]> jfr.im git - uguu.git/commitdiff
no more double dots
authorGo Johansson <redacted>
Sat, 22 Jan 2022 18:50:06 +0000 (19:50 +0100)
committerGo Johansson <redacted>
Sat, 22 Jan 2022 18:50:06 +0000 (19:50 +0100)
dist.json
static/php/includes/Core.namespace.php
static/php/includes/Upload.class.php

index 3de53777e18c7448aa09ee0486ef980dad26fcd5..125b32d73ea31f36b47c0aa4758b7268769bcd01 100644 (file)
--- a/dist.json
+++ b/dist.json
     "application/x-executable",
     "application/x-mach-binary",
     "image/svg+xml"
-  ],
-  "DOUBLE_DOTS": [
-    "tar.gz",
-    "tar.bz",
-    "tar.bz2",
-    "tar.xz",
-    "user.js"
   ]
 }
\ No newline at end of file
index b4b9c2cc26fcd899b6e2d02952ec6ed1a45f5247..e183a016a61f7cb4447975313b7012d74570e9f6 100644 (file)
@@ -85,7 +85,6 @@ namespace Core {
                 self::$ID_CHARSET = $settings_array['ID_CHARSET'];
                 self::$BLOCKED_EXTENSIONS = $settings_array['BLOCKED_EXTENSIONS'];
                 self::$BLOCKED_MIME = $settings_array['BLOCKED_MIME'];
-                self::$DOUBLE_DOTS = $settings_array['DOUBLE_DOTS'];
             } catch (Exception) {
                 throw new Exception('Cant populate settings.', 500);
             }
index 15ba8f68933148b04d86ce511f5d63463896a5d2..9d5d8e5d2192a4e68316817b07eb77736b4a6b2e 100644 (file)
@@ -106,7 +106,23 @@ class Upload
             'size' => self::$FILE_SIZE
         ];
     }
+    public function fileInfo()
+    {
+        if (isset($_FILES['files'])) {
+            self::$SHA1 = sha1_file(self::$TEMP_FILE);
+            $finfo = finfo_open(FILEINFO_MIME_TYPE);
+            self::$FILE_MIME = finfo_file($finfo, self::$TEMP_FILE);
+            $extension = explode('.',self::$FILE_NAME,2);
+            self::$FILE_EXTENSION = $extension['1'];
+            finfo_close($finfo);
 
+            if (Settings::$LOG_IP) {
+                self::$IP = $_SERVER['REMOTE_ADDR'];
+            } else {
+                self::$IP = '0';
+            }
+        }
+    }
     /**
      * @throws Exception
      */
@@ -124,8 +140,9 @@ class Upload
                 self::$NEW_NAME .= Settings::$ID_CHARSET[mt_rand(0, strlen(Settings::$ID_CHARSET))];
             }
 
-            if (isset(self::$FILE_EXTENSION) && self::$FILE_EXTENSION !== '') {
-                self::$NEW_NAME_FULL = self::$NEW_NAME . '.' . self::$FILE_EXTENSION;
+            if(isset(self::$FILE_EXTENSION)){
+                self::$NEW_NAME_FULL = self::$NEW_NAME;
+                self::$NEW_NAME_FULL .= '.'.self::$FILE_EXTENSION;
             }
 
             if (Settings::$BLACKLIST_DB) {
@@ -141,30 +158,6 @@ class Upload
         return self::$NEW_NAME_FULL;
     }
 
-    public function fileInfo()
-    {
-        if (isset($_FILES['files'])) {
-            self::$SHA1 = sha1_file(self::$TEMP_FILE);
-            $finfo = finfo_open(FILEINFO_MIME_TYPE);
-            self::$FILE_MIME = finfo_file($finfo, self::$TEMP_FILE);
-            finfo_close($finfo);
-
-            if (Settings::$LOG_IP) {
-                self::$IP = $_SERVER['REMOTE_ADDR'];
-            } else {
-                self::$IP = '0';
-            }
-
-            foreach (Settings::$DOUBLE_DOTS as $DDOT) {
-                if (stripos(strrev(self::$FILE_NAME), $DDOT) === 0) {
-                    self::$FILE_EXTENSION = strrev($DDOT);
-                } else {
-                    self::$FILE_EXTENSION = pathinfo(self::$FILE_NAME, PATHINFO_EXTENSION);
-                }
-            }
-        }
-    }
-
     /**
      * @throws Exception
      */