Restore data htaccess on admin and write upload
This commit is contained in:
@@ -3,6 +3,10 @@ define('G5_IS_ADMIN', true);
|
|||||||
require_once '../common.php';
|
require_once '../common.php';
|
||||||
require_once G5_ADMIN_PATH . '/admin.lib.php';
|
require_once G5_ADMIN_PATH . '/admin.lib.php';
|
||||||
|
|
||||||
|
if (function_exists('g5_check_data_htaccess')) {
|
||||||
|
g5_check_data_htaccess();
|
||||||
|
}
|
||||||
|
|
||||||
if (isset($token)) {
|
if (isset($token)) {
|
||||||
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
|
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -484,6 +484,11 @@ $file_upload_msg = '';
|
|||||||
$upload = array();
|
$upload = array();
|
||||||
|
|
||||||
if(isset($_FILES['bf_file']['name']) && is_array($_FILES['bf_file']['name'])) {
|
if(isset($_FILES['bf_file']['name']) && is_array($_FILES['bf_file']['name'])) {
|
||||||
|
|
||||||
|
if (function_exists('g5_check_data_htaccess')) {
|
||||||
|
g5_check_data_htaccess();
|
||||||
|
}
|
||||||
|
|
||||||
$bf_file_cnt = count($_FILES['bf_file']['name']);
|
$bf_file_cnt = count($_FILES['bf_file']['name']);
|
||||||
for ($i=0; $i<$bf_file_cnt; $i++) {
|
for ($i=0; $i<$bf_file_cnt; $i++) {
|
||||||
$upload[$i]['file'] = '';
|
$upload[$i]['file'] = '';
|
||||||
@@ -776,4 +781,4 @@ run_event('write_update_after', $board, $wr_id, $w, $qstr, $redirect_url);
|
|||||||
if ($file_upload_msg)
|
if ($file_upload_msg)
|
||||||
alert($file_upload_msg, $redirect_url);
|
alert($file_upload_msg, $redirect_url);
|
||||||
else
|
else
|
||||||
goto_url($redirect_url);
|
goto_url($redirect_url);
|
||||||
|
|||||||
@@ -4629,6 +4629,46 @@ function get_call_func_cache($func, $args=array()){
|
|||||||
return $result;
|
return $result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function g5_check_data_htaccess($data_path='')
|
||||||
|
{
|
||||||
|
if ($data_path === '') {
|
||||||
|
if (!defined('G5_DATA_PATH')) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
$data_path = G5_DATA_PATH;
|
||||||
|
}
|
||||||
|
|
||||||
|
$htaccess_file = $data_path.'/.htaccess';
|
||||||
|
|
||||||
|
if (@is_file($htaccess_file) && @filesize($htaccess_file) > 0) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!@is_dir($data_path) || !@is_writable($data_path)) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
$content = <<<EOD
|
||||||
|
<FilesMatch "\.(htaccess|htpasswd|[Pp][Hh][Pp]|[Pp][Hh][Tt]|[Ss]?[Pp]?[Hh][Tt][Mm][Ll]?|[Ii][Nn][Cc]|[Cc][Gg][Ii]|[Pp][Ll]|[Pp][Hh][Aa][Rr]|[Ss][Vv][Gg][Zz]?)">
|
||||||
|
Order allow,deny
|
||||||
|
Deny from all
|
||||||
|
</FilesMatch>
|
||||||
|
RedirectMatch 403 /session/.*
|
||||||
|
EOD;
|
||||||
|
|
||||||
|
$result = @file_put_contents($htaccess_file, $content);
|
||||||
|
if ($result === false) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (defined('G5_FILE_PERMISSION')) {
|
||||||
|
@chmod($htaccess_file, G5_FILE_PERMISSION);
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
// include 하는 경로에 data file 경로나 안전하지 않은 경로가 있는지 체크합니다.
|
// include 하는 경로에 data file 경로나 안전하지 않은 경로가 있는지 체크합니다.
|
||||||
function is_include_path_check($path='', $is_input='')
|
function is_include_path_check($path='', $is_input='')
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user