up observations

This commit is contained in:
qronald
2017-05-31 16:34:08 -04:00
parent 6c997908ab
commit 208b821295

View File

@@ -152,7 +152,8 @@ class FilesManager
{ {
try { try {
$aData['prf_path'] = rtrim($aData['prf_path'], '/') . '/'; $aData['prf_path'] = rtrim($aData['prf_path'], '/') . '/';
if (!$aData['prf_filename'] || strpbrk($aData['prf_filename'], "\\/?%*:|\"<>") !== false) { $path = pathinfo($aData['prf_filename']);
if (!$aData['prf_filename'] || $path['dirname'] != '.') {
throw new \Exception(\G::LoadTranslation("ID_INVALID_VALUE_FOR", array('prf_filename'))); throw new \Exception(\G::LoadTranslation("ID_INVALID_VALUE_FOR", array('prf_filename')));
} }
$extention = strstr($aData['prf_filename'], '.'); $extention = strstr($aData['prf_filename'], '.');