Version 4.1.19.4

This commit is contained in:
Neo committed 2025-12-19 05:42:01 -08:00
1 parent 2bd5025018
commit 0dc2aee5ed
312 files changed
+53730 -32118

No files matched your search

+1 -1
View File
@@ -167,7 +167,7 @@ class _Node extends FormAbstract
else
{
/* Recurse three levels in to allow for discoverability */
foreach( $nodeClass::roots( $permCheck, NULL, $this->options['where'] ) AS $node )
foreach( $nodeClass::roots( NULL, NULL, $this->options['where'] ) AS $node )
{
$this->_populate( $nodes, $disabled, 0, $node, $children, 3 );
}
-2
View File
@@ -356,7 +356,6 @@ class _Upload extends FormAbstract
{
$existing[] = array(
'id' => $id,
'fileurl' => (string) $file,
'insertable' => (bool) $this->options['postKey'],
'hasThumb' => false,
'originalFileName' => $file,
@@ -370,7 +369,6 @@ class _Upload extends FormAbstract
{
$existing[] = array(
'id' => $id,
'fileurl' => (string) $file,
'insertable' => (bool) $this->options['postKey'],
'hasThumb' => ( isset( $attachment ) AND isset( $attachment['attach_is_image'] ) ) ? ( $attachment['attach_is_image'] AND $attachment['attach_thumb_location'] ) : $file->isImage(),
'originalFileName' => $file->originalFilename,
+79 -72
View File
@@ -28,7 +28,8 @@ class _Url extends Text
* @code
$childDefaultOptions = array(
'allowedProtocols' => array( 'http', 'https' ), // Allowed protocols. Default is http and https. Be careful changing this not to introduce security issues.
'allowedMimes' => 'image/*', // Sets the allowed mimetype(s). Can be string or array. * is a wildcard. Default is NULL, which allows any mimetypes. Note, setting this will not allow localhost URLs.
'image' => TRUE, // If TRUE, will check the URL is for an image. Note, setting this will not allow localhost URLs.
'allowedMimes' => \IPS\Image::$imageMimes, // Sets the allowed mimetype(s). Can be string or array. * is a wildcard. Default is NULL, which allows any mimetypes. Note, setting this will not allow localhost URLs. If the 'image' option is set, it will already be restricted to images
'file' => 'Profile', // If provided, the contents of the URL will be fetched and written as a file, an \IPS\File object will then be returned rather than a string. Provide the extension name which specifies the storage location to use. Note, setting this will not allow localhost URLs.
'maxFileSize' => NULL, // If provided along with 'file', the resulting file that is written to disk cannot be greater than this size in megabytes. NULL for no limit (default is NULL).
'maxDimensions' => NULL, // If supplied as an array with keys 'width' and 'height' and the resulting file is an image, the image will be scaled down to these maximum dimensions. NULL for no limits (default is NULL).
@@ -73,7 +74,7 @@ class _Url extends Text
}
/* Try to fetch it, if necessary */
if ( $this->options['file'] or $this->options['allowedMimes'] )
if ( $this->options['file'] or $this->options['allowedMimes'] or $this->options['image'] )
{
/* Localhost is not allowed as sending a HTTP request to the local server will cause scripts which are relying
on only being accessible to the local machine to execute */
@@ -100,84 +101,90 @@ class _Url extends Text
$_SESSION[ $_key ] = time();
}
/* Make the request */
try
{
$response = $value->request()->get();
/* Check MIME */
if ( $this->options['allowedMimes'] )
{
$match = FALSE;
$contentType = ( isset( $response->httpHeaders['Content-Type'] ) ) ? $response->httpHeaders['Content-Type'] : ( ( isset( $response->httpHeaders['content-type'] ) ) ? $response->httpHeaders['content-type'] : NULL );
if( $contentType )
{
foreach ( is_array( $this->options['allowedMimes'] ) ? $this->options['allowedMimes'] : array( $this->options['allowedMimes'] ) as $mime )
{
if ( preg_match( '/^' . str_replace( '~~', '.+', preg_quote( str_replace( '*', '~~', $mime ), '/' ) ) . '$/i', $contentType ) )
{
$match = TRUE;
break;
}
}
}
if ( !$match )
{
throw new \DomainException( 'form_url_bad_mime' );
}
}
/* Write file if necessary */
if ( $this->options['file'] )
{
$filename = preg_replace( "/(.+?)(\?|$)/", "$1", mb_substr( $value, mb_strrpos( $value, '/' ) + 1 ) );
$response = (string) $response;
if( $this->options['maxFileSize'] !== NULL )
{
$maxFileSize = $this->options['maxFileSize'] * 1048576;
if( \strlen( $response ) > $maxFileSize )
{
unset( $response );
throw new \DomainException( \IPS\Member::loggedIn()->language()->addToStack( 'upload_too_big', TRUE, array( 'sprintf' => $this->options['maxFileSize'] ) ), 2 );
}
}
try
{
$this->value = \IPS\File::create( $this->options['file'], $filename, $response );
/* Do we need to resize images down? */
if( $this->value->isImage() AND $this->options['maxDimensions'] !== NULL )
{
try
{
$image = \IPS\Image::create( $this->value->contents() );
if( $image::exifSupported() )
{
$image->setExifData( $this->value->contents() );
}
$image->resizeToMax( $this->options['maxDimensions']['width'] ?: NULL, $this->options['maxDimensions']['height'] ?: NULL );
$this->value->replace( (string) $image );
}
catch ( \Exception $e ) { }
}
}
catch( \InvalidArgumentException $e )
{
throw new \DomainException( 'form_url_error' );
}
}
}
catch ( \IPS\Http\Request\Exception $e )
{
throw new \DomainException( 'form_url_error' );
}
/* Check MIME */
if ( $this->options['allowedMimes'] or $this->options['image'] )
{
$allowedMimes = $this->options['allowedMimes'] ? ( is_array( $this->options['allowedMimes'] ) ? $this->options['allowedMimes'] : array( $this->options['allowedMimes'] ) ): \IPS\Image::$imageMimes;
$match = FALSE;
$contentType = ( isset( $response->httpHeaders['Content-Type'] ) ) ? $response->httpHeaders['Content-Type'] : ( ( isset( $response->httpHeaders['content-type'] ) ) ? $response->httpHeaders['content-type'] : NULL );
if( $contentType )
{
foreach ( $allowedMimes as $mime )
{
if ( preg_match( '/^' . str_replace( '~~', '.+', preg_quote( str_replace( '*', '~~', $mime ), '/' ) ) . '$/i', $contentType ) )
{
$match = TRUE;
break;
}
}
}
if ( !$match )
{
throw new \DomainException( 'form_url_bad_mime' );
}
}
/* Max file size */
if( $this->options['maxFileSize'] !== NULL )
{
$maxFileSize = $this->options['maxFileSize'] * 1048576;
if( \strlen( $response ) > $maxFileSize )
{
unset( $response );
throw new \DomainException( \IPS\Member::loggedIn()->language()->addToStack( 'upload_too_big', TRUE, array( 'sprintf' => $this->options['maxFileSize'] ) ), 2 );
}
}
/* Image check and resize if necessary */
if ( $this->options['image'] or $this->options['maxDimensions'] !== NULL )
{
try
{
$image = \IPS\Image::create( $response );
if ( $this->options['maxDimensions'] !== NULL )
{
$image->resizeToMax( $this->options['maxDimensions']['width'] ?: NULL, $this->options['maxDimensions']['height'] ?: NULL );
$response = (string) $image;
}
}
catch ( \Exception $e )
{
if ( $this->options['image'] )
{
throw new \DomainException( 'form_url_bad_mime' );
}
}
}
/* Write file if necessary */
if ( $this->options['file'] )
{
$filename = preg_replace( "/(.+?)(\?|$)/", "$1", mb_substr( $value, mb_strrpos( $value, '/' ) + 1 ) );
try
{
$this->value = \IPS\File::create( $this->options['file'], $filename, $response );
}
catch( \InvalidArgumentException $e )
{
throw new \DomainException( 'form_url_error' );
}
}
}
}
}