Restore data htaccess on admin and write upload

This commit is contained in:
thisgun
2026-05-29 07:22:08 +00:00
parent 9869be5970
commit ff9a7534ed
3 changed files with 50 additions and 1 deletions
+4
View File
@@ -3,6 +3,10 @@ define('G5_IS_ADMIN', true);
require_once '../common.php';
require_once G5_ADMIN_PATH . '/admin.lib.php';
if (function_exists('g5_check_data_htaccess')) {
g5_check_data_htaccess();
}
if (isset($token)) {
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
}
+6 -1
View File
@@ -484,6 +484,11 @@ $file_upload_msg = '';
$upload = array();
if(isset($_FILES['bf_file']['name']) && is_array($_FILES['bf_file']['name'])) {
if (function_exists('g5_check_data_htaccess')) {
g5_check_data_htaccess();
}
$bf_file_cnt = count($_FILES['bf_file']['name']);
for ($i=0; $i<$bf_file_cnt; $i++) {
$upload[$i]['file'] = '';
@@ -776,4 +781,4 @@ run_event('write_update_after', $board, $wr_id, $w, $qstr, $redirect_url);
if ($file_upload_msg)
alert($file_upload_msg, $redirect_url);
else
goto_url($redirect_url);
goto_url($redirect_url);
+40
View File
@@ -4629,6 +4629,46 @@ function get_call_func_cache($func, $args=array()){
return $result;
}
function g5_check_data_htaccess($data_path='')
{
if ($data_path === '') {
if (!defined('G5_DATA_PATH')) {
return false;
}
$data_path = G5_DATA_PATH;
}
$htaccess_file = $data_path.'/.htaccess';
if (@is_file($htaccess_file) && @filesize($htaccess_file) > 0) {
return true;
}
if (!@is_dir($data_path) || !@is_writable($data_path)) {
return false;
}
$content = <<<EOD
<FilesMatch "\.(htaccess|htpasswd|[Pp][Hh][Pp]|[Pp][Hh][Tt]|[Ss]?[Pp]?[Hh][Tt][Mm][Ll]?|[Ii][Nn][Cc]|[Cc][Gg][Ii]|[Pp][Ll]|[Pp][Hh][Aa][Rr]|[Ss][Vv][Gg][Zz]?)">
Order allow,deny
Deny from all
</FilesMatch>
RedirectMatch 403 /session/.*
EOD;
$result = @file_put_contents($htaccess_file, $content);
if ($result === false) {
return false;
}
if (defined('G5_FILE_PERMISSION')) {
@chmod($htaccess_file, G5_FILE_PERMISSION);
}
return true;
}
// include 하는 경로에 data file 경로나 안전하지 않은 경로가 있는지 체크합니다.
function is_include_path_check($path='', $is_input='')
{