我正在创建一个人们可以上传图片的网站。但是,当最终用户上传包含特殊字符或外来字符的图像时,图像会上传,但无法在网站上显示,就像图像不存在于服务器上一样。 / p>
我看到很多人在另一篇帖子上回答说我需要使用preg_replace
但问题是,我真的不知道如何使用它。我将如何在我的代码中使用它。
这是我的控制器方法:
public function upload(Requests\CreatePostsRequest $request)
{
$target_dir = "uploads/";
$target_file = $target_dir . basename($_FILES['fileToUpload']["name"]);
$uploadOk = 1;
$findme = ".";
$pos = strpos($target_file, $findme);
//echo $target_file;
//dd($_POST);
echo ini_get('upload_max_filesize');
echo $_FILES["fileToUpload"]["error"];
$imageFileType = strtolower(substr($target_file,$pos+1));
if(isset($_POST["submit"])) {
$check = getimagesize($_FILES["fileToUpload"]["tmp_name"]);
//$check = true;
//dd($check);
if($check !== false) {
echo "File is an image - " . $check["mime"] . ".";
$uploadOk = 1;
} else {
echo "File is not an image.";
$uploadOk = 0;
}
}
$filecheck = 0;
$orgFileName = $target_file;
while (file_exists($target_file)) {
$target_file = substr($orgFileName,0,$pos).$filecheck.substr($orgFileName,$pos);
$filecheck++;
$uploadOk = 1;
}
if ($_FILES["fileToUpload"]["size"] > 500000000*8) {
echo "Sorry, your file is too large.";
$uploadOk = 0;
}
if($imageFileType != "jpg" && $imageFileType != "png" && $imageFileType != "jpeg"
&& $imageFileType != "gif" ) {
echo "Sorry, only JPG, JPEG, PNG & GIF files are allowed.";
echo $imageFileType;
$uploadOk = 0;
}
if ($uploadOk == 0) {
echo "Sorry, your file was not uploaded.";
} else {
if (move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $target_file)) {
echo "The file ". basename( $_FILES["fileToUpload"]["name"]). " has been uploaded.";
$post = new Posts($request->all());
$post->fileToUpload = $target_file;
Auth::user()->posts()->save($post);
} else {
echo "Sorry, there was an error uploading your file.";
}
}
return redirect('');
echo $target_file;
}
答案 0 :(得分:12)
使用preg替换:
$target_file = $target_dir . preg_replace("/[^a-z0-9\_\-\.]/i", '', basename($_FILES['fileToUpload']["name"]));
这将删除所有不是字母(a-z),数字(0-9)或短划线,下划线或点(我们希望保留文件扩展名)的字符。最后的i
标志使匹配大小写不敏感。
要缩短表达式,您可以将a-z0-9\_
- 部分替换为单词token \w
。
然后模式为:/[^\w\-\.]/
。这里我们不需要i
标志,因为单词token为我们处理。