Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/Http/Controllers/HandleActionController.php
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ protected function resolveActionInstance(Request $request): Action

$actionClass = str_replace('_', '\\', $request->get('_action'));

if (! class_exists($actionClass)) {
if (! class_exists($actionClass) || ! is_subclass_of($actionClass, Action::class)) {
throw new AdminException("Action [{$actionClass}] does not exist.");
}

Expand Down
4 changes: 4 additions & 0 deletions src/Http/Controllers/RenderableController.php
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,10 @@ protected function newRenderable(Request $request): LazyRenderable

$class = str_replace('_', '\\', $class);

if (! class_exists($class) || ! is_subclass_of($class, LazyRenderable::class)) {
throw new \InvalidArgumentException("Renderable [{$class}] does not exist or does not implement LazyRenderable.");
}

$renderable = new $class();

$renderable->payload($request->all());
Expand Down
23 changes: 22 additions & 1 deletion src/Http/Controllers/TinymceController.php
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ class TinymceController
public function upload(Request $request)
{
$file = $request->file('file');
$dir = trim($request->get('dir'), '/');
$dir = $this->sanitizeDir($request->get('dir'));
$disk = $this->disk();

$newName = $this->generateNewName($file);
Expand All @@ -27,13 +27,34 @@ protected function generateNewName(UploadedFile $file)
return uniqid(md5($file->getClientOriginalName()), true).'.'.$file->getClientOriginalExtension();
}

/**
* Sanitize directory path to prevent path traversal.
*/
protected function sanitizeDir(?string $dir): string
{
$dir = trim($dir ?? '', '/');

// 移除路径遍历字符
$dir = str_replace(['../', '..\\', '..'], '', $dir);

// 确保路径不以点开头(隐藏文件)
$dir = ltrim($dir, '.');

return $dir ?: 'uploads';
}

/**
* @return \Illuminate\Contracts\Filesystem\Filesystem|FilesystemAdapter
*/
protected function disk()
{
$disk = request()->get('disk') ?: config('admin.upload.disk');

// 验证磁盘配置存在
if (! config("filesystems.disks.{$disk}")) {
$disk = config('admin.upload.disk', 'local');
}

return Storage::disk($disk);
}
}
5 changes: 2 additions & 3 deletions src/Repositories/EloquentRepository.php
Original file line number Diff line number Diff line change
Expand Up @@ -872,9 +872,8 @@ protected function updateRelation(Form $form, EloquentModel $model, array $relat
$parent->save();

// When in creating, associate two models
$foreignKeyMethod = version_compare(app()->version(), '5.8.0', '<') ? 'getForeignKey' : 'getForeignKeyName';
if (! $model->{$relation->{$foreignKeyMethod}()}) {
$model->{$relation->{$foreignKeyMethod}()} = $parent->getKey();
if (! $model->{$relation->getForeignKeyName()}) {
$model->{$relation->getForeignKeyName()} = $parent->getKey();

$model->save();
}
Expand Down
Loading