From ff9a7534edac66e8bc5248a5c01f8f18b070aed9 Mon Sep 17 00:00:00 2001 From: thisgun Date: Fri, 29 May 2026 07:22:08 +0000 Subject: [PATCH] Restore data htaccess on admin and write upload --- adm/_common.php | 4 ++++ bbs/write_update.php | 7 ++++++- lib/common.lib.php | 40 ++++++++++++++++++++++++++++++++++++++++ 3 files changed, 50 insertions(+), 1 deletion(-) diff --git a/adm/_common.php b/adm/_common.php index 989845be2..57efefd48 100644 --- a/adm/_common.php +++ b/adm/_common.php @@ -3,6 +3,10 @@ define('G5_IS_ADMIN', true); require_once '../common.php'; require_once G5_ADMIN_PATH . '/admin.lib.php'; +if (function_exists('g5_check_data_htaccess')) { + g5_check_data_htaccess(); +} + if (isset($token)) { $token = @htmlspecialchars(strip_tags($token), ENT_QUOTES); } diff --git a/bbs/write_update.php b/bbs/write_update.php index 80c9da899..875a253b5 100644 --- a/bbs/write_update.php +++ b/bbs/write_update.php @@ -484,6 +484,11 @@ $file_upload_msg = ''; $upload = array(); if(isset($_FILES['bf_file']['name']) && is_array($_FILES['bf_file']['name'])) { + + if (function_exists('g5_check_data_htaccess')) { + g5_check_data_htaccess(); + } + $bf_file_cnt = count($_FILES['bf_file']['name']); for ($i=0; $i<$bf_file_cnt; $i++) { $upload[$i]['file'] = ''; @@ -776,4 +781,4 @@ run_event('write_update_after', $board, $wr_id, $w, $qstr, $redirect_url); if ($file_upload_msg) alert($file_upload_msg, $redirect_url); else - goto_url($redirect_url); \ No newline at end of file + goto_url($redirect_url); diff --git a/lib/common.lib.php b/lib/common.lib.php index 1b396f3c9..a3fe37859 100644 --- a/lib/common.lib.php +++ b/lib/common.lib.php @@ -4629,6 +4629,46 @@ function get_call_func_cache($func, $args=array()){ return $result; } +function g5_check_data_htaccess($data_path='') +{ + if ($data_path === '') { + if (!defined('G5_DATA_PATH')) { + return false; + } + + $data_path = G5_DATA_PATH; + } + + $htaccess_file = $data_path.'/.htaccess'; + + if (@is_file($htaccess_file) && @filesize($htaccess_file) > 0) { + return true; + } + + if (!@is_dir($data_path) || !@is_writable($data_path)) { + return false; + } + + $content = << +Order allow,deny +Deny from all + +RedirectMatch 403 /session/.* +EOD; + + $result = @file_put_contents($htaccess_file, $content); + if ($result === false) { + return false; + } + + if (defined('G5_FILE_PERMISSION')) { + @chmod($htaccess_file, G5_FILE_PERMISSION); + } + + return true; +} + // include 하는 경로에 data file 경로나 안전하지 않은 경로가 있는지 체크합니다. function is_include_path_check($path='', $is_input='') {