From 266339fadeeefada5ad6c8683d3974c115f1d722 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E9=82=B9=E6=99=AF=E7=AB=8B?= Date: Wed, 15 Sep 2021 17:01:48 +0800 Subject: [PATCH] Update Upload.php --- app/admin/controller/api/Upload.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/app/admin/controller/api/Upload.php b/app/admin/controller/api/Upload.php index af8781349..71414988f 100644 --- a/app/admin/controller/api/Upload.php +++ b/app/admin/controller/api/Upload.php @@ -112,7 +112,9 @@ class Upload extends Controller $extension = strtolower($file->getOriginalExtension()); $saveName = input('key') ?: Storage::name($file->getPathname(), $extension, '', 'md5_file'); // 检查文件名称是否合法 - if (strpos($saveName, '../') !== false) $this->error('文件路径不能出现跳级操作!'); + if (strpos($saveName, '../') !== false) { + $this->error('文件路径不能出现跳级操作!'); + } // 检查文件后缀是否被恶意修改 if (pathinfo(parse_url($saveName, PHP_URL_PATH), PATHINFO_EXTENSION) !== $extension) { $this->error('文件后缀异常,请重新上传文件!');