X-Git-Url: http://git.shiar.nl/minimedit.git/blobdiff_plain/621fc2f9638a1a92aa8535310e7852de5542f11e..04a1a7a24edbf8423a48f51609d545a5a7a3eb42:/upload.inc.php?ds=sidebyside
diff --git a/upload.inc.php b/upload.inc.php
index 6175fe2..d7d572d 100644
--- a/upload.inc.php
+++ b/upload.inc.php
@@ -27,6 +27,9 @@ function userupload($input, $target = NULL, $filename = NULL)
$target .= $input['name'];
}
+ if (file_exists($target)) {
+ throw new Exception("bestandsnaam al aanwezig op $target");
+ }
if (!@move_uploaded_file($input['tmp_name'], $target)) {
throw new Exception("bestand kon niet worden opgeslagen in $target");
}
@@ -48,10 +51,13 @@ function messagehtml($input)
if ($User->admin and preg_match('/\A<[a-z][^>]*>/', $input)) {
return $input; # allow html input as is if privileged
}
- $html = preg_replace(
- ["/\r?\n/", "'(?:
\n?){2}'"],
- ["
\n", "
"],
- htmlspecialchars($input)
- );
+ $markup = [
+ "/\r\n?/" => "\n", # unix newlines
+ "/ +\n/" => "
", # trailing spaces for hard line break
+ "/\n/" => "
", # newlines start paragraphs + '/\b_(\w+)_\b/' => '$1', # italic + '/\b\*(\w+)\*\b/' => '$1', # bold + ]; + $html = preg_replace(array_keys($markup), array_values($markup), htmlspecialchars($input)); return "
$html
"; }