From 71209fc7c9dc699c3cda4b53c9f80359dc8a8f53 Mon Sep 17 00:00:00 2001 From: whitedot Date: Mon, 31 Aug 2026 18:21:34 +0900 Subject: [PATCH] =?UTF-8?q?security:=20KVE-2026-1899=20KVE-2026-1900=20KVE?= =?UTF-8?q?-2026-1909=20=EC=9E=85=EB=A0=A5=20=EB=B0=8F=20=EA=B6=8C?= =?UTF-8?q?=ED=95=9C=20=EA=B2=80=EC=A6=9D=20=EA=B0=95=ED=99=94?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 상품 정렬값을 허용 목록으로 검증하고 관리자 권한 컨텍스트를 명확히 구분한다. 모바일 KCP의 Windows 명령 인자를 안전하게 조립하고 검증한다. --- AGENTS.md | 9 +++- bbs/qadelete.php | 4 +- bbs/qadownload.php | 4 +- bbs/qalist.php | 10 +++-- bbs/qaview.php | 8 ++-- bbs/qawrite.php | 12 +++--- bbs/qawrite_update.php | 6 ++- lib/common.lib.php | 7 ++++ lib/shop.lib.php | 42 ++++++++++++++++++- mobile/shop/_common.php | 24 ++++------- mobile/shop/event.php | 2 +- mobile/shop/itemqaform.php | 4 +- mobile/shop/itemuseform.php | 4 +- mobile/shop/kcp/pp_ax_hub_lib.php | 24 +++++++---- mobile/shop/list.php | 7 +--- mobile/shop/listtype.php | 5 +-- mobile/skin/qa/basic/view.answerform.skin.php | 4 +- mobile/skin/shop/basic/itemqa.skin.php | 6 +-- mobile/skin/shop/basic/itemqalist.skin.php | 4 +- mobile/skin/shop/basic/itemuse.skin.php | 4 +- shop/_common.php | 22 ++++------ shop/event.php | 7 +--- shop/itemqaform.php | 4 +- shop/itemuseform.php | 4 +- shop/kcp/pp_ax_hub_lib.php | 16 ++++--- shop/list.php | 10 +---- shop/listtype.php | 4 +- skin/qa/basic/view.answerform.skin.php | 4 +- skin/shop/basic/itemqa.skin.php | 6 +-- skin/shop/basic/itemqalist.skin.php | 4 +- skin/shop/basic/itemuse.skin.php | 4 +- .../skin/qa/basic/view.answerform.skin.php | 4 +- .../mobile/skin/shop/basic/itemqa.skin.php | 6 +-- .../skin/shop/basic/itemqalist.skin.php | 4 +- .../mobile/skin/shop/basic/itemuse.skin.php | 4 +- theme/basic/shop/_common.php | 22 ++++------ .../skin/qa/basic/view.answerform.skin.php | 4 +- theme/basic/skin/shop/basic/itemqa.skin.php | 6 +-- .../basic/skin/shop/basic/itemqalist.skin.php | 4 +- theme/basic/skin/shop/basic/itemuse.skin.php | 4 +- 40 files changed, 185 insertions(+), 148 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 8207863b1..24147eee0 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -35,9 +35,16 @@ - `chore`: 기능과 직접 관련 없는 유지보수 작업 - `revert`: 이전 변경 되돌리기 +### 보안 이슈 식별자 + +- KVE, CVE 등 식별자가 부여된 보안 이슈를 조치하는 커밋은 제목에 관련 식별자를 반드시 병기한다. +- 식별자는 `security:` 접두어 바로 뒤에 원문 그대로 작성한다. +- 하나의 커밋이 여러 보안 이슈를 함께 조치하면 관련 식별자를 모두 병기한다. +- 예: `security: KVE-2026-1909 모바일 KCP Windows 명령 인자 주입 차단` + ### 작성 예시 - `docs: Git과 압축파일 설치 절차를 구분해 README에 안내` - `fix: 품목 일부 취소 시 PG 취소금액 불일치 수정` -- `security: 상품 정렬값 화이트리스트 검증으로 SQL 삽입 차단` +- `security: KVE-2026-1899 상품 정렬값 화이트리스트 검증으로 SQL 삽입 차단` - `refactor: 객체 캐시의 유형별 저장 키 생성 로직 분리` diff --git a/bbs/qadelete.php b/bbs/qadelete.php index 499745e9d..3fa54573c 100644 --- a/bbs/qadelete.php +++ b/bbs/qadelete.php @@ -1,6 +1,8 @@ '.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.'; } -include_once('./qatail.php'); \ No newline at end of file +include_once('./qatail.php'); diff --git a/bbs/qaview.php b/bbs/qaview.php index de008d1c9..fc93f9f7e 100644 --- a/bbs/qaview.php +++ b/bbs/qaview.php @@ -2,6 +2,8 @@ include_once('./_common.php'); include_once(G5_EDITOR_LIB); +$is_admin = get_super_admin_type($is_admin); + $qa_id = isset($_REQUEST['qa_id']) ? (int) $_REQUEST['qa_id'] : 0; if($is_guest) @@ -115,7 +117,7 @@ if(is_file($skin_file)) { } */ - if(($view['qa_type'] && $is_admin) || (!$view['qa_type'] && $view['qa_status'] == 0)) { + if(($view['qa_type'] && $is_admin === 'super') || (!$view['qa_type'] && $view['qa_status'] == 0)) { $update_href = G5_BBS_URL.'/qawrite.php?w=u&qa_id='.$view['qa_id'].$qstr; $delete_href = G5_BBS_URL.'/qadelete.php?qa_id='.$view['qa_id'].'&token='.$token.$qstr; } @@ -131,7 +133,7 @@ if(is_file($skin_file)) { and qa_parent = '{$view['qa_id']}' "; $answer = sql_fetch($sql); - if($is_admin) { + if($is_admin === 'super') { $answer_update_href = G5_BBS_URL.'/qawrite.php?w=u&qa_id='.$answer['qa_id'].$qstr; $answer_delete_href = G5_BBS_URL.'/qadelete.php?qa_id='.$answer['qa_id'].'&token='.$token.$qstr; } @@ -216,4 +218,4 @@ if(is_file($skin_file)) { echo '
'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.
'; } -include_once('./qatail.php'); \ No newline at end of file +include_once('./qatail.php'); diff --git a/bbs/qawrite.php b/bbs/qawrite.php index 8904f574e..a42dc111b 100644 --- a/bbs/qawrite.php +++ b/bbs/qawrite.php @@ -2,6 +2,8 @@ include_once('./_common.php'); include_once(G5_EDITOR_LIB); +$is_admin = get_super_admin_type($is_admin); + if($w != '' && $w != 'u' && $w != 'r') { alert('올바른 방법으로 이용해 주십시오.'); } @@ -30,7 +32,7 @@ if(is_file($skin_file)) { if($w == 'u' || $w == 'r') { $sql = " select * from {$g5['qa_content_table']} where qa_id = '$qa_id' "; - if(!$is_admin) { + if($is_admin !== 'super') { $sql .= " and mb_id = '{$member['mb_id']}' "; } @@ -40,7 +42,7 @@ if(is_file($skin_file)) { if(!$write['qa_id']) alert('게시글이 존재하지 않습니다.\\n삭제되었거나 자신의 글이 아닌 경우입니다.'); - if(!$is_admin) { + if($is_admin !== 'super') { if($write['qa_type'] == 0 && $write['qa_status'] == 1) alert('답변이 등록된 문의글은 수정할 수 없습니다.'); @@ -117,7 +119,7 @@ if(is_file($skin_file)) { if($w == '' || $w == 'r') $write['qa_email'] = $member['mb_email']; - if($w == 'u' && $is_admin && $write['qa_type']) + if($w == 'u' && $is_admin === 'super' && $write['qa_type']) $is_email = false; } @@ -132,7 +134,7 @@ if(is_file($skin_file)) { if($w == '' || $w == 'r') $write['qa_hp'] = $member['mb_hp']; - if($w == 'u' && $is_admin && $write['qa_type']) + if($w == 'u' && $is_admin === 'super' && $write['qa_type']) $is_hp = false; } @@ -145,4 +147,4 @@ if(is_file($skin_file)) { echo '
'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.
'; } -include_once('./qatail.php'); \ No newline at end of file +include_once('./qatail.php'); diff --git a/bbs/qawrite_update.php b/bbs/qawrite_update.php index 0f6252175..3c0397d1a 100644 --- a/bbs/qawrite_update.php +++ b/bbs/qawrite_update.php @@ -1,6 +1,8 @@ $qaconfig['qa_upload_size']) { + // 최고관리자가 아니면서 설정한 업로드 사이즈보다 크다면 건너뜀 + if ($is_admin !== 'super' && $filesize > $qaconfig['qa_upload_size']) { $file_upload_msg .= '"'.$filename.'" 파일의 용량('.number_format($filesize).' 바이트)이 게시판에 설정('.number_format($qaconfig['qa_upload_size']).' 바이트)된 값보다 크므로 업로드 하지 않습니다.\\n'; continue; } diff --git a/lib/common.lib.php b/lib/common.lib.php index b9eec2ea0..add6d4e33 100644 --- a/lib/common.lib.php +++ b/lib/common.lib.php @@ -20,6 +20,13 @@ function get_microtime() } +// 게시판/그룹 관리자 문맥을 제외하고 최고관리자 권한만 반환 +function get_super_admin_type($admin_type) +{ + return $admin_type === 'super' ? 'super' : ''; +} + + // 한페이지에 보여줄 행, 현재페이지, 총페이지수, URL function get_paging($write_pages, $cur_page, $total_page, $url, $add="") { diff --git a/lib/shop.lib.php b/lib/shop.lib.php index eb11e4b15..4f0d35738 100644 --- a/lib/shop.lib.php +++ b/lib/shop.lib.php @@ -26,6 +26,46 @@ function get_shop_uid($type, $id, $time, $ip) return hash_hmac('sha256', $payload, $key); } +/** + * 상품 목록 정렬 요청을 허용된 DB 컬럼과 방향으로 변환한다. + * + * @param mixed $sort 외부 정렬 키 + * @param mixed $sortodr 외부 정렬 방향 + * @return array 검증된 정렬 컬럼과 방향. 잘못된 입력이면 모두 빈 문자열 + */ +function get_shop_item_sort($sort, $sortodr) +{ + $sort_columns = array( + 'it_name' => 'it_name', + 'it_sum_qty' => 'it_sum_qty', + 'it_price' => 'it_price', + 'it_use_avg' => 'it_use_avg', + 'it_use_cnt' => 'it_use_cnt', + 'it_update_time' => 'it_update_time', + ); + + if (!is_string($sort) || !isset($sort_columns[$sort])) { + return array('', ''); + } + + if (!is_string($sortodr)) { + return array('', ''); + } + + $sortodr = strtolower($sortodr); + if (!in_array($sortodr, array('asc', 'desc'), true)) { + return array('', ''); + } + + return array($sort_columns[$sort], $sortodr); +} + +// 쇼핑몰 리소스 소유자 또는 최고관리자인지 확인 +function is_shop_resource_owner_or_super_admin($owner_id, $member_id, $admin_type) +{ + return $admin_type === 'super' || ($member_id !== '' && $owner_id === $member_id); +} + /** * 현금영수증 발급 또는 조회에 대한 검증 * @@ -2094,7 +2134,7 @@ function check_itemuse_write($it_id, $mb_id, $close=true) { global $g5, $default, $is_admin; - if(!$is_admin && $default['de_item_use_write']) + if($is_admin !== 'super' && $default['de_item_use_write']) { $sql = " select count(*) as cnt from {$g5['g5_shop_cart_table']} diff --git a/mobile/shop/_common.php b/mobile/shop/_common.php index c1d8470e3..3b26589bd 100644 --- a/mobile/shop/_common.php +++ b/mobile/shop/_common.php @@ -1,20 +1,14 @@ \'\"\\\'\\\"\%\=\(\)\s]/", "", $sort); -} else { - $sort = ''; -} - -if (isset($_REQUEST['sortodr'])) { - $sortodr = preg_match("/^(asc|desc)$/i", $sortodr) ? $sortodr : ''; -} else { - $sortodr = ''; -} - if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) die('

쇼핑몰 설치 후 이용해 주십시오.

'); -define('_SHOP_', true); \ No newline at end of file + +$is_admin = get_super_admin_type($is_admin); + +$request_sort = (isset($_REQUEST['sort']) && is_string($_REQUEST['sort'])) ? $_REQUEST['sort'] : ''; +$request_sortodr = (isset($_REQUEST['sortodr']) && is_string($_REQUEST['sortodr'])) ? $_REQUEST['sortodr'] : ''; +list($sort, $sortodr) = get_shop_item_sort($request_sort, $request_sortodr); +unset($request_sort, $request_sortodr); + +define('_SHOP_', true); diff --git a/mobile/shop/event.php b/mobile/shop/event.php index f481b8b4e..83f387f58 100644 --- a/mobile/shop/event.php +++ b/mobile/shop/event.php @@ -93,4 +93,4 @@ echo '
'.conv_content($ev['ev_tail_html'], 1).'
'; mf_exec($bin_exe . "\"". + $res_data = $this->mf_exec($bin_exe, "site_cd=" . $site_cd . "," . "site_key=" . $site_key . "," . "tx_cd=" . $tx_cd . "," . @@ -188,8 +189,7 @@ $ordr_data . $rcvr_data . $escw_data . - $modx_data . - "\"") ; + $modx_data) ; } else { @@ -276,21 +276,27 @@ return $my_data; } - function mf_exec() + function mf_build_exec_cmd( $arg ) { - $arg = func_get_args(); - if ( is_array( $arg[0] ) ) $arg = $arg[0]; $exec_cmd = array_shift( $arg ); - foreach($arg as $i) + foreach((array) $arg as $key=>$i) { $exec_cmd .= " " . escapeshellarg( $i ); } + return $exec_cmd; + } + + function mf_exec() + { + $arg = func_get_args(); + $exec_cmd = $this->mf_build_exec_cmd( $arg ); + $rt = exec( $exec_cmd ); return $rt; } - } \ No newline at end of file + } diff --git a/mobile/shop/list.php b/mobile/shop/list.php index 188fca1b7..50eb66ee4 100644 --- a/mobile/shop/list.php +++ b/mobile/shop/list.php @@ -11,11 +11,6 @@ if(defined('G5_THEME_MSHOP_PATH')) { unset($theme_list_file); } -// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요. -if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){ - $sort=''; -} - $sql = " select * from {$g5['g5_shop_category_table']} where ca_id = '$ca_id' @@ -200,4 +195,4 @@ var g5_shop_url = ""; \n"; \ No newline at end of file +echo "\n\n"; diff --git a/mobile/shop/listtype.php b/mobile/shop/listtype.php index dee950022..e984fac87 100644 --- a/mobile/shop/listtype.php +++ b/mobile/shop/listtype.php @@ -1,9 +1,6 @@

답변등록

@@ -151,4 +151,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가 - \ No newline at end of file + diff --git a/mobile/skin/shop/basic/itemqa.skin.php b/mobile/skin/shop/basic/itemqa.skin.php index 9e80154c4..693d56550 100644 --- a/mobile/skin/shop/basic/itemqa.skin.php +++ b/mobile/skin/shop/basic/itemqa.skin.php @@ -27,7 +27,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' 비밀글'; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -87,7 +87,7 @@ add_stylesheet('', - +
" class="itemqa_form btn01" onclick="return false;">수정 " class="itemqa_delete btn01">삭제 @@ -148,4 +148,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/mobile/skin/shop/basic/itemqalist.skin.php b/mobile/skin/shop/basic/itemqalist.skin.php index dbc384332..20d00cab7 100644 --- a/mobile/skin/shop/basic/itemqalist.skin.php +++ b/mobile/skin/shop/basic/itemqalist.skin.php @@ -46,7 +46,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' '; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -141,4 +141,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/mobile/skin/shop/basic/itemuse.skin.php b/mobile/skin/shop/basic/itemuse.skin.php index 8f6d5e3da..a012a046c 100644 --- a/mobile/skin/shop/basic/itemuse.skin.php +++ b/mobile/skin/shop/basic/itemuse.skin.php @@ -52,7 +52,7 @@ add_stylesheet('',
- +
" class="itemuse_form btn01" onclick="return false;">수정 " class="itemuse_delete btn01">삭제 @@ -130,4 +130,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/shop/_common.php b/shop/_common.php index 594dc4f7c..eb390667a 100644 --- a/shop/_common.php +++ b/shop/_common.php @@ -1,22 +1,16 @@ \'\"\\\'\\\"\%\=\(\)\s]/", "", $sort); -} else { - $sort = ''; -} - -if (isset($_REQUEST['sortodr'])) { - $sortodr = preg_match("/^(asc|desc)$/i", $sortodr) ? $sortodr : ''; -} else { - $sortodr = ''; -} - if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) die('

쇼핑몰 설치 후 이용해 주십시오.

'); +$is_admin = get_super_admin_type($is_admin); + +$request_sort = (isset($_REQUEST['sort']) && is_string($_REQUEST['sort'])) ? $_REQUEST['sort'] : ''; +$request_sortodr = (isset($_REQUEST['sortodr']) && is_string($_REQUEST['sortodr'])) ? $_REQUEST['sortodr'] : ''; +list($sort, $sortodr) = get_shop_item_sort($request_sort, $request_sortodr); +unset($request_sort, $request_sortodr); + define('_SHOP_', true); define('_SHOP_COMMON_', true); // 모바일 페이지의 직접 접근을 막는 경우에 사용 -?> \ No newline at end of file +?> diff --git a/shop/event.php b/shop/event.php index c0f950bac..c44745708 100644 --- a/shop/event.php +++ b/shop/event.php @@ -5,11 +5,6 @@ $ev_id = isset($_GET['ev_id']) ? (int) $_GET['ev_id'] : 0; $skin = isset($_GET['skin']) ? clean_xss_tags($_GET['skin'], 1, 1) : ''; $ca_id = isset($_GET['ca_id']) ? clean_xss_tags($_GET['ca_id'], 1, 1) : ''; -// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요. -if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){ - $sort=''; -} - if (G5_IS_MOBILE) { include_once(G5_MSHOP_PATH.'/event.php'); return; @@ -117,4 +112,4 @@ if (file_exists($timg)) mf_exec($bin_exe, @@ -276,10 +276,8 @@ return $my_data; } - function mf_exec() + function mf_build_exec_cmd( $arg ) { - $arg = func_get_args(); - if ( is_array( $arg[0] ) ) $arg = $arg[0]; $exec_cmd = array_shift( $arg ); @@ -289,8 +287,16 @@ $exec_cmd .= " " . escapeshellarg( $i ); } + return $exec_cmd; + } + + function mf_exec() + { + $arg = func_get_args(); + $exec_cmd = $this->mf_build_exec_cmd( $arg ); + $rt = exec( $exec_cmd ); return $rt; } - } \ No newline at end of file + } diff --git a/shop/list.php b/shop/list.php index a7d3f0d9f..525b2cbd6 100644 --- a/shop/list.php +++ b/shop/list.php @@ -4,14 +4,6 @@ include_once('./_common.php'); $ca_id = isset($_REQUEST['ca_id']) ? safe_replace_regex($_REQUEST['ca_id'], 'ca_id') : ''; $skin = isset($_REQUEST['skin']) ? safe_replace_regex($_REQUEST['skin'], 'skin') : ''; -// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요. -if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){ - $sort=''; -} -if( !isset($sortodr) || !in_array(strtolower($sortodr), array('asc', 'desc')) ){ - $sortodr=''; -} - if (G5_IS_MOBILE) { include_once(G5_MSHOP_PATH.'/list.php'); return; @@ -181,4 +173,4 @@ if ($ca['ca_include_tail'] && is_include_path_check($ca['ca_include_tail']) else include_once(G5_SHOP_PATH.'/_tail.php'); -echo "\n\n"; \ No newline at end of file +echo "\n\n"; diff --git a/shop/listtype.php b/shop/listtype.php index 276d737c5..4980c9f80 100644 --- a/shop/listtype.php +++ b/shop/listtype.php @@ -1,8 +1,6 @@

답변등록

@@ -152,4 +152,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가 - \ No newline at end of file + diff --git a/skin/shop/basic/itemqa.skin.php b/skin/shop/basic/itemqa.skin.php index 9e4741463..ac733a0f4 100644 --- a/skin/shop/basic/itemqa.skin.php +++ b/skin/shop/basic/itemqa.skin.php @@ -29,7 +29,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' 비밀글'; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -85,7 +85,7 @@ add_stylesheet('',
- +
" class="itemqa_form btn01" onclick="return false;">수정 " class="itemqa_delete btn01">삭제 @@ -140,4 +140,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/skin/shop/basic/itemqalist.skin.php b/skin/shop/basic/itemqalist.skin.php index d70285924..22a4e8b7c 100644 --- a/skin/shop/basic/itemqalist.skin.php +++ b/skin/shop/basic/itemqalist.skin.php @@ -44,7 +44,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' '; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -141,4 +141,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/skin/shop/basic/itemuse.skin.php b/skin/shop/basic/itemuse.skin.php index 1c796be50..fc3d84369 100644 --- a/skin/shop/basic/itemuse.skin.php +++ b/skin/shop/basic/itemuse.skin.php @@ -59,7 +59,7 @@ add_stylesheet('',
- +
" class="itemuse_form btn01" onclick="return false;">수정 " class="itemuse_delete btn01">삭제 @@ -131,4 +131,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/theme/basic/mobile/skin/qa/basic/view.answerform.skin.php b/theme/basic/mobile/skin/qa/basic/view.answerform.skin.php index e89ec6c66..1aa9556ea 100644 --- a/theme/basic/mobile/skin/qa/basic/view.answerform.skin.php +++ b/theme/basic/mobile/skin/qa/basic/view.answerform.skin.php @@ -4,7 +4,7 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가

답변등록

@@ -151,4 +151,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가 -
\ No newline at end of file + diff --git a/theme/basic/mobile/skin/shop/basic/itemqa.skin.php b/theme/basic/mobile/skin/shop/basic/itemqa.skin.php index 9e80154c4..693d56550 100644 --- a/theme/basic/mobile/skin/shop/basic/itemqa.skin.php +++ b/theme/basic/mobile/skin/shop/basic/itemqa.skin.php @@ -27,7 +27,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' 비밀글'; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -87,7 +87,7 @@ add_stylesheet('',
- +
" class="itemqa_form btn01" onclick="return false;">수정 " class="itemqa_delete btn01">삭제 @@ -148,4 +148,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/theme/basic/mobile/skin/shop/basic/itemqalist.skin.php b/theme/basic/mobile/skin/shop/basic/itemqalist.skin.php index dbc384332..20d00cab7 100644 --- a/theme/basic/mobile/skin/shop/basic/itemqalist.skin.php +++ b/theme/basic/mobile/skin/shop/basic/itemqalist.skin.php @@ -46,7 +46,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' '; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -141,4 +141,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/theme/basic/mobile/skin/shop/basic/itemuse.skin.php b/theme/basic/mobile/skin/shop/basic/itemuse.skin.php index 8f6d5e3da..a012a046c 100644 --- a/theme/basic/mobile/skin/shop/basic/itemuse.skin.php +++ b/theme/basic/mobile/skin/shop/basic/itemuse.skin.php @@ -52,7 +52,7 @@ add_stylesheet('',
- +
" class="itemuse_form btn01" onclick="return false;">수정 " class="itemuse_delete btn01">삭제 @@ -130,4 +130,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/theme/basic/shop/_common.php b/theme/basic/shop/_common.php index 3d77e83c4..64fef14f7 100644 --- a/theme/basic/shop/_common.php +++ b/theme/basic/shop/_common.php @@ -1,20 +1,14 @@ \'\"\\\'\\\"\%\=\(\)\s]/", "", $sort); -} else { - $sort = ''; -} - -if (isset($_REQUEST['sortodr'])) { - $sortodr = preg_match("/^(asc|desc)$/i", $sortodr) ? $sortodr : ''; -} else { - $sortodr = ''; -} - if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) die('

쇼핑몰 설치 후 이용해 주십시오.

'); -define('_SHOP_', true); \ No newline at end of file +$is_admin = get_super_admin_type($is_admin); + +$request_sort = (isset($_REQUEST['sort']) && is_string($_REQUEST['sort'])) ? $_REQUEST['sort'] : ''; +$request_sortodr = (isset($_REQUEST['sortodr']) && is_string($_REQUEST['sortodr'])) ? $_REQUEST['sortodr'] : ''; +list($sort, $sortodr) = get_shop_item_sort($request_sort, $request_sortodr); +unset($request_sort, $request_sortodr); + +define('_SHOP_', true); diff --git a/theme/basic/skin/qa/basic/view.answerform.skin.php b/theme/basic/skin/qa/basic/view.answerform.skin.php index 931ca38ee..6c6b9f129 100644 --- a/theme/basic/skin/qa/basic/view.answerform.skin.php +++ b/theme/basic/skin/qa/basic/view.answerform.skin.php @@ -4,7 +4,7 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가

답변등록

@@ -152,4 +152,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가 -
\ No newline at end of file + diff --git a/theme/basic/skin/shop/basic/itemqa.skin.php b/theme/basic/skin/shop/basic/itemqa.skin.php index 9e4741463..ac733a0f4 100644 --- a/theme/basic/skin/shop/basic/itemqa.skin.php +++ b/theme/basic/skin/shop/basic/itemqa.skin.php @@ -29,7 +29,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' 비밀글'; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -85,7 +85,7 @@ add_stylesheet('',
- +
" class="itemqa_form btn01" onclick="return false;">수정 " class="itemqa_delete btn01">삭제 @@ -140,4 +140,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/theme/basic/skin/shop/basic/itemqalist.skin.php b/theme/basic/skin/shop/basic/itemqalist.skin.php index d70285924..22a4e8b7c 100644 --- a/theme/basic/skin/shop/basic/itemqalist.skin.php +++ b/theme/basic/skin/shop/basic/itemqalist.skin.php @@ -44,7 +44,7 @@ add_stylesheet('', if($row['iq_secret']) { $iq_subject .= ' '; - if($is_admin || $member['mb_id' ] == $row['mb_id']) { + if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); } else { $iq_question = '비밀글로 보호된 문의입니다.'; @@ -141,4 +141,4 @@ $(function(){ }); }); - \ No newline at end of file + diff --git a/theme/basic/skin/shop/basic/itemuse.skin.php b/theme/basic/skin/shop/basic/itemuse.skin.php index 1c796be50..fc3d84369 100644 --- a/theme/basic/skin/shop/basic/itemuse.skin.php +++ b/theme/basic/skin/shop/basic/itemuse.skin.php @@ -59,7 +59,7 @@ add_stylesheet('',
- +
" class="itemuse_form btn01" onclick="return false;">수정 " class="itemuse_delete btn01">삭제 @@ -131,4 +131,4 @@ $(function(){ }); }); - \ No newline at end of file +