PluginProbe
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization / trunk
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization vtrunk
4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 2.5.5 2.5.6 2.5.7 3.0.0 3.0.1 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.11.0 3.11.1 3.11.2 3.11.3 All 136 releases
← All changes | inc/media_rename/attachment_replace.php +72 -1 4.2.11 → trunk View file →
@@ -76,8 +76,14 @@
76 76 if ( $original_filetype['type'] !== $uploaded_filetype['type'] ) {
77 77 return new WP_Error( 'file_error', __( 'The uploaded file type does not match the original file type.', 'optimole-wp' ) );
78 78 }
79 79
80 + if ( $uploaded_filetype['type'] === 'image/svg+xml' ) {
81 + if ( ! Optml_Main::instance()->admin->sanitize_svg( $this->file['tmp_name'] ) ) {
82 + return new WP_Error( 'file_error', __( 'Error uploading file.', 'optimole-wp' ) );
83 + }
84 + }
85 +
80 86 global $wp_filesystem;
81 87
82 88 if ( ! $wp_filesystem->move( $this->file['tmp_name'], $original_file, true ) ) {
83 89 return new WP_Error( 'file_error', __( 'Could not move file.', 'optimole-wp' ) );
@@ -82,9 +88,9 @@
82 88 if ( ! $wp_filesystem->move( $this->file['tmp_name'], $original_file, true ) ) {
83 89 return new WP_Error( 'file_error', __( 'Could not move file.', 'optimole-wp' ) );
84 90 }
85 91
86 - $wp_filesystem->chmod( $original_file, FS_CHMOD_FILE );
92 + $permissions_normalized = $this->normalize_file_permissions( $original_file );
87 93
88 94 $this->remove_all_image_sizes();
89 95
90 96 clean_attachment_cache( $this->attachment_id );
@@ -101,9 +107,74 @@
101 107 $this->handle_scaled_images();
102 108
103 109 do_action( 'optml_attachment_replaced', $this->attachment_id );
104 110
111 + if ( ! $permissions_normalized ) {
112 + return new WP_Error( 'file_permissions_error', __( 'Error replacing file', 'optimole-wp' ) );
113 + }
114 +
105 115 return true;
116 + }
117 +
118 + /**
119 + * Normalize the permissions of the replaced file.
120 + *
121 + * @param string $file File path.
122 + *
123 + * @return bool Whether the file ended up with the expected permissions.
124 + */
125 + private function normalize_file_permissions( $file ) {
126 + global $wp_filesystem;
127 +
128 + $mode = defined( 'FS_CHMOD_FILE' ) ? FS_CHMOD_FILE : 0644;
129 +
130 + $applied = $wp_filesystem->chmod( $file, $mode );
131 +
132 + $reason = '';
133 +
134 + if ( ! $applied || ! $this->has_permissions( $file, $mode ) ) {
135 + // Fallback for transports where the filesystem abstraction can't chmod.
136 + set_error_handler(
137 + function ( $errno, $errstr ) use ( &$reason ) {
138 + $reason = $errstr;
139 +
140 + return true;
141 + }
142 + );
143 +
144 + $applied = chmod( $file, $mode );
145 +
146 + restore_error_handler();
147 + }
148 +
149 + if ( $applied && $this->has_permissions( $file, $mode ) ) {
150 + return true;
151 + }
152 +
153 + if ( OPTML_DEBUG ) {
154 + do_action(
155 + 'optml_log',
156 + sprintf( 'Could not normalize permissions to %o for replaced file %s. %s', $mode, $file, $reason )
157 + );
158 + }
159 +
160 + return false;
161 + }
162 +
163 + /**
164 + * Check the current permissions of a file against an expected mode.
165 + *
166 + * @param string $file File path.
167 + * @param int $mode Expected mode.
168 + *
169 + * @return bool
170 + */
171 + private function has_permissions( $file, $mode ) {
172 + clearstatcache( true, $file );
173 +
174 + $perms = fileperms( $file );
175 +
176 + return false !== $perms && ( $perms & 0777 ) === ( $mode & 0777 );
106 177 }
107 178
108 179 /**
109 180 * Remove all image sizes files.