X-Git-Url: http://git.shiar.nl/minimedit.git/blobdiff_plain/28b4486013bb2738dfa16f27b73862e287d7f04d..5940cdf5f5ebc65bc181ea63979442eeb4858320:/upload.inc.php
diff --git a/upload.inc.php b/upload.inc.php
index afaa047..e270b76 100644
--- a/upload.inc.php
+++ b/upload.inc.php
@@ -27,6 +27,9 @@ function userupload($input, $target = NULL, $filename = NULL)
$target .= $input['name'];
}
+ if (file_exists($target)) {
+ throw new Exception("bestandsnaam al aanwezig op $target");
+ }
if (!@move_uploaded_file($input['tmp_name'], $target)) {
throw new Exception("bestand kon niet worden opgeslagen in $target");
}
@@ -41,13 +44,26 @@ function userupload($input, $target = NULL, $filename = NULL)
function messagehtml($input)
{
# convert user textarea post to formatted html
+ global $User;
if (empty($input)) {
return;
}
- $html = preg_replace(
- ["/\r?\n/", "'(?:
\n?){2}'"],
- ["
\n", "
"], - htmlspecialchars($input) - ); - return "
$html
"; + if ($User and $User->admin and preg_match('/\A<[a-z][^>]*>/', $input)) { + return $input; # allow html input as is if privileged + } + $markup = [ + '{<((?:\w+:|/).+?)>}' => '<$1>', # unescape link entities + '{<(?:https?://)?([^>\s|]+)>}' => '<$1 $1>', # unnamed link + '{<([^>\s|]+)[\s|]([^>]+)>}' => '$2', # hyperlink + "/\r\n?/" => "\n", # unix newlines + "/ +\n/" => "$1
\n", # paragraph + "{^(
$1
', # monospace
+ ];
+ return preg_replace(array_keys($markup), array_values($markup), htmlspecialchars($input));
}