--- loncom/publisher/lonupload.pm 2010/02/16 10:26:17 1.49
+++ loncom/publisher/lonupload.pm 2023/07/23 11:54:56 1.71
@@ -1,8 +1,7 @@
-
# The LearningOnline Network with CAPA
# Handler to upload files into construction space
#
-# $Id: lonupload.pm,v 1.49 2010/02/16 10:26:17 bisitz Exp $
+# $Id: lonupload.pm,v 1.71 2023/07/23 11:54:56 raeburn Exp $
#
# Copyright Michigan State University Board of Trustees
#
@@ -70,7 +69,7 @@ Start page output
=item *
-output relevant interface phase (phaseone or phasetwo or phasethree)
+output relevant interface phase (phaseone, phasetwo, phasethree or phasefour)
=item *
@@ -99,6 +98,11 @@ as overwriting an existing file).
Interface for handling secondary uploads of embedded objects
in an html file.
+=item phasefour()
+
+Interface for handling optional renaming of links to embedded
+objects.
+
=item upfile_store()
Store contents of uploaded file into temporary space. Invoked
@@ -121,13 +125,12 @@ use Apache::File;
use File::Copy;
use File::Basename;
use Apache::Constants qw(:common :http :methods);
-use Apache::loncacc;
use Apache::loncommon();
use Apache::lonnet;
use HTML::Entities();
use Apache::lonlocal;
use Apache::lonnet;
-use LONCAPA();
+use LONCAPA qw(:DEFAULT :match);
my $DEBUG=0;
@@ -147,8 +150,12 @@ sub upfile_store {
chomp($env{'form.upfile'});
- my $datatoken=$env{'user.name'}.'_'.$env{'user.domain'}.
- '_upload_'.$fname.'_'.time.'_'.$$;
+ my $datatoken;
+ if (($env{'user.name'} =~ /^$match_username$/) && ($env{'user.domain'} =~ /^$match_domain$/)) {
+ $datatoken=$env{'user.name'}.'_'.$env{'user.domain'}.
+ '_upload_'.$fname.'_'.time.'_'.$$;
+ }
+ return if ($datatoken eq '');
{
my $fh=Apache::File->new('>'.$r->dir_config('lonDaemons').
'/tmp/'.$datatoken.'.tmp');
@@ -158,7 +165,7 @@ sub upfile_store {
}
sub phaseone {
- my ($r,$fn,$uname,$udom,$mode)=@_;
+ my ($r,$fn,$mode,$uname,$udom)=@_;
my $action = '/adm/upload';
if ($mode eq 'testbank') {
$action = '/adm/testbank';
@@ -169,17 +176,16 @@ sub phaseone {
# Check for file to be uploaded
$env{'form.upfile.filename'}=~s/\\/\//g;
$env{'form.upfile.filename'}=~s/^.*\/([^\/]+)$/$1/;
+ $env{'form.upfile.filename'}=~s/(\s+$|^\s+)//g;
if (!$env{'form.upfile.filename'}) {
- $r->print('
'.&mt('No upload file specified.').'
');
+ $r->print('
'.&mt('No upload file specified.').'
'.
+ &earlyout($fn,$uname,$udom));
return;
}
- $fn=~s/\/[^\/]+$//;
- $fn=~s/([^\/])$/$1\//;
+ # Append the name of the uploaded file
$fn.=$env{'form.upfile.filename'};
- $fn=~s/^\///;
$fn=~s/(\/)+/\//g;
- # Fn is the full path to the destination filename.
# Check for illegal filename
&Debug($r, "Filename for upload: $fn");
@@ -187,20 +193,49 @@ sub phaseone {
$r->print('
'.&mt('Illegal filename.').'
');
return;
}
+ # Check if quota exceeded
+ my $filesize = length($env{'form.upfile'});
+ if (!$filesize) {
+ $r->print('
'.
+ &mt('Unable to upload [_1]. (size = [_2] bytes)',
+ ''.$env{'form.upfile.filename'}.'',
+ $filesize).' '.
+ &mt('Either the file you attempted to upload was empty, or your web browser was unable to read its contents.').' '.
+ '
'.
+ &earlyout($fn,$uname,$udom));
+ return;
+ }
+ $filesize = int($filesize/1000); #expressed in kb
+ my $output = &Apache::loncommon::excess_filesize_warning($uname,$udom,'author',
+ $env{'form.upfile.filename'},$filesize,'upload');
+ if ($output) {
+ $r->print($output.&earlyout($fn,$uname,$udom));
+ return;
+ }
+# Split part that I can change from the part that I cannot change
+ my ($fn1,$fn2)=($fn=~/^(\/priv\/[^\/]+\/[^\/]+\/)(.*)$/);
+# Check for pattern: .number.extension which is reserved for LON-CAPA versioning.
+# Check for disallowed characters: #?&%:<>`|, and remove
+ if ($fn2 ne '') {
+ ($fn2,my $warning) = &check_filename($fn2);
+ if ($warning ne '') {
+ $r->print($warning);
+ }
+ }
# Display additional options for upload
# and upload button
$r->print(
'