Moved the remaining upload logics to use the checkFileUpload() Function
This commit is contained in:
+1
-2
@@ -595,8 +595,7 @@ function getInvoiceBadgeColor($invoice_status)
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Pass $_FILE['file'] to check an uploaded file before saving it
|
// Pass $_FILE['file'] to check an uploaded file before saving it
|
||||||
function checkFileUpload($file, $allowed_extensions)
|
function checkFileUpload($file, $allowed_extensions) {
|
||||||
{
|
|
||||||
// Variables
|
// Variables
|
||||||
$name = $file['name'];
|
$name = $file['name'];
|
||||||
$tmp = $file['tmp_name'];
|
$tmp = $file['tmp_name'];
|
||||||
|
|||||||
@@ -241,40 +241,19 @@ if(isset($_POST['edit_profile'])){
|
|||||||
|
|
||||||
// Check to see if a file is attached
|
// Check to see if a file is attached
|
||||||
if($_FILES['file']['tmp_name'] != ''){
|
if($_FILES['file']['tmp_name'] != ''){
|
||||||
|
if ($new_file_name = checkFileUpload($_FILES['file'], array('jpg', 'jpeg', 'gif', 'png'))) {
|
||||||
|
|
||||||
// get details of the uploaded file
|
|
||||||
$file_error = 0;
|
|
||||||
$file_tmp_path = $_FILES['file']['tmp_name'];
|
$file_tmp_path = $_FILES['file']['tmp_name'];
|
||||||
$file_name = $_FILES['file']['name'];
|
|
||||||
$file_size = $_FILES['file']['size'];
|
|
||||||
$file_type = $_FILES['file']['type'];
|
|
||||||
$file_extension = strtolower(end(explode('.',$_FILES['file']['name'])));
|
|
||||||
|
|
||||||
// sanitize file-name
|
|
||||||
$new_file_name = md5(time() . $file_name) . '.' . $file_extension;
|
|
||||||
|
|
||||||
// check if file has one of the following extensions
|
|
||||||
$allowed_file_extensions = array('jpg', 'gif', 'png');
|
|
||||||
|
|
||||||
if(in_array($file_extension,$allowed_file_extensions) === false){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
//Check File Size
|
|
||||||
if($file_size > 2097152){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if($file_error == 0){
|
|
||||||
// directory in which the uploaded file will be moved
|
// directory in which the uploaded file will be moved
|
||||||
$upload_file_dir = "uploads/users/$user_id/";
|
$upload_file_dir = "uploads/users/$user_id/";
|
||||||
$dest_path = $upload_file_dir . $new_file_name;
|
$dest_path = $upload_file_dir . $new_file_name;
|
||||||
|
|
||||||
move_uploaded_file($file_tmp_path, $dest_path);
|
move_uploaded_file($file_tmp_path, $dest_path);
|
||||||
|
|
||||||
// Delete old file
|
// Delete old file
|
||||||
unlink("uploads/users/$user_id/$existing_file_name");
|
unlink("uploads/users/$user_id/$existing_file_name");
|
||||||
|
|
||||||
|
// Set Avatar
|
||||||
mysqli_query($mysqli,"UPDATE users SET user_avatar = '$new_file_name' WHERE user_id = $user_id");
|
mysqli_query($mysqli,"UPDATE users SET user_avatar = '$new_file_name' WHERE user_id = $user_id");
|
||||||
|
|
||||||
// Extended Logging
|
// Extended Logging
|
||||||
@@ -418,31 +397,10 @@ if(isset($_POST['edit_company'])){
|
|||||||
|
|
||||||
// Check to see if a file is attached
|
// Check to see if a file is attached
|
||||||
if($_FILES['file']['tmp_name'] != ''){
|
if($_FILES['file']['tmp_name'] != ''){
|
||||||
|
if ($new_file_name = checkFileUpload($_FILES['file'], array('jpg', 'jpeg', 'gif', 'png'))) {
|
||||||
// get details of the uploaded file
|
|
||||||
$file_error = 0;
|
|
||||||
$file_tmp_path = $_FILES['file']['tmp_name'];
|
$file_tmp_path = $_FILES['file']['tmp_name'];
|
||||||
$file_name = $_FILES['file']['name'];
|
|
||||||
$file_size = $_FILES['file']['size'];
|
|
||||||
$file_type = $_FILES['file']['type'];
|
|
||||||
$file_extension = strtolower(end(explode('.',$_FILES['file']['name'])));
|
|
||||||
|
|
||||||
// sanitize file-name
|
|
||||||
$new_file_name = md5(time() . $file_name) . '.' . $file_extension;
|
|
||||||
|
|
||||||
// check if file has one of the following extensions
|
|
||||||
$allowed_file_extensions = array('jpg', 'gif', 'png');
|
|
||||||
|
|
||||||
if(in_array($file_extension,$allowed_file_extensions) === false){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
//Check File Size
|
|
||||||
if($file_size > 2097152){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if($file_error == 0){
|
|
||||||
// directory in which the uploaded file will be moved
|
// directory in which the uploaded file will be moved
|
||||||
$upload_file_dir = "uploads/settings/";
|
$upload_file_dir = "uploads/settings/";
|
||||||
$dest_path = $upload_file_dir . $new_file_name;
|
$dest_path = $upload_file_dir . $new_file_name;
|
||||||
@@ -452,6 +410,7 @@ if(isset($_POST['edit_company'])){
|
|||||||
// Delete old file
|
// Delete old file
|
||||||
unlink("uploads/settings/$existing_file_name");
|
unlink("uploads/settings/$existing_file_name");
|
||||||
|
|
||||||
|
// Set Logo
|
||||||
mysqli_query($mysqli,"UPDATE companies SET company_logo = '$new_file_name' WHERE company_id = 1");
|
mysqli_query($mysqli,"UPDATE companies SET company_logo = '$new_file_name' WHERE company_id = 1");
|
||||||
|
|
||||||
$_SESSION['alert_message'] = 'File successfully uploaded.';
|
$_SESSION['alert_message'] = 'File successfully uploaded.';
|
||||||
@@ -4401,31 +4360,10 @@ if(isset($_POST['add_location'])){
|
|||||||
|
|
||||||
//Check to see if a file is attached
|
//Check to see if a file is attached
|
||||||
if($_FILES['file']['tmp_name'] != ''){
|
if($_FILES['file']['tmp_name'] != ''){
|
||||||
|
if ($new_file_name = checkFileUpload($_FILES['file'], array('jpg', 'jpeg', 'gif', 'png'))) {
|
||||||
|
|
||||||
// get details of the uploaded file
|
|
||||||
$file_error = 0;
|
|
||||||
$file_tmp_path = $_FILES['file']['tmp_name'];
|
$file_tmp_path = $_FILES['file']['tmp_name'];
|
||||||
$file_name = $_FILES['file']['name'];
|
|
||||||
$file_size = $_FILES['file']['size'];
|
|
||||||
$file_type = $_FILES['file']['type'];
|
|
||||||
$file_extension = strtolower(end(explode('.',$_FILES['file']['name'])));
|
|
||||||
|
|
||||||
// sanitize file-name
|
|
||||||
$new_file_name = md5(time() . $file_name) . '.' . $file_extension;
|
|
||||||
|
|
||||||
// check if file has one of the following extensions
|
|
||||||
$allowed_file_extensions = array('jpg', 'gif', 'png');
|
|
||||||
|
|
||||||
if(in_array($file_extension,$allowed_file_extensions) === false){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
//Check File Size
|
|
||||||
if($file_size > 2097152){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if($file_error == 0){
|
|
||||||
// directory in which the uploaded file will be moved
|
// directory in which the uploaded file will be moved
|
||||||
$upload_file_dir = "uploads/clients/$client_id/";
|
$upload_file_dir = "uploads/clients/$client_id/";
|
||||||
$dest_path = $upload_file_dir . $new_file_name;
|
$dest_path = $upload_file_dir . $new_file_name;
|
||||||
@@ -4484,30 +4422,10 @@ if(isset($_POST['edit_location'])){
|
|||||||
//Check to see if a file is attached
|
//Check to see if a file is attached
|
||||||
if($_FILES['file']['tmp_name'] != ''){
|
if($_FILES['file']['tmp_name'] != ''){
|
||||||
|
|
||||||
// get details of the uploaded file
|
if ($new_file_name = checkFileUpload($_FILES['file'], array('jpg', 'jpeg', 'gif', 'png'))) {
|
||||||
$file_error = 0;
|
|
||||||
$file_tmp_path = $_FILES['file']['tmp_name'];
|
$file_tmp_path = $_FILES['file']['tmp_name'];
|
||||||
$file_name = $_FILES['file']['name'];
|
|
||||||
$file_size = $_FILES['file']['size'];
|
|
||||||
$file_type = $_FILES['file']['type'];
|
|
||||||
$file_extension = strtolower(end(explode('.',$_FILES['file']['name'])));
|
|
||||||
|
|
||||||
// sanitize file-name
|
|
||||||
$new_file_name = md5(time() . $file_name) . '.' . $file_extension;
|
|
||||||
|
|
||||||
// check if file has one of the following extensions
|
|
||||||
$allowed_file_extensions = array('jpg', 'gif', 'png');
|
|
||||||
|
|
||||||
if(in_array($file_extension,$allowed_file_extensions) === false){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
//Check File Size
|
|
||||||
if($file_size > 2097152){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if($file_error == 0){
|
|
||||||
// directory in which the uploaded file will be moved
|
// directory in which the uploaded file will be moved
|
||||||
$upload_file_dir = "uploads/clients/$client_id/";
|
$upload_file_dir = "uploads/clients/$client_id/";
|
||||||
$dest_path = $upload_file_dir . $new_file_name;
|
$dest_path = $upload_file_dir . $new_file_name;
|
||||||
@@ -7175,32 +7093,10 @@ if(isset($_POST['add_file'])){
|
|||||||
//Check to see if a file is attached
|
//Check to see if a file is attached
|
||||||
if($_FILES['file']['tmp_name'] != ''){
|
if($_FILES['file']['tmp_name'] != ''){
|
||||||
|
|
||||||
// get details of the uploaded file
|
if ($file_reference_name = checkFileUpload($_FILES['file'], array('jpg', 'jpeg', 'gif', 'png', 'webp', 'pdf', 'txt', 'md', 'doc', 'docx', 'csv', 'xls', 'xlsx', 'xlsm', 'zip', 'tar', 'gz'))) {
|
||||||
$file_error = 0;
|
|
||||||
$file_tmp_path = $_FILES['file']['tmp_name'];
|
$file_tmp_path = $_FILES['file']['tmp_name'];
|
||||||
if(empty($file_name)) {
|
|
||||||
$file_name = sanitizeInput($_FILES['file']['name']);
|
|
||||||
}
|
|
||||||
$file_size = $_FILES['file']['size'];
|
|
||||||
$file_type = $_FILES['file']['type'];
|
|
||||||
$file_extension = strtolower(end(explode('.',$_FILES['file']['name'])));
|
|
||||||
|
|
||||||
// sanitize file-name
|
|
||||||
$file_reference_name = md5(time() . $file_name) . '.' . $file_extension;
|
|
||||||
|
|
||||||
// check if file has one of the following extensions
|
|
||||||
$allowed_file_extensions = array('jpg', 'jpeg', 'gif', 'png', 'webp', 'pdf', 'txt', 'md', 'doc', 'docx', 'csv', 'xls', 'xlsx', 'xlsm', 'zip', 'tar', 'gz');
|
|
||||||
|
|
||||||
if(in_array($file_extension,$allowed_file_extensions) === false){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
//Check File Size
|
|
||||||
if($file_size > 20097152){
|
|
||||||
$file_error = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if($file_error == 0){
|
|
||||||
// directory in which the uploaded file will be moved
|
// directory in which the uploaded file will be moved
|
||||||
$upload_file_dir = "uploads/clients/$client_id/";
|
$upload_file_dir = "uploads/clients/$client_id/";
|
||||||
$dest_path = $upload_file_dir . $file_reference_name;
|
$dest_path = $upload_file_dir . $file_reference_name;
|
||||||
|
|||||||
Reference in New Issue
Block a user