upload.php 2.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273
  1. <?php
  2. require 'system/includes/dispatch.php';
  3. require 'system/includes/session.php';
  4. // Load the configuration file
  5. config('source', 'config/config.ini');
  6. // Set the timezone
  7. if (config('timezone')) {
  8. date_default_timezone_set(config('timezone'));
  9. } else {
  10. date_default_timezone_set('Asia/Jakarta');
  11. }
  12. $whitelist = array('jpg', 'jpeg', 'jfif', 'pjpeg', 'pjp', 'png', 'gif', 'webp');
  13. $name = null;
  14. $dir = 'content/images/';
  15. $dirThumb = 'content/images/thumbnails/';
  16. $error = null;
  17. $timestamp = date('YmdHis');
  18. $path = null;
  19. $width = config('thumbnail.width');
  20. if (login()) {
  21. if (!is_dir($dir)) {
  22. mkdir($dir, 0755, true);
  23. }
  24. if (is_null($width) || empty($width)) {
  25. $width = 500;
  26. }
  27. if (isset($_FILES) && isset($_FILES['file'])) {
  28. $tmp_name = $_FILES['file']['tmp_name'];
  29. $name = basename($_FILES['file']['name']);
  30. $error = $_FILES['file']['error'];
  31. $path = $dir . $timestamp . '-' . $name;
  32. $check = getimagesize($tmp_name);
  33. if($check !== false) {
  34. if ($error === UPLOAD_ERR_OK) {
  35. $extension = pathinfo($name, PATHINFO_EXTENSION);
  36. if (!in_array(strtolower($extension), $whitelist)) {
  37. $error = 'Invalid file type uploaded.';
  38. } else {
  39. move_uploaded_file($tmp_name, $path);
  40. }
  41. $imageFile = pathinfo($path, PATHINFO_FILENAME);
  42. $thumbFile = $dirThumb . $imageFile. '-' . $width . '.webp';
  43. if (!file_exists($thumbFile)) {
  44. create_thumb($path, $width);
  45. }
  46. }
  47. } else {
  48. $error = "File is not an image.";
  49. }
  50. }
  51. header('Content-Type: application/json');
  52. echo json_encode(array(
  53. 'path' => $path,
  54. 'name' => $name,
  55. 'error' => $error,
  56. ));
  57. die();
  58. } else {
  59. $login = site_url() . 'login';
  60. header("location: $login");
  61. }