Complete security audit fixes

This commit is contained in:
Thanakorn S
2026-03-09 14:31:39 +07:00
parent 93d903c4b2
commit 7cb78d013b
33 changed files with 317 additions and 313 deletions
+38 -8
View File
@@ -1,7 +1,6 @@
<?php
session_start();
require '../../../preset.php';
require '../../../assets/utils/db_auth.php';
$id = (int)$data['id'];
@@ -67,21 +66,52 @@
/** 3. PROCESSING NEW UPLOADS **/
$uploaded_names = [];
// Allowed MIME types whitelist
$allowed_mimes = ['image/jpeg', 'image/png', 'image/gif', 'image/webp', 'application/pdf'];
// Allowed extensions whitelist
$allowed_extensions = ['jpg', 'jpeg', 'png', 'gif', 'webp', 'pdf'];
// Max file size: 5MB
$max_size = 5 * 1024 * 1024;
if (isset($_FILES['contact_files'])) {
foreach ($_FILES['contact_files']['name'] as $key => $name) {
if ($_FILES['contact_files']['error'][$key] === UPLOAD_ERR_OK) {
$tmp_name = $_FILES['contact_files']['tmp_name'][$key];
$extension = pathinfo($name, PATHINFO_EXTENSION);
// Assign a unique ID to prevent filename collisions on the server
$file_id = uniqid() . "_" . time() . "." . $extension;
$tmp_name = $_FILES['contact_files']['tmp_name'][$key];
$file_size = $_FILES['contact_files']['size'][$key];
$extension = strtolower(pathinfo($name, PATHINFO_EXTENSION));
// Check 1: File size
if ($file_size > $max_size) {
error_log("Rejected oversized file: " . $name);
continue;
}
// Check 2: Extension whitelist
if (!in_array($extension, $allowed_extensions)) {
error_log("Rejected extension: " . $name);
continue;
}
// Check 3: Real MIME type (reads actual file bytes, not filename)
$finfo = finfo_open(FILEINFO_MIME_TYPE);
$mime = finfo_file($finfo, $tmp_name);
finfo_close($finfo);
if (!in_array($mime, $allowed_mimes)) {
error_log("Rejected MIME type: " . $mime . " for file: " . $name);
continue;
}
// Safe unique filename — no original extension trusted
$file_id = uniqid() . "_" . time() . "." . $extension;
$destination = $target_dir . $file_id;
if (move_uploaded_file($tmp_name, $destination)) {
$uploaded_names[] = $file_id;
// Standard readable permission
chmod($destination, 0644);
chmod($destination, 0644);
} else {
error_log("Failed to move uploaded file: " . $name);
}