From 2024ccaf394be511e0dd81cc0a9ca0a3513404be Mon Sep 17 00:00:00 2001 From: Tobias Reich Date: Fri, 23 Jan 2015 21:52:19 +0100 Subject: [PATCH] Disallow import of the medium-folder --- php/modules/Import.php | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/php/modules/Import.php b/php/modules/Import.php index 15de375..c8313bb 100644 --- a/php/modules/Import.php +++ b/php/modules/Import.php @@ -71,9 +71,11 @@ class Import extends Module { } # Skip folders of Lychee - if ($path===LYCHEE_UPLOADS_BIG||($path . '/')===LYCHEE_UPLOADS_BIG||$path===LYCHEE_UPLOADS_THUMB||($path . '/')===LYCHEE_UPLOADS_THUMB) { - Log::error($database, __METHOD__, __LINE__, 'Given path is a reserved path of Lychee (' . $path . ')'); - return 'Error: Given path is a reserved path of Lychee!'; + if ($path===LYCHEE_UPLOADS_BIG||($path . '/')===LYCHEE_UPLOADS_BIG|| + $path===LYCHEE_UPLOADS_MEDIUM||($path . '/')===LYCHEE_UPLOADS_MEDIUM|| + $path===LYCHEE_UPLOADS_THUMB||($path . '/')===LYCHEE_UPLOADS_THUMB) { + Log::error($database, __METHOD__, __LINE__, 'The given path is a reserved path of Lychee (' . $path . ')'); + return 'Error: Given path is a reserved path of Lychee!'; } $error = false;