott committed
3386
    /**
ProThoughts committed
3387 3388 3389 3390 3391 3392 3393 3394
     * Create a message body from an HTML string.
     * Automatically inlines images and creates a plain-text version by converting the HTML,
     * overwriting any existing values in Body and AltBody.
     * Do not source $message content from user input!
     * $basedir is prepended when handling relative URLs, e.g. <img src="/images/a.png"> and must not be empty
     * will look for an image file in $basedir/images/a.png and convert it to inline.
     * If you don't provide a $basedir, relative paths will be left untouched (and thus probably break in email)
     * If you don't want to apply these transformations to your HTML, just set Body and AltBody directly.
Scott committed
3395 3396
     * @access public
     * @param string $message HTML message string
ProThoughts committed
3397
     * @param string $basedir Absolute path to a base directory to prepend to relative paths to images
Scott committed
3398
     * @param boolean|callable $advanced Whether to use the internal HTML to text converter
Scott committed
3399
     *    or your own custom converter @see PHPMailer::html2text()
ProThoughts committed
3400
     * @return string $message The transformed message Body
Scott committed
3401 3402 3403
     */
    public function msgHTML($message, $basedir = '', $advanced = false)
    {
Scott committed
3404
        preg_match_all('/(src|background)=["\'](.*)["\']/Ui', $message, $images);
Scott committed
3405
        if (array_key_exists(2, $images)) {
ProThoughts committed
3406 3407 3408 3409
            if (strlen($basedir) > 1 && substr($basedir, -1) != '/') {
                // Ensure $basedir has a trailing /
                $basedir .= '/';
            }
Scott committed
3410 3411 3412 3413 3414 3415 3416 3417 3418 3419 3420 3421 3422 3423 3424 3425 3426
            foreach ($images[2] as $imgindex => $url) {
                // Convert data URIs into embedded images
                if (preg_match('#^data:(image[^;,]*)(;base64)?,#', $url, $match)) {
                    $data = substr($url, strpos($url, ','));
                    if ($match[2]) {
                        $data = base64_decode($data);
                    } else {
                        $data = rawurldecode($data);
                    }
                    $cid = md5($url) . '@phpmailer.0'; // RFC2392 S 2
                    if ($this->addStringEmbeddedImage($data, $cid, 'embed' . $imgindex, 'base64', $match[1])) {
                        $message = str_replace(
                            $images[0][$imgindex],
                            $images[1][$imgindex] . '="cid:' . $cid . '"',
                            $message
                        );
                    }
ProThoughts committed
3427 3428 3429 3430 3431 3432 3433
                    continue;
                }
                if (
                    // Only process relative URLs if a basedir is provided (i.e. no absolute local paths)
                    !empty($basedir)
                    // Ignore URLs containing parent dir traversal (..)
                    && (strpos($url, '..') === false)
Scott committed
3434
                    // Do not change urls that are already inline images
ProThoughts committed
3435 3436 3437 3438
                    && substr($url, 0, 4) !== 'cid:'
                    // Do not change absolute URLs, including anonymous protocol
                    && !preg_match('#^[a-z][a-z0-9+.-]*:?//#i', $url)
                ) {
Scott committed
3439 3440 3441 3442 3443
                    $filename = basename($url);
                    $directory = dirname($url);
                    if ($directory == '.') {
                        $directory = '';
                    }
Scott committed
3444
                    $cid = md5($url) . '@phpmailer.0'; // RFC2392 S 2
Scott committed
3445 3446 3447 3448 3449 3450 3451 3452
                    if (strlen($directory) > 1 && substr($directory, -1) != '/') {
                        $directory .= '/';
                    }
                    if ($this->addEmbeddedImage(
                        $basedir . $directory . $filename,
                        $cid,
                        $filename,
                        'base64',
Scott committed
3453
                        self::_mime_types((string)self::mb_pathinfo($filename, PATHINFO_EXTENSION))
Scott committed
3454 3455 3456
                    )
                    ) {
                        $message = preg_replace(
Scott committed
3457 3458
                            '/' . $images[1][$imgindex] . '=["\']' . preg_quote($url, '/') . '["\']/Ui',
                            $images[1][$imgindex] . '="cid:' . $cid . '"',
Scott committed
3459 3460 3461 3462 3463 3464 3465
                            $message
                        );
                    }
                }
            }
        }
        $this->isHTML(true);
Scott committed
3466
        // Convert all message body line breaks to CRLF, makes quoted-printable encoding work much better
Scott committed
3467 3468
        $this->Body = $this->normalizeBreaks($message);
        $this->AltBody = $this->normalizeBreaks($this->html2text($message, $advanced));
ProThoughts committed
3469
        if (!$this->alternativeExists()) {
Scott committed
3470 3471 3472 3473 3474 3475 3476 3477
            $this->AltBody = 'To view this email message, open it in a program that understands HTML!' .
                self::CRLF . self::CRLF;
        }
        return $this->Body;
    }

    /**
     * Convert an HTML string into plain text.
Scott committed
3478 3479
     * This is used by msgHTML().
     * Note - older versions of this function used a bundled advanced converter
ProThoughts committed
3480
     * which was been removed for license reasons in #232.
Scott committed
3481 3482 3483 3484 3485 3486 3487 3488 3489 3490
     * Example usage:
     * <code>
     * // Use default conversion
     * $plain = $mail->html2text($html);
     * // Use your own custom converter
     * $plain = $mail->html2text($html, function($html) {
     *     $converter = new MyHtml2text($html);
     *     return $converter->get_text();
     * });
     * </code>
Scott committed
3491
     * @param string $html The HTML text to convert
Scott committed
3492 3493
     * @param boolean|callable $advanced Any boolean value to use the internal converter,
     *   or provide your own callable for custom conversion.
Scott committed
3494 3495 3496 3497
     * @return string
     */
    public function html2text($html, $advanced = false)
    {
Scott committed
3498 3499
        if (is_callable($advanced)) {
            return call_user_func($advanced, $html);
Scott committed
3500 3501 3502 3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517
        }
        return html_entity_decode(
            trim(strip_tags(preg_replace('/<(head|title|style|script)[^>]*>.*?<\/\\1>/si', '', $html))),
            ENT_QUOTES,
            $this->CharSet
        );
    }

    /**
     * Get the MIME type for a file extension.
     * @param string $ext File extension
     * @access public
     * @return string MIME type of file.
     * @static
     */
    public static function _mime_types($ext = '')
    {
        $mimes = array(
Scott committed
3518 3519 3520 3521 3522 3523 3524 3525 3526 3527 3528 3529 3530 3531 3532 3533 3534
            'xl'    => 'application/excel',
            'js'    => 'application/javascript',
            'hqx'   => 'application/mac-binhex40',
            'cpt'   => 'application/mac-compactpro',
            'bin'   => 'application/macbinary',
            'doc'   => 'application/msword',
            'word'  => 'application/msword',
            'xlsx'  => 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet',
            'xltx'  => 'application/vnd.openxmlformats-officedocument.spreadsheetml.template',
            'potx'  => 'application/vnd.openxmlformats-officedocument.presentationml.template',
            'ppsx'  => 'application/vnd.openxmlformats-officedocument.presentationml.slideshow',
            'pptx'  => 'application/vnd.openxmlformats-officedocument.presentationml.presentation',
            'sldx'  => 'application/vnd.openxmlformats-officedocument.presentationml.slide',
            'docx'  => 'application/vnd.openxmlformats-officedocument.wordprocessingml.document',
            'dotx'  => 'application/vnd.openxmlformats-officedocument.wordprocessingml.template',
            'xlam'  => 'application/vnd.ms-excel.addin.macroEnabled.12',
            'xlsb'  => 'application/vnd.ms-excel.sheet.binary.macroEnabled.12',
Scott committed
3535
            'class' => 'application/octet-stream',
Scott committed
3536 3537 3538 3539 3540 3541 3542 3543 3544 3545 3546 3547 3548 3549 3550 3551 3552 3553
            'dll'   => 'application/octet-stream',
            'dms'   => 'application/octet-stream',
            'exe'   => 'application/octet-stream',
            'lha'   => 'application/octet-stream',
            'lzh'   => 'application/octet-stream',
            'psd'   => 'application/octet-stream',
            'sea'   => 'application/octet-stream',
            'so'    => 'application/octet-stream',
            'oda'   => 'application/oda',
            'pdf'   => 'application/pdf',
            'ai'    => 'application/postscript',
            'eps'   => 'application/postscript',
            'ps'    => 'application/postscript',
            'smi'   => 'application/smil',
            'smil'  => 'application/smil',
            'mif'   => 'application/vnd.mif',
            'xls'   => 'application/vnd.ms-excel',
            'ppt'   => 'application/vnd.ms-powerpoint',
Scott committed
3554
            'wbxml' => 'application/vnd.wap.wbxml',
Scott committed
3555 3556 3557 3558 3559 3560 3561 3562 3563
            'wmlc'  => 'application/vnd.wap.wmlc',
            'dcr'   => 'application/x-director',
            'dir'   => 'application/x-director',
            'dxr'   => 'application/x-director',
            'dvi'   => 'application/x-dvi',
            'gtar'  => 'application/x-gtar',
            'php3'  => 'application/x-httpd-php',
            'php4'  => 'application/x-httpd-php',
            'php'   => 'application/x-httpd-php',
Scott committed
3564
            'phtml' => 'application/x-httpd-php',
Scott committed
3565 3566 3567 3568 3569 3570
            'phps'  => 'application/x-httpd-php-source',
            'swf'   => 'application/x-shockwave-flash',
            'sit'   => 'application/x-stuffit',
            'tar'   => 'application/x-tar',
            'tgz'   => 'application/x-tar',
            'xht'   => 'application/xhtml+xml',
Scott committed
3571
            'xhtml' => 'application/xhtml+xml',
Scott committed
3572 3573 3574 3575 3576 3577 3578 3579 3580 3581 3582 3583 3584 3585 3586 3587 3588 3589 3590 3591 3592 3593 3594 3595 3596 3597
            'zip'   => 'application/zip',
            'mid'   => 'audio/midi',
            'midi'  => 'audio/midi',
            'mp2'   => 'audio/mpeg',
            'mp3'   => 'audio/mpeg',
            'mpga'  => 'audio/mpeg',
            'aif'   => 'audio/x-aiff',
            'aifc'  => 'audio/x-aiff',
            'aiff'  => 'audio/x-aiff',
            'ram'   => 'audio/x-pn-realaudio',
            'rm'    => 'audio/x-pn-realaudio',
            'rpm'   => 'audio/x-pn-realaudio-plugin',
            'ra'    => 'audio/x-realaudio',
            'wav'   => 'audio/x-wav',
            'bmp'   => 'image/bmp',
            'gif'   => 'image/gif',
            'jpeg'  => 'image/jpeg',
            'jpe'   => 'image/jpeg',
            'jpg'   => 'image/jpeg',
            'png'   => 'image/png',
            'tiff'  => 'image/tiff',
            'tif'   => 'image/tiff',
            'eml'   => 'message/rfc822',
            'css'   => 'text/css',
            'html'  => 'text/html',
            'htm'   => 'text/html',
Scott committed
3598
            'shtml' => 'text/html',
Scott committed
3599 3600 3601 3602 3603 3604 3605 3606 3607 3608 3609 3610 3611 3612 3613 3614
            'log'   => 'text/plain',
            'text'  => 'text/plain',
            'txt'   => 'text/plain',
            'rtx'   => 'text/richtext',
            'rtf'   => 'text/rtf',
            'vcf'   => 'text/vcard',
            'vcard' => 'text/vcard',
            'xml'   => 'text/xml',
            'xsl'   => 'text/xml',
            'mpeg'  => 'video/mpeg',
            'mpe'   => 'video/mpeg',
            'mpg'   => 'video/mpeg',
            'mov'   => 'video/quicktime',
            'qt'    => 'video/quicktime',
            'rv'    => 'video/vnd.rn-realvideo',
            'avi'   => 'video/x-msvideo',
Scott committed
3615 3616
            'movie' => 'video/x-sgi-movie'
        );
Scott committed
3617 3618 3619 3620
        if (array_key_exists(strtolower($ext), $mimes)) {
            return $mimes[strtolower($ext)];
        }
        return 'application/octet-stream';
Scott committed
3621 3622 3623 3624 3625 3626 3627 3628 3629 3630 3631
    }

    /**
     * Map a file name to a MIME type.
     * Defaults to 'application/octet-stream', i.e.. arbitrary binary data.
     * @param string $filename A file name or full path, does not need to exist as a file
     * @return string
     * @static
     */
    public static function filenameToType($filename)
    {
Scott committed
3632
        // In case the path is a URL, strip any query string before getting extension
Scott committed
3633
        $qpos = strpos($filename, '?');
Scott committed
3634
        if (false !== $qpos) {
Scott committed
3635 3636 3637 3638 3639 3640 3641 3642 3643 3644 3645 3646 3647 3648 3649 3650 3651 3652 3653 3654
            $filename = substr($filename, 0, $qpos);
        }
        $pathinfo = self::mb_pathinfo($filename);
        return self::_mime_types($pathinfo['extension']);
    }

    /**
     * Multi-byte-safe pathinfo replacement.
     * Drop-in replacement for pathinfo(), but multibyte-safe, cross-platform-safe, old-version-safe.
     * Works similarly to the one in PHP >= 5.2.0
     * @link http://www.php.net/manual/en/function.pathinfo.php#107461
     * @param string $path A filename or path, does not need to exist as a file
     * @param integer|string $options Either a PATHINFO_* constant,
     *      or a string name to return only the specified piece, allows 'filename' to work on PHP < 5.2
     * @return string|array
     * @static
     */
    public static function mb_pathinfo($path, $options = null)
    {
        $ret = array('dirname' => '', 'basename' => '', 'extension' => '', 'filename' => '');
Scott committed
3655 3656 3657 3658 3659 3660 3661 3662 3663 3664 3665 3666 3667 3668
        $pathinfo = array();
        if (preg_match('%^(.*?)[\\\\/]*(([^/\\\\]*?)(\.([^\.\\\\/]+?)|))[\\\\/\.]*$%im', $path, $pathinfo)) {
            if (array_key_exists(1, $pathinfo)) {
                $ret['dirname'] = $pathinfo[1];
            }
            if (array_key_exists(2, $pathinfo)) {
                $ret['basename'] = $pathinfo[2];
            }
            if (array_key_exists(5, $pathinfo)) {
                $ret['extension'] = $pathinfo[5];
            }
            if (array_key_exists(3, $pathinfo)) {
                $ret['filename'] = $pathinfo[3];
            }
Scott committed
3669 3670 3671 3672 3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689
        }
        switch ($options) {
            case PATHINFO_DIRNAME:
            case 'dirname':
                return $ret['dirname'];
            case PATHINFO_BASENAME:
            case 'basename':
                return $ret['basename'];
            case PATHINFO_EXTENSION:
            case 'extension':
                return $ret['extension'];
            case PATHINFO_FILENAME:
            case 'filename':
                return $ret['filename'];
            default:
                return $ret;
        }
    }

    /**
     * Set or reset instance properties.
Scott committed
3690 3691
     * You should avoid this function - it's more verbose, less efficient, more error-prone and
     * harder to debug than setting properties directly.
Scott committed
3692
     * Usage Example:
Scott committed
3693 3694 3695
     * `$mail->set('SMTPSecure', 'tls');`
     *   is the same as:
     * `$mail->SMTPSecure = 'tls';`
Scott committed
3696
     * @access public
Scott committed
3697 3698 3699 3700
     * @param string $name The property name to set
     * @param mixed $value The value to set the property to
     * @return boolean
     * @TODO Should this not be using the __set() magic function?
Scott committed
3701 3702 3703
     */
    public function set($name, $value = '')
    {
Scott committed
3704 3705 3706 3707 3708 3709
        if (property_exists($this, $name)) {
            $this->$name = $value;
            return true;
        } else {
            $this->setError($this->lang('variable_set') . $name);
            return false;
Scott committed
3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726 3727 3728 3729 3730 3731 3732 3733 3734 3735 3736 3737 3738 3739 3740 3741 3742 3743 3744
        }
    }

    /**
     * Strip newlines to prevent header injection.
     * @access public
     * @param string $str
     * @return string
     */
    public function secureHeader($str)
    {
        return trim(str_replace(array("\r", "\n"), '', $str));
    }

    /**
     * Normalize line breaks in a string.
     * Converts UNIX LF, Mac CR and Windows CRLF line breaks into a single line break format.
     * Defaults to CRLF (for message bodies) and preserves consecutive breaks.
     * @param string $text
     * @param string $breaktype What kind of line break to use, defaults to CRLF
     * @return string
     * @access public
     * @static
     */
    public static function normalizeBreaks($text, $breaktype = "\r\n")
    {
        return preg_replace('/(\r\n|\r|\n)/ms', $breaktype, $text);
    }

    /**
     * Set the public and private key files and password for S/MIME signing.
     * @access public
     * @param string $cert_filename
     * @param string $key_filename
     * @param string $key_pass Password for private key
Scott committed
3745
     * @param string $extracerts_filename Optional path to chain certificate
Scott committed
3746
     */
Scott committed
3747
    public function sign($cert_filename, $key_filename, $key_pass, $extracerts_filename = '')
Scott committed
3748 3749 3750 3751
    {
        $this->sign_cert_file = $cert_filename;
        $this->sign_key_file = $key_filename;
        $this->sign_key_pass = $key_pass;
Scott committed
3752
        $this->sign_extracerts_file = $extracerts_filename;
Scott committed
3753 3754 3755 3756 3757 3758 3759 3760 3761 3762 3763 3764 3765 3766 3767 3768
    }

    /**
     * Quoted-Printable-encode a DKIM header.
     * @access public
     * @param string $txt
     * @return string
     */
    public function DKIM_QP($txt)
    {
        $line = '';
        for ($i = 0; $i < strlen($txt); $i++) {
            $ord = ord($txt[$i]);
            if (((0x21 <= $ord) && ($ord <= 0x3A)) || $ord == 0x3C || ((0x3E <= $ord) && ($ord <= 0x7E))) {
                $line .= $txt[$i];
            } else {
Scott committed
3769
                $line .= '=' . sprintf('%02X', $ord);
Scott committed
3770 3771 3772 3773 3774 3775 3776 3777
            }
        }
        return $line;
    }

    /**
     * Generate a DKIM signature.
     * @access public
Scott committed
3778
     * @param string $signHeader
Scott committed
3779
     * @throws phpmailerException
ProThoughts committed
3780
     * @return string The DKIM signature value
Scott committed
3781
     */
Scott committed
3782
    public function DKIM_Sign($signHeader)
Scott committed
3783 3784 3785
    {
        if (!defined('PKCS7_TEXT')) {
            if ($this->exceptions) {
Scott committed
3786
                throw new phpmailerException($this->lang('extension_missing') . 'openssl');
Scott committed
3787 3788 3789
            }
            return '';
        }
ProThoughts committed
3790 3791
        $privKeyStr = !empty($this->DKIM_private_string) ? $this->DKIM_private_string : file_get_contents($this->DKIM_private);
        if ('' != $this->DKIM_passphrase) {
Scott committed
3792 3793
            $privKey = openssl_pkey_get_private($privKeyStr, $this->DKIM_passphrase);
        } else {
ProThoughts committed
3794
            $privKey = openssl_pkey_get_private($privKeyStr);
Scott committed
3795
        }
ProThoughts committed
3796 3797 3798 3799 3800 3801 3802 3803 3804 3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816
        //Workaround for missing digest algorithms in old PHP & OpenSSL versions
        //@link http://stackoverflow.com/a/11117338/333340
        if (version_compare(PHP_VERSION, '5.3.0') >= 0 and
            in_array('sha256WithRSAEncryption', openssl_get_md_methods(true))) {
            if (openssl_sign($signHeader, $signature, $privKey, 'sha256WithRSAEncryption')) {
                openssl_pkey_free($privKey);
                return base64_encode($signature);
            }
        } else {
            $pinfo = openssl_pkey_get_details($privKey);
            $hash = hash('sha256', $signHeader);
            //'Magic' constant for SHA256 from RFC3447
            //@link https://tools.ietf.org/html/rfc3447#page-43
            $t = '3031300d060960864801650304020105000420' . $hash;
            $pslen = $pinfo['bits'] / 8 - (strlen($t) / 2 + 3);
            $eb = pack('H*', '0001' . str_repeat('FF', $pslen) . '00' . $t);

            if (openssl_private_encrypt($eb, $signature, $privKey, OPENSSL_NO_PADDING)) {
                openssl_pkey_free($privKey);
                return base64_encode($signature);
            }
Scott committed
3817
        }
ProThoughts committed
3818
        openssl_pkey_free($privKey);
Scott committed
3819 3820 3821 3822 3823 3824
        return '';
    }

    /**
     * Generate a DKIM canonicalization header.
     * @access public
Scott committed
3825
     * @param string $signHeader Header
Scott committed
3826 3827
     * @return string
     */
Scott committed
3828
    public function DKIM_HeaderC($signHeader)
Scott committed
3829
    {
Scott committed
3830 3831
        $signHeader = preg_replace('/\r\n\s+/', ' ', $signHeader);
        $lines = explode("\r\n", $signHeader);
Scott committed
3832
        foreach ($lines as $key => $line) {
Scott committed
3833
            list($heading, $value) = explode(':', $line, 2);
Scott committed
3834
            $heading = strtolower($heading);
ProThoughts committed
3835
            $value = preg_replace('/\s{2,}/', ' ', $value); // Compress useless spaces
Scott committed
3836
            $lines[$key] = $heading . ':' . trim($value); // Don't forget to remove WSP around the value
Scott committed
3837
        }
Scott committed
3838 3839
        $signHeader = implode("\r\n", $lines);
        return $signHeader;
Scott committed
3840 3841 3842 3843 3844 3845 3846 3847 3848 3849 3850 3851 3852 3853 3854 3855 3856 3857 3858 3859 3860 3861 3862 3863 3864 3865 3866 3867 3868 3869 3870 3871 3872
    }

    /**
     * Generate a DKIM canonicalization body.
     * @access public
     * @param string $body Message Body
     * @return string
     */
    public function DKIM_BodyC($body)
    {
        if ($body == '') {
            return "\r\n";
        }
        // stabilize line endings
        $body = str_replace("\r\n", "\n", $body);
        $body = str_replace("\n", "\r\n", $body);
        // END stabilize line endings
        while (substr($body, strlen($body) - 4, 4) == "\r\n\r\n") {
            $body = substr($body, 0, strlen($body) - 2);
        }
        return $body;
    }

    /**
     * Create the DKIM header and body in a new message header.
     * @access public
     * @param string $headers_line Header lines
     * @param string $subject Subject
     * @param string $body Body
     * @return string
     */
    public function DKIM_Add($headers_line, $subject, $body)
    {
ProThoughts committed
3873
        $DKIMsignatureType = 'rsa-sha256'; // Signature & hash algorithms
Scott committed
3874 3875 3876 3877 3878 3879 3880
        $DKIMcanonicalization = 'relaxed/simple'; // Canonicalization of header/body
        $DKIMquery = 'dns/txt'; // Query method
        $DKIMtime = time(); // Signature Timestamp = seconds since 00:00:00 - Jan 1, 1970 (UTC time zone)
        $subject_header = "Subject: $subject";
        $headers = explode($this->LE, $headers_line);
        $from_header = '';
        $to_header = '';
ProThoughts committed
3881
        $date_header = '';
Scott committed
3882 3883 3884 3885 3886 3887 3888 3889
        $current = '';
        foreach ($headers as $header) {
            if (strpos($header, 'From:') === 0) {
                $from_header = $header;
                $current = 'from_header';
            } elseif (strpos($header, 'To:') === 0) {
                $to_header = $header;
                $current = 'to_header';
ProThoughts committed
3890 3891 3892
            } elseif (strpos($header, 'Date:') === 0) {
                $date_header = $header;
                $current = 'date_header';
Scott committed
3893
            } else {
Scott committed
3894 3895
                if (!empty($$current) && strpos($header, ' =?') === 0) {
                    $$current .= $header;
Scott committed
3896 3897 3898 3899 3900 3901 3902
                } else {
                    $current = '';
                }
            }
        }
        $from = str_replace('|', '=7C', $this->DKIM_QP($from_header));
        $to = str_replace('|', '=7C', $this->DKIM_QP($to_header));
ProThoughts committed
3903
        $date = str_replace('|', '=7C', $this->DKIM_QP($date_header));
Scott committed
3904 3905 3906 3907 3908 3909 3910
        $subject = str_replace(
            '|',
            '=7C',
            $this->DKIM_QP($subject_header)
        ); // Copied header fields (dkim-quoted-printable)
        $body = $this->DKIM_BodyC($body);
        $DKIMlen = strlen($body); // Length of body
ProThoughts committed
3911
        $DKIMb64 = base64_encode(pack('H*', hash('sha256', $body))); // Base64 of packed binary SHA-256 hash of body
Scott committed
3912 3913 3914 3915 3916 3917 3918 3919 3920
        if ('' == $this->DKIM_identity) {
            $ident = '';
        } else {
            $ident = ' i=' . $this->DKIM_identity . ';';
        }
        $dkimhdrs = 'DKIM-Signature: v=1; a=' .
            $DKIMsignatureType . '; q=' .
            $DKIMquery . '; l=' .
            $DKIMlen . '; s=' .
Scott committed
3921 3922
            $this->DKIM_selector .
            ";\r\n" .
Scott committed
3923
            "\tt=" . $DKIMtime . '; c=' . $DKIMcanonicalization . ";\r\n" .
ProThoughts committed
3924
            "\th=From:To:Date:Subject;\r\n" .
Scott committed
3925
            "\td=" . $this->DKIM_domain . ';' . $ident . "\r\n" .
Scott committed
3926 3927
            "\tz=$from\r\n" .
            "\t|$to\r\n" .
ProThoughts committed
3928
            "\t|$date\r\n" .
Scott committed
3929 3930 3931 3932
            "\t|$subject;\r\n" .
            "\tbh=" . $DKIMb64 . ";\r\n" .
            "\tb=";
        $toSign = $this->DKIM_HeaderC(
Scott committed
3933 3934
            $from_header . "\r\n" .
            $to_header . "\r\n" .
ProThoughts committed
3935
            $date_header . "\r\n" .
Scott committed
3936 3937
            $subject_header . "\r\n" .
            $dkimhdrs
Scott committed
3938 3939 3940 3941 3942
        );
        $signed = $this->DKIM_Sign($toSign);
        return $dkimhdrs . $signed . "\r\n";
    }

Scott committed
3943 3944 3945 3946 3947 3948 3949 3950 3951 3952 3953 3954
    /**
     * Detect if a string contains a line longer than the maximum line length allowed.
     * @param string $str
     * @return boolean
     * @static
     */
    public static function hasLineLongerThanMax($str)
    {
        //+2 to include CRLF line break for a 1000 total
        return (boolean)preg_match('/^(.{'.(self::MAX_LINE_LENGTH + 2).',})/m', $str);
    }

Scott committed
3955 3956
    /**
     * Allows for public read access to 'to' property.
Scott committed
3957
     * @note: Before the send() call, queued addresses (i.e. with IDN) are not yet included.
Scott committed
3958 3959 3960 3961 3962 3963 3964 3965 3966 3967
     * @access public
     * @return array
     */
    public function getToAddresses()
    {
        return $this->to;
    }

    /**
     * Allows for public read access to 'cc' property.
Scott committed
3968
     * @note: Before the send() call, queued addresses (i.e. with IDN) are not yet included.
Scott committed
3969 3970 3971 3972 3973 3974 3975 3976 3977 3978
     * @access public
     * @return array
     */
    public function getCcAddresses()
    {
        return $this->cc;
    }

    /**
     * Allows for public read access to 'bcc' property.
Scott committed
3979
     * @note: Before the send() call, queued addresses (i.e. with IDN) are not yet included.
Scott committed
3980 3981 3982 3983 3984 3985 3986 3987 3988 3989
     * @access public
     * @return array
     */
    public function getBccAddresses()
    {
        return $this->bcc;
    }

    /**
     * Allows for public read access to 'ReplyTo' property.
Scott committed
3990
     * @note: Before the send() call, queued addresses (i.e. with IDN) are not yet included.
Scott committed
3991 3992 3993 3994 3995 3996 3997 3998 3999 4000
     * @access public
     * @return array
     */
    public function getReplyToAddresses()
    {
        return $this->ReplyTo;
    }

    /**
     * Allows for public read access to 'all_recipients' property.
Scott committed
4001
     * @note: Before the send() call, queued addresses (i.e. with IDN) are not yet included.
Scott committed
4002 4003 4004 4005 4006 4007 4008 4009 4010 4011
     * @access public
     * @return array
     */
    public function getAllRecipientAddresses()
    {
        return $this->all_recipients;
    }

    /**
     * Perform a callback.
Scott committed
4012 4013 4014 4015
     * @param boolean $isSent
     * @param array $to
     * @param array $cc
     * @param array $bcc
Scott committed
4016 4017 4018 4019
     * @param string $subject
     * @param string $body
     * @param string $from
     */
Scott committed
4020
    protected function doCallback($isSent, $to, $cc, $bcc, $subject, $body, $from)
Scott committed
4021 4022 4023 4024 4025 4026 4027 4028 4029 4030 4031 4032 4033 4034 4035 4036 4037 4038 4039 4040
    {
        if (!empty($this->action_function) && is_callable($this->action_function)) {
            $params = array($isSent, $to, $cc, $bcc, $subject, $body, $from);
            call_user_func_array($this->action_function, $params);
        }
    }
}

/**
 * PHPMailer exception handler
 * @package PHPMailer
 */
class phpmailerException extends Exception
{
    /**
     * Prettify error message output
     * @return string
     */
    public function errorMessage()
    {
4041
        $errorMsg = '<strong>' . htmlspecialchars($this->getMessage()) . "</strong><br />\n";
Scott committed
4042 4043 4044
        return $errorMsg;
    }
}