Product: FILE uploads
This commit is contained in:
@@ -289,10 +289,12 @@ class FileUploader {
|
||||
|
||||
private function ensureDirectory() {
|
||||
if (!is_dir($this->target_dir)) {
|
||||
mkdir($this->target_dir, 0755, true);
|
||||
if (!mkdir($this->target_dir, 0755, true)) {
|
||||
throw new Exception("Failed to create directory: " . $this->target_dir);
|
||||
}
|
||||
}
|
||||
if (!is_writable($this->target_dir)) {
|
||||
throw new Exception("Target directory is not writable.");
|
||||
throw new Exception("Target directory is not writable: " . $this->target_dir);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -325,16 +327,25 @@ class FileUploader {
|
||||
|
||||
$errors = [];
|
||||
|
||||
foreach ($_FILES[$field_name]['name'] as $key => $name) {
|
||||
$error_code = $_FILES[$field_name]['error'][$key];
|
||||
// Normalize single file to array structure
|
||||
$files = $_FILES[$field_name];
|
||||
if (!is_array($files['name'])) {
|
||||
$files['name'] = [$files['name']];
|
||||
$files['tmp_name'] = [$files['tmp_name']];
|
||||
$files['error'] = [$files['error']];
|
||||
$files['size'] = [$files['size']];
|
||||
}
|
||||
|
||||
foreach ($files['name'] as $key => $name) {
|
||||
$error_code = $files['error'][$key];
|
||||
|
||||
if ($error_code !== UPLOAD_ERR_OK) {
|
||||
$errors[] = "{$name}: " . $this->getUploadError($error_code);
|
||||
continue;
|
||||
}
|
||||
|
||||
$tmp_name = $_FILES[$field_name]['tmp_name'][$key];
|
||||
$file_size = $_FILES[$field_name]['size'][$key];
|
||||
$tmp_name = $files['tmp_name'][$key];
|
||||
$file_size = $files['size'][$key];
|
||||
$extension = strtolower(pathinfo($name, PATHINFO_EXTENSION));
|
||||
|
||||
if ($file_size > $this->max_size) {
|
||||
@@ -356,7 +367,11 @@ class FileUploader {
|
||||
continue;
|
||||
}
|
||||
|
||||
$file_id = uniqid() . "_" . time() . "." . $extension;
|
||||
// FILE NAME SANITIZATION + UNIQUE ID
|
||||
$original = pathinfo($name, PATHINFO_FILENAME);
|
||||
$original = preg_replace('/[^a-zA-Z0-9_-]/', '_', $original); // sanitize
|
||||
$file_id = $original . "_" . uniqid() . "." . $extension;
|
||||
|
||||
$destination = $this->target_dir . $file_id;
|
||||
|
||||
if (move_uploaded_file($tmp_name, $destination)) {
|
||||
@@ -378,6 +393,13 @@ class FileUploader {
|
||||
$final = array_merge($keep, $this->uploaded_files);
|
||||
return implode(",", array_filter($final));
|
||||
}
|
||||
|
||||
/**
|
||||
* Build final CSV string for DB as single file
|
||||
*/
|
||||
public function getUploadedFiles() {
|
||||
return $this->uploaded_files;
|
||||
}
|
||||
|
||||
/**
|
||||
* Rollback uploaded files if DB fails
|
||||
|
||||
Reference in New Issue
Block a user