Skip to content

Commit

Permalink
文件下载漏洞修正
Browse files Browse the repository at this point in the history
  • Loading branch information
songdengfeng committed Sep 17, 2021
1 parent b0b7bd5 commit 9b5f13d
Show file tree
Hide file tree
Showing 2 changed files with 10 additions and 5 deletions.
5 changes: 3 additions & 2 deletions app/Http/Controllers/AttachController.php
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,8 @@ public function upload(Request $request){


public function download($name){
$attachFile = storage_path('app/'.str_replace("-","/",$name));
$fileName = str_replace("..","",$name);
$attachFile = storage_path('app/'.str_replace("-","/",$fileName));
if(!is_file($attachFile)){
abort(404);
}
Expand All @@ -48,4 +49,4 @@ public function download($name){



}
}
10 changes: 7 additions & 3 deletions app/Http/Controllers/ImageController.php
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,9 @@ class ImageController extends Controller
*/
public function avatar($avatar_name)
{
list($user_id,$size) = explode('_',str_replace(".jpg",'',$avatar_name));
$fileName = str_replace("..","",$avatar_name);

list($user_id,$size) = explode('_',str_replace(".jpg",'',$fileName));
$avatarFile = storage_path('app/'.User::getAvatarPath($user_id,$size));
if(!is_file($avatarFile)){
$avatarFile = public_path('static/images/default_avatar.jpg');
Expand All @@ -38,15 +40,17 @@ public function avatar($avatar_name)

public function show($image_name)
{
$imageFile = storage_path('app/'.str_replace("-","/",$image_name));
$fileName = str_replace("..","",$image_name);

$imageFile = storage_path('app/'.str_replace("-","/",$fileName));
if(!is_file($imageFile)){
abort(404);
}


$image = Image::make($imageFile);

if(config('tipask.upload.open_watermark') && $image_name != config('tipask.upload.watermark_image') && str_contains($image_name,'attachments')){
if(config('tipask.upload.open_watermark') && $fileName != config('tipask.upload.watermark_image') && str_contains($fileName,'attachments')){
$watermarkImage = storage_path('app/'.str_replace("-","/",config('tipask.upload.watermark_image')));
$image->insert($watermarkImage, 'bottom-right', 15, 10);
}
Expand Down

0 comments on commit 9b5f13d

Please sign in to comment.