cvs: pear /HTTP_Upload Upload.php

From: Date: Wed, 15 Aug 2001 01:25:27 +0000
Subject: cvs: pear /HTTP_Upload Upload.php
Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-522@lists.php.net to get a copy of this message
cox Tue Aug 14 21:25:27 2001 EDT Modified files: /pear/HTTP_Upload Upload.php Log: - more safe checks - the default file name mode is now 'safe' - phpdoc update Please use this version if you are using the class Index: pear/HTTP_Upload/Upload.php diff -u pear/HTTP_Upload/Upload.php:1.2 pear/HTTP_Upload/Upload.php:1.3 --- pear/HTTP_Upload/Upload.php:1.2 Sun Aug 12 09:08:32 2001 +++ pear/HTTP_Upload/Upload.php Tue Aug 14 21:25:27 2001 @@ -7,7 +7,7 @@ // // ********************************************** // -// $Id: Upload.php,v 1.2 2001/08/12 13:08:32 cox Exp $ +// $Id: Upload.php,v 1.3 2001/08/15 01:25:27 cox Exp $ /** * Pear File Uploader class. Easy and secure managment of files @@ -176,7 +176,7 @@ foreach ($this->post_files as $userfile => $value) { if (is_array($value['name'])) { foreach ($value['name'] as $key => $val) { - $name = $value['name'][$key]; + $name = basename($value['name'][$key]); $tmp_name = $value['tmp_name'][$key]; $size = $value['size'][$key]; $type = $value['type'][$key]; @@ -186,7 +186,7 @@ } // One file } else { - $name = $value['name']; + $name = basename($value['name']); $tmp_name = $value['tmp_name']; $size = $value['size']; $type = $value['type']; @@ -203,8 +203,14 @@ { /** * Assoc array with file properties + * @var array */ var $upload = array(); + /** + * If user haven't selected a mode, by default 'safe' will be used + * @var bool + */ + var $mode_name_selected = false; function HTTP_Upload_File ($name=null, $tmp=null, $formname=null, $type=null, $size=null, $lang=null) @@ -260,6 +266,7 @@ $name = $mode; } $this->upload['name'] = $prepend . $name . $append; + $this->mode_name_selected = true; return $this->upload['name']; } /** @@ -273,25 +280,23 @@ } /** - * Dada una cadena de texto, la formatea para que - * se pueda convertir en un nombre de fichero seguro + * Format a file name to be safe * - * @param string $file - La cadena de texto a convertir + * @param string $file - The string file name * @param int $maxlen - Maximun permited string lenght - * @result string - Cadena de texto con formato de nombre de fichero + * @result string - Formatted file name */ function nameToSafe ($name, $maxlen=250) { $noalpha = 'áéíóúàèìòùäëïöüÁÉÍÓÚÀÈÌÒÙÄËÏÖÜâêîôûÂÊÎÔÛñçÇ@'; $alpha = 'aeiouaeiouaeiouAEIOUAEIOUAEIOUaeiouAEIOUncCa'; - // el largo del nombre del fichero no debe exceder los 200 cc - // se dejan 55 cc para poder poner extensiones y otros datos $name = substr ($name, 0, $maxlen); $name = strtr ($name, $noalpha, $alpha); - // si no es un caracter permitido, se substituye por "_" - return ereg_replace ('[^a-zA-Z0-9/,._\+\()\-]', '_', $name); + // not permitted chars are replaced with "_" + return ereg_replace ('[^a-zA-Z0-9,._\+\()\-]', '_', $name); } /** + * The upload was valid * @return bool If the file was submitted correctly */ function isValid() @@ -302,6 +307,7 @@ return false; } /** + * User haven't submit a file * @return bool If the user submitted a file or not */ function isMissing() @@ -312,6 +318,8 @@ return false; } /** + * Some error occured during upload (most common due a file size problem, + * like max size exceeded or 0 bytes long). * @return bool If there were errors submitting the file (probably * because the file excess the max permitted file size) */ @@ -329,7 +337,7 @@ * * @param string $dir_dest * @param bool $overwrite - * @return mixed True on success or Pear_Error object on errors + * @return mixed True on success or Pear_Error object on error */ function moveTo ($dir_dest, $overwrite=true) { @@ -343,19 +351,22 @@ if ($err_code !== false) { return $this->raiseError($err_code); } + // Use 'safe' mode by default if no other was selected + if (!$this->mode_name_selected) { + $this->setName('safe'); + } $slash = ''; if ($dir_dest[strlen($dir_dest)-1] != '/') { $slash = '/'; } $name_dest = $dir_dest . $slash . $this->upload['name']; - $is_file = @is_file($name_dest); - - if (($overwrite !== true) && $is_file) { - return $this->raiseError('FILE_EXISTS'); - } - if ($is_file && !is_writable($name_dest)) { - return $this->raiseError('CANNOT_OVERWRITE'); + if (@is_file($name_dest)) { + if ($overwrite !== true) { + return $this->raiseError('FILE_EXISTS'); + } elseif (!is_writable($name_dest)) { + return $this->raiseError('CANNOT_OVERWRITE'); + } } // Copy the file and let php clean the tmp if (!@copy ($this->upload['tmp_name'], $name_dest)) {

« previous php.pear.cvs (#522) next »