--- loncom/publisher/loncfile.pm 2003/03/08 01:41:53 1.28 +++ loncom/publisher/loncfile.pm 2003/06/20 15:30:13 1.33 @@ -9,7 +9,7 @@ # and displays a page showing the results of the action. # # -# $Id: loncfile.pm,v 1.28 2003/03/08 01:41:53 www Exp $ +# $Id: loncfile.pm,v 1.33 2003/06/20 15:30:13 www Exp $ # # Copyright Michigan State University Board of Trustees # @@ -92,6 +92,7 @@ use Apache::Constants qw(:common :http : use Apache::loncacc; use Apache::Log (); use Apache::lonnet; +use Apache::loncommon(); my $DEBUG=0; my $r; # Needs to be global for some stuff RF. @@ -387,6 +388,17 @@ sub checksuffix { } return $result; } + +sub cleanDest { + my ($request,$dest)=@_; + #remove bad characters + if ($dest=~/[\#\?&]/) { + $request->print("
Invalid characters in requested name have been removed.
"); + $dest=~s/[\#\?&]//g; + } + return $dest; +} + =pod =item CloseForm1($request, $user, $file) @@ -412,7 +424,7 @@ sub CloseForm1 { &Debug($request, "Cancel url is: ".$cancelurl); $request->print(''); $request->print(''); + '" method="POST">'); } @@ -494,7 +506,7 @@ sub Rename1 { if(-e $conspace) { if($ENV{'form.newfilename'}) { my $newfilename = $ENV{'form.newfilename'}; - if ($newfilename =~ m|^[^\.]+$|) { + if ($newfilename =~ m|/[^\.]+$|) { #no extension add on orignal extension if ($filename =~ m|/[^\.]*\.([^\.]+)$|) { $newfilename.='.'.$1; @@ -792,9 +804,9 @@ sub NewFile1 { &Debug($request, "Dest url is: ".$dest); $request->print(''); $request->print(''); + '" method="POST">'); $request->print(''); + '" method="POST">'); } } @@ -836,7 +848,8 @@ sub phaseone { # my $conspace=ConstructionPathFromRelative($uname, $fn); - + $ENV{'form.newfilename'}=&cleanDest($r,$ENV{'form.newfilename'}); + $r->print('