From 0961139ea46c66990178fb2d5097515ea1bc6331 Mon Sep 17 00:00:00 2001 From: caoyanyi Date: Wed, 23 Mar 2022 09:14:27 +0800 Subject: [PATCH 1/4] * Fix bug #18017. --- module/user/model.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/module/user/model.php b/module/user/model.php index eadbe7e435..4ad6e0849c 100644 --- a/module/user/model.php +++ b/module/user/model.php @@ -126,7 +126,7 @@ class userModel extends model } else { - $firstLetter = ucfirst(substr($user->account, 0, 1)) . ':'; + $firstLetter = ucfirst(mb_substr($user->account, 0, 1)) . ':'; if(strpos($params, 'noletter') !== false or !empty($this->config->isINT)) $firstLetter = ''; $users[$account] = $firstLetter . (($user->deleted and strpos($params, 'realname') === false) ? $user->account : ($user->realname ? $user->realname : $user->account)); } From 290ff3677cf6c7f53d39a730d4e06e8c7dab642f Mon Sep 17 00:00:00 2001 From: caoyanyi Date: Wed, 23 Mar 2022 09:37:53 +0800 Subject: [PATCH 2/4] * Fix bug #18018. --- module/install/model.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/module/install/model.php b/module/install/model.php index c4ab6ccb7b..ecdc7c90bc 100644 --- a/module/install/model.php +++ b/module/install/model.php @@ -514,7 +514,7 @@ class installModel extends model /* Insert a company. */ $company = new stdclass(); - $company->name = $this->post->company; + $company->name = strip_tags($this->post->company); $company->admins = ",{$this->post->account},"; $this->dao->insert(TABLE_COMPANY)->data($company)->autoCheck()->exec(); if(!dao::isError()) From 39fbdad08ab742cb56f2a221aa4c752aceebf7f1 Mon Sep 17 00:00:00 2001 From: caoyanyi Date: Wed, 23 Mar 2022 09:50:06 +0800 Subject: [PATCH 3/4] * Fix bug #17620. --- module/upgrade/model.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/module/upgrade/model.php b/module/upgrade/model.php index 9fea8b78e4..f816b1b4d7 100644 --- a/module/upgrade/model.php +++ b/module/upgrade/model.php @@ -1260,7 +1260,7 @@ class upgradeModel extends model if(file_exists($fullPath)) { $isDir = is_dir($fullPath); - if(($isDir and !$zfile->removeDir($fullPath)) or + if(!is_writable($fullPath) or ($isDir and !$zfile->removeDir($fullPath)) or (!$isDir and !$zfile->removeFile($fullPath))) { $result[] = 'rm -f ' . ($isDir ? '-r ' : '') . $fullPath; From 203a3607d8cf327eabe63917a7b28ea9f8c4fa02 Mon Sep 17 00:00:00 2001 From: caoyanyi Date: Wed, 23 Mar 2022 11:32:56 +0800 Subject: [PATCH 4/4] * Adjust codes. --- module/install/model.php | 8 ++++++-- module/upgrade/model.php | 2 +- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/module/install/model.php b/module/install/model.php index ecdc7c90bc..5961e2d9b2 100644 --- a/module/install/model.php +++ b/module/install/model.php @@ -502,10 +502,14 @@ class installModel extends model */ public function grantPriv() { + $data = fixer::input('post') + ->stripTags('company') + ->get(); + $requiredFields = explode(',', $this->config->install->step5RequiredFields); foreach($requiredFields as $field) { - if(empty($this->post->{$field})) + if(empty($data->{$field})) { dao::$errors[] = $this->lang->install->errorEmpty[$field]; return false; @@ -514,7 +518,7 @@ class installModel extends model /* Insert a company. */ $company = new stdclass(); - $company->name = strip_tags($this->post->company); + $company->name = $data->company; $company->admins = ",{$this->post->account},"; $this->dao->insert(TABLE_COMPANY)->data($company)->autoCheck()->exec(); if(!dao::isError()) diff --git a/module/upgrade/model.php b/module/upgrade/model.php index f816b1b4d7..62f61e14e6 100644 --- a/module/upgrade/model.php +++ b/module/upgrade/model.php @@ -1260,7 +1260,7 @@ class upgradeModel extends model if(file_exists($fullPath)) { $isDir = is_dir($fullPath); - if(!is_writable($fullPath) or ($isDir and !$zfile->removeDir($fullPath)) or + if(!is_writable($fullPath) or ($isDir and !$zfile->removeDir($fullPath)) or (!$isDir and !$zfile->removeFile($fullPath))) { $result[] = 'rm -f ' . ($isDir ? '-r ' : '') . $fullPath;