diff --git a/config/zentaopms.php b/config/zentaopms.php index 889fd58b98..31a2d4ee4c 100644 --- a/config/zentaopms.php +++ b/config/zentaopms.php @@ -140,6 +140,7 @@ $config->features = new stdclass(); $config->features->apiGetModel = false; $config->features->apiSQL = false; $config->features->cronSystemCall = false; +$config->features->checkClient = true; /* Define the tables. */ define('TABLE_COMPANY', '`' . $config->db->prefix . 'company`'); diff --git a/module/file/model.php b/module/file/model.php index 650f0cbfaa..8f8981da81 100644 --- a/module/file/model.php +++ b/module/file/model.php @@ -536,7 +536,8 @@ class fileModel extends model public function parseCSV($fileName) { /* Parse file only in zentao. */ - if(strpos(realpath($fileName), $this->app->getBasePath()) !== 0) return array(); + if(strpos($fileName, $this->app->getBasePath()) !== 0) return array(); + $content = file_get_contents($fileName); /* Fix bug #890. */ $content = str_replace(array("\r\n","\r"), "\n", $content); diff --git a/module/repo/lang/zh-cn.php b/module/repo/lang/zh-cn.php index 6fe790f7f5..69f50ca6c0 100644 --- a/module/repo/lang/zh-cn.php +++ b/module/repo/lang/zh-cn.php @@ -147,6 +147,7 @@ $lang->repo->error->version = "https和svn协议需要1.8及以上版本 $lang->repo->error->path = '版本库地址直接填写文件路径,如:/home/test。'; $lang->repo->error->cmd = '客户端错误!'; $lang->repo->error->diff = '必须选择两个版本'; +$lang->repo->error->safe = '因为安全原因,需要检测客户端版本,请将版本号写入文件 %s
可以执行命令:%s'; $lang->repo->error->product = "请选择{$lang->productCommon}!"; $lang->repo->error->commentText = '请填写评审内容'; $lang->repo->error->comment = '请填写内容'; diff --git a/module/repo/model.php b/module/repo/model.php index e249040b7d..04550906d4 100644 --- a/module/repo/model.php +++ b/module/repo/model.php @@ -189,11 +189,11 @@ class repoModel extends model */ public function create() { + if(!$this->checkClient()) return false; if(!$this->checkConnection()) return false; - $data = fixer::input('post')->skipSpecial('path,client,account,password')->get(); + $data = fixer::input('post')->setDefault('client', 'svn')->skipSpecial('path,client,account,password')->get(); $data->acl = empty($data->acl) ? '' : json_encode($data->acl); - if(empty($data->client)) $data->client = 'svn'; if($data->SCM == 'Subversion') { @@ -210,6 +210,9 @@ class repoModel extends model ->checkIF($data->SCM == 'Subversion', $this->config->repo->svn->requiredFields, 'notempty') ->autoCheck() ->exec(); + + $this->rmClientVersionFile(); + return $this->dao->lastInsertID(); } @@ -222,14 +225,16 @@ class repoModel extends model */ public function update($id) { - if(!$this->checkConnection()) return false; + $repo = $this->getRepoByID($id); - $data = fixer::input('post')->skipSpecial('path,client,account,password')->get(); + $data = fixer::input('post') + ->setDefault('client', 'svn') + ->setDefault('prefix', $repo->prefix) + ->setIF($this->post->path != $repo->path, 'synced', 0) + ->skipSpecial('path,client,account,password') + ->get(); $data->acl = empty($data->acl) ? '' : json_encode($data->acl); - if(empty($data->client)) $data->client = 'svn'; - $repo = $this->getRepoByID($id); - $data->prefix = $repo->prefix; if($data->SCM == 'Subversion' and $data->path != $repo->path) { $scm = $this->app->loadClass('scm'); @@ -243,7 +248,8 @@ class repoModel extends model $data->prefix = ''; } - if($data->path != $repo->path) $data->synced = 0; + if($data->client != $repo->client and !$this->checkClient()) return false; + if(!$this->checkConnection()) return false; if($data->encrypt == 'base64') $data->password = base64_encode($data->password); $this->dao->update(TABLE_REPO)->data($data) @@ -252,6 +258,8 @@ class repoModel extends model ->autoCheck() ->where('id')->eq($id)->exec(); + $this->rmClientVersionFile(); + if($repo->path != $data->path) { $this->dao->delete()->from(TABLE_REPOHISTORY)->where('repo')->eq($id)->exec(); @@ -905,6 +913,55 @@ class repoModel extends model ); } + /** + * Check svn/git client. + * + * @access public + * @return bool + */ + public function checkClient() + { + if(!$this->config->features->checkClient) return true; + if(!$this->post->client) return true; + + $clientVersionFile = $this->session->clientVersionFile; + if(empty($clientVersionFile)) + { + $clientVersionFile = $this->app->getLogRoot() . uniqid('version_') . '.log'; + + session_start(); + $this->session->set('clientVersionFile', $clientVersionFile); + session_write_close(); + } + + if(file_exists($clientVersionFile)) return true; + + $cmd = $this->post->client . " --version > $clientVersionFile"; + dao::$errors['client'] = sprintf($this->lang->repo->error->safe, $clientVersionFile, $cmd); + + return false; + } + + + /** + * remove client version file. + * + * @access public + * @return void + */ + public function rmClientVersionFile() + { + $clientVersionFile = $this->session->clientVersionFile; + if($clientVersionFile) + { + session_start(); + $this->session->set('clientVersionFile', $clientVersionFile); + session_write_close(); + + if(file_exists($clientVersionFile)) unlink($clientVersionFile); + } + } + /** * Check connection *