← All changes
|
vendor/rosell-dk/webp-convert/src/Serve/ServeConvertedWebP.php
+9
-1
3.2.3
→
4.7.0
View file →
| @@ -3,8 +3,9 @@ | ||
| 3 | 3 | |
| 4 | 4 | use WebPConvert\Convert\Exceptions\ConversionFailedException; |
| 5 | 5 | use WebPConvert\Helpers\InputValidator; |
| 6 | 6 | use WebPConvert\Helpers\MimeType; |
| 7 | +use WebPConvert\Helpers\PathChecker; | |
| 7 | 8 | use WebPConvert\Serve\Exceptions\ServeFailedException; |
| 8 | 9 | use WebPConvert\Serve\Header; |
| 9 | 10 | use WebPConvert\Serve\Report; |
| 10 | 11 | use WebPConvert\Serve\ServeFile; |
| @@ -71,9 +72,16 @@ | ||
| 71 | 72 | * @return void |
| 72 | 73 | */ |
| 73 | 74 | public static function serveOriginal($source, $serveImageOptions = []) |
| 74 | 75 | { |
| 75 | - InputValidator::checkSource($source); | |
| 76 | + // PS: We do not use InputValidator::checkSource($source) because we want to be | |
| 77 | + // a bit more lenient here and allow any image to be served (even though ie webp does not | |
| 78 | + // qualify for being used as a source when converting) | |
| 79 | + | |
| 80 | + // Check that the filename is ok (no control chars, streamwrappers), and that the file exists | |
| 81 | + // and is not a dir | |
| 82 | + PathChecker::checkSourcePath($source); | |
| 83 | + | |
| 76 | 84 | $contentType = MimeType::getMimeTypeDetectionResult($source); |
| 77 | 85 | if (is_null($contentType)) { |
| 78 | 86 | throw new ServeFailedException('Rejecting to serve original (mime type cannot be determined)'); |
| 79 | 87 | } elseif ($contentType === false) { |