feat: VivesPOS landing on Winter CMS 1.2 — theme + plugin + Dockerfile
Some checks are pending
Module sub-split / Sub-split (push) Waiting to run
Some checks are pending
Module sub-split / Sub-split (push) Waiting to run
- Base: wintercms/winter branch 1.2 (full framework) - Theme vivespos: Canvas 7 + Bootstrap 5 CDN, custom CSS - Layout: deferred GTM/GA4 tracking, JSON-LD SoftwareApplication - Partials: hero (offline-first), features, modes (offline/nube toggle), screenshots, pricing (3 planes), comparison, FAQ, CTA - Plugin VivesPOS.Site with ContactForm - Dockerfile: PHP 8.2 Apache, port 80, healthcheck - Added winter/wn-pages, blog, sitemap, seo plugins - Active theme set to vivespos
This commit is contained in:
74
modules/cms/helpers/File.php
Normal file
74
modules/cms/helpers/File.php
Normal file
@@ -0,0 +1,74 @@
|
||||
<?php namespace Cms\Helpers;
|
||||
|
||||
use Config;
|
||||
use File as Filesystem;
|
||||
|
||||
/**
|
||||
* Defines some file-system helpers for the CMS system.
|
||||
*
|
||||
* @package winter\wn-system-module
|
||||
* @author Alexey Bobkov, Samuel Georges
|
||||
*/
|
||||
class File
|
||||
{
|
||||
/**
|
||||
* Validates a CMS object file or directory name.
|
||||
* CMS object file names can contain only alphanumeric symbols, dashes, underscores and dots.
|
||||
* Name can also begin with a component name, eg: MyComponent::filename.
|
||||
* @param string $fileName Specifies a path to validate
|
||||
* @return boolean Returns true if the file name is valid. Otherwise returns false.
|
||||
*/
|
||||
public static function validateName($fileName)
|
||||
{
|
||||
return preg_match('/^[a-z0-9\_\-\.\/]+$/i', $fileName) ? true : false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Validates whether a file has an allowed extension.
|
||||
* @param string $fileName Specifies a path to validate
|
||||
* @param array $allowedExtensions A list of allowed file extensions
|
||||
* @param boolean $allowEmpty Determines whether the file extension could be empty.
|
||||
* @return boolean Returns true if the file extension is valid. Otherwise returns false.
|
||||
*/
|
||||
public static function validateExtension($fileName, $allowedExtensions, $allowEmpty = true)
|
||||
{
|
||||
$extension = strtolower(pathinfo($fileName, PATHINFO_EXTENSION));
|
||||
if (empty($extension)) {
|
||||
return $allowEmpty;
|
||||
}
|
||||
|
||||
return in_array($extension, $allowedExtensions);
|
||||
}
|
||||
|
||||
/**
|
||||
* Validates a CMS object path.
|
||||
* CMS object directory and file names can contain only alphanumeric symbols, dashes and dots.
|
||||
* CMS objects support only a single level of subdirectories.
|
||||
* @param string $filePath Specifies a path to validate
|
||||
* @param integer $maxNesting Specifies the maximum allowed nesting level
|
||||
* @return boolean Returns true if the file name is valid. Otherwise returns false.
|
||||
*/
|
||||
public static function validatePath($filePath, $maxNesting = 2)
|
||||
{
|
||||
if (strpos($filePath, '..') !== false) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if (strpos($filePath, './') !== false || strpos($filePath, '//') !== false) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$segments = explode('/', $filePath);
|
||||
if ($maxNesting !== null && count($segments) > $maxNesting) {
|
||||
return false;
|
||||
}
|
||||
|
||||
foreach ($segments as $segment) {
|
||||
if (!self::validateName($segment)) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user