diff --git a/bdd.php b/bdd.php index 82b07e7..d78c854 100644 --- a/bdd.php +++ b/bdd.php @@ -103,12 +103,12 @@ function saveFilesFromPost($postData,$id_ensemble) { foreach ($_FILES as $file) { $safe_type = checkFileTypeSecure($file['tmp_name']); - // Create a unique filename to avoid overwriting existing files - $uniqueFileName = uniqid() . '_' . $fileName; // Extract file information if (isset($file['name'])){ $fileName = htmlspecialchars($file['name']); + // Create a unique filename to avoid overwriting existing files + $uniqueFileName = uniqid() . '_' . $fileName; // le dernier check est pour autoriser l'upload de fichiers html aux admins if(!check_ext($fileName) || $safe_type == 0 || ($safe_type == 5 && !$_SESSION["admin"])){ echo(json_encode(["status"=>"0","msg"=>"le fichier '$fileName' n'a pas passé les filtres de contenu. ( dommaaaaggee :c )"])); diff --git a/index.php b/index.php index a6abb66..07938fb 100644 --- a/index.php +++ b/index.php @@ -34,6 +34,8 @@ S'inscrire Se connecter -