diff --git a/app/admin/controller/Auth.php b/app/admin/controller/Auth.php index 7e1c87271..5f8d51c8e 100644 --- a/app/admin/controller/Auth.php +++ b/app/admin/controller/Auth.php @@ -80,7 +80,6 @@ class Auth extends Controller */ public function state() { - $this->_applyFormToken(); $this->_save($this->table, ['status' => input('status')]); } diff --git a/app/admin/controller/Config.php b/app/admin/controller/Config.php index c247b869d..d97c6d293 100644 --- a/app/admin/controller/Config.php +++ b/app/admin/controller/Config.php @@ -115,13 +115,11 @@ class Config extends Controller $post = $this->request->post(); if (!empty($post['storage']['allow_exts'])) { $exts = array_unique(explode(',', strtolower($post['storage']['allow_exts']))); + if (in_array('php', $exts)) $this->error('禁止上传可执行文件到本地服务器!'); sort($exts); - if (in_array('php', $exts)) { - $this->error('禁止上传可执行文件到本地服务器!'); - } $post['storage']['allow_exts'] = join(',', $exts); } - foreach ($post as $key => $value) sysconf($key, $value); + foreach ($post as $name => $value) sysconf($name, $value); $this->success('修改文件存储成功!'); }