1000000) { throw new RuntimeException('Exceeded filesize limit.'); }*/ // DO NOT TRUST $_FILES['upfile']['mime'] VALUE !! // Check MIME Type by yourself. if (function_exists('finfo_file') && (defined('FILEINFO_MIME_TYPE'))) { $r = finfo_open(FILEINFO_MIME_TYPE); if (false === $ext = array_search( finfo_file($r, $_FILES['file']['tmp_name']), array( 'jpg' => 'image/jpeg', 'png' => 'image/png', 'gif' => 'image/gif', ), true )) { self::accessDenied('Invalid file format.'); } } else { $ext = 'jpg'; // We set it to something, in case above fails. } $uploadfile = $uploaddir . '/' . sha1_file($_FILES['file']['tmp_name']) . '.' . $ext; //echo $uploadfile; if (move_uploaded_file($_FILES['file']['tmp_name'], $uploadfile)) { // File is valid, and was successfully uploaded $source = $uploadfile; /* if (!empty($password)) { $hash = md5(md5_file($source) . $password); if ($hash != $_POST['hash']) { self::accessDenied('Wrong password.'); } } */ $destination = $uploadfile . '.webp'; if (isset($_POST['options'])) { // Merge in options in $_POST, overwriting the webp-convert options in config $convertOptionsInPost = (array) json_decode($_POST['options'], true); $convertOptions = array_merge($options['webp-convert'], $convertOptionsInPost); } else { $convertOptions = $options['webp-convert']; } try { WebPConvert::convert($source, $destination, $convertOptions); header('Content-type: application/octet-stream'); echo file_get_contents($destination); unlink($source); unlink($destination); } catch (\Exception $e) { echo 'Conversion failed!'; echo $e->getMessage(); } } else { // Possible file upload attack! self::configurationError('Failed to move uploaded file'); //echo 'Failed to move uploaded file'; } } }