better-staridc-MNBT
1<?php
2if($egn=='ftpsc') {
3 //删除文件/目录
4 $lx=daddslashes($_POST['lx'] ?? '');
5 $filepath=daddslashes($_POST['path'] ?? '');
6 $filename=trim(daddslashes($_POST['name'] ?? ''));
7 if(substr($filepath,0,1)!='/')exit('{"code":"目录格式错误!"}');
8 if(strpos($filename,'/')!==false)exit('{"code":"文件名格式错误!"}');
9 if($filename=='.user.ini' && $lx=='file')exit('{"code":"错误!您在删除配置文件(.user.ini)!这是不被允许的!"}');
10 include("../class.php");
11 $api = new bt_api($btipe,$btkeye);
12 if($lx=='file') {
13 $r_data = $api->delwj($os_xt.$yhc['sqldz'].$filepath.$filename);
14 } else {
15 $r_data = $api->delwjj($filepath,$filename,[$yhc['btid'],$os_xt.$yhc['sqldz']]);
16 }
17 $r_data = $r_data ?: [];
18 logjl($yhc['user'],'文件删除','删除了文件'.$filepath.$filename,(($r_data['status']??'')=='true'?'删除成功':'删除失败'),$DB);
19 echo ($r_data['status']??'')=='true' ? '{"code":"删除成功"}' : '{"code":"'.($r_data['msg']??'未知错误').'"}';
20 exit;
21 return;
22}
23if($egn=='ftpscxz') {
24 //删除多个文件/目录
25 $idsze=daddslashes($_POST['idsz'] ?? '');
26 //被删除的文件(数组)
27 $path=daddslashes($_POST['path'] ?? '');
28 if(substr($path,0,1)!='/')exit('{"code":"目录格式错误!"}');
29 if(empty($idsze))exit('{"code":"您未选择需要删除的文件或目录!"}');
30 if(in_array('.user.ini',$idsze))exit('{"code":"错误!您在删除配置文件(.user.ini)!这是不被允许的!"}');
31 if($path==null)exit('{"code":"目录错误!"}');
32 include("../class.php");
33 $api = new bt_api($btipe,$btkeye);
34 $wjne=json_encode($idsze,256);
35 $r_data = $api->xzdelwj($path,$wjne,[$yhc['btid'],$os_xt.$yhc['sqldz']]);
36 //print_r($wjlj);
37 if($r_data['status']??false)json_exit('删除成功'); else json_exit($r_data['msg']??'');
38 return;
39}
40if($egn=='xjwj') {
41 //新建文件
42 $name=daddslashes($_POST['wjname'] ?? '');
43 $ml=daddslashes($_POST['ml'] ?? '');
44 if(substr($ml,0,1)!='/')exit('{"code":"目录格式错误!"}');
45 if(strpos($name,'/')!==false)exit('{"code":"文件名格式错误!"}');
46 include("../class.php");
47 $api = new bt_api($btipe,$btkeye);
48 $abc=$api->xjwj($os_xt.$yhc['sqldz'].$ml.$name);
49 $abc = $abc ?: [];
50 logjl($yhc['user'],'新建文件','新建了文件'.$ml.$name,(($abc['msg']??'')=='success'?'新建成功':'新建失败'),$DB);
51 json_exit($abc['msg']??'');
52 return;
53}
54if($egn=='xjwjj') {
55 //新建文件夹
56 $name=daddslashes($_POST['wjname']);
57 $ml=daddslashes($_POST['ml']);
58 if(substr($ml,0,1)!='/')exit('{"code":"目录格式错误!"}');
59 if(strpos($name,'/')!==false)exit('{"code":"文件名格式错误!"}');
60 include("../class.php");
61 $api = new bt_api($btipe,$btkeye);
62 $abc=$api->xjwjj($os_xt.$yhc['sqldz'].$ml.$name);
63 $abc = $abc ?: [];
64 logjl($yhc['user'],'新建目录','新建了目录'.$ml.$name,(($abc['msg']??'')=='success'?'新建成功':'新建失败'),$DB);
65 json_exit($abc['msg']??'');
66 return;
67}
68if($egn=='hqwj') {
69 //获取文件内容
70 $lw=daddslashes($_POST['wj'] ?? '');
71 if(substr($lw,0,1)!='/')exit('{"code":"文件不存在!"}');
72 include("../class.php");
73 $api = new bt_api($btipe,$btkeye);
74 $abc=$api->hqwjnr($os_xt.$yhc['sqldz'].$lw) ?: [];
75 exit($abc['data']??'');
76 return;
77}
78if($egn=='setwj') {
79 //修改文件内容
80 $lm=daddslashes($_POST['wj'] ?? '');
81 if(substr($lm,0,1)!='/')exit('{"code":"被修改文件不存在!"}');
82 $nr=$_POST['nr'] ?? '';
83 //赋值时不对文件内容进行转义
84 if(strpos($lm,'.user.ini')!==false)exit('{"code":"错误!您在修改配置文件(.user.ini)!这是不被允许的!"}');
85 include("../class.php");
86 $api = new bt_api($btipe,$btkeye);
87 $abc=$api->setwj(array($nr,$os_xt.$yhc['sqldz'].$lm));
88 $abc = $abc ?: [];
89 logjl($yhc['user'],'修改文件','修改了文件'.$lm,'修改成功',$DB);
90 json_exit($abc['msg']??'');
91 return;
92}
93if($egn=='hqdx') {
94 //获取文件大小
95 $lw=daddslashes($_POST['dw'] ?? '');
96 if(substr($lw,0,1)!='/')exit('{"code":"文件所在目录错误!"}');
97 include("../class.php");
98 $api = new bt_api($btipe,$btkeye);
99 $abc=$api->hqsize($os_xt.$yhc['sqldz'].$lw) ?: [];
100 exit('{"code":"'.($abc['size']??'0').'"}');
101 return;
102}
103if($egn=='setname') {
104 //重命名文件
105 $name=daddslashes($_POST['wjmc'] ?? '');
106 $jmc=daddslashes($_POST['wjjm'] ?? '');
107 $lj=($_POST['lj'] ?? '')=='' ? '/' : daddslashes($_POST['lj']);
108 if(substr($lj,0,1)!='/')exit('{"code":"目录格式错误!"}');
109 if(strpos($jmc,'/')!==false)exit('{"code":"旧文件名格式错误!"}');
110 if(strpos($name,'/')!==false)exit('{"code":"新文件名格式错误!"}');
111 if($jmc=='.user.ini')exit('{"code":"错误!您在重命名配置文件(.user.ini)!这是不被允许的!"}');
112 if($name=='.user.ini')exit('{"code":"错误!该文件(.user.ini)已存在!"}');
113 if($name==null)exit('{"code":"文件名禁止为空!"}');
114 include("../class.php");
115 $api = new bt_api($btipe,$btkeye);
116 $abc=$api->cxname(array($os_xt.$yhc['sqldz'],$lj,$jmc,$name));
117 $abc = $abc ?: [];
118 logjl($yhc['user'],'重命名','将'.$jmc.'重命名为'.$name,'重命名成功',$DB);
119 json_exit($abc['msg']??'');
120 return;
121}
122if($egn=='file_upload_size') {
123 //判断文件是否为断点续传
124 include("../class.php");
125 $api = new bt_api($btipe,$btkeye);
126 $path=$_POST['htl'] ?? '';
127 $file_name=trim($_POST['fename'] ?? '');
128 if(substr($path,0,1)!='/')exit('{"code":"目录格式错误!"}');
129 if($file_name==='' || strpos($file_name,'/')!==false)exit('{"code":"文件名格式错误!"}');
130 if($file_name==='.user.ini')exit('{"code":"禁止上传.user.ini配置文件!"}');
131 $abcm=$api->fileupa($os_xt.$yhc['sqldz'].$path.($_POST['fename']??'').'.'.($_POST['size']??'0').'.upload.tmp') ?: [];
132 $asei=($abcm['status']??false) ? ($abcm['msg']['size']??0) : 0;
133 exit(json_encode(['code'=>1,'size'=>$asei]));
134}
135if($egn=='fileupload') {
136 //上传文件
137 if(substr(($_POST['htl']??''),0,1)!='/')exit(json_encode(['error'=>1,'size'=>4,'msg'=>'目录格式错误!']));
138 if(strpos(($_POST['tempfilename']??''),'/')!==false)exit(json_encode(['error'=>1,'size'=>4,'msg'=>'上传的文件名格式错误!']));
139
140 if(in_array(($_POST['tempfilename']??''),['.user.ini','.user.ini.upload.tmp']))exit(json_encode(['error'=>1,'size'=>4,'msg'=>'禁止上传.user.ini配置文件!']));
141
142 include("../class.php");
143 $api = new bt_api($btipe,$btkeye);
144 if(!isset($_FILES['file']) || $_FILES['file']==null)exit(json_encode(['error'=>1,'size'=>4,'msg'=>'上传的文件不能为空']));
145 $websize=json_decode($yhc['hxa'],true);
146 $mbsize=round(($_POST['zsize'] ?? 0)/1048576);
147 if($mbsize>$websize['max'])exit(json_encode(['error'=>1,'size'=>4,'msg'=>'错误!上传的文件大于您的最大可用网页空间!故无法上传此文件']));
148 if($websize['max']<=$websize['dq'])exit(json_encode(['error'=>1,'size'=>4,'msg'=>'错误!网页空间已满!']));
149 if($mbsize>$websize['max']-$websize['dq'])exit(json_encode(['error'=>1,'size'=>4,'msg'=>'错误!上传的文件大于现在您当前可使用的网页空间!请清除空间至剩余'.$mbsize.'MB后再试']));
150 $abc=$api->fileups($os_xt.$yhc['sqldz'].($_POST['htl']??''),$_FILES['file']??[],$_POST['fesw']??'',$_POST['tempfilename']??'',$_POST['zsize']??'');
151 if(is_numeric($abc)) {
152 exit(json_encode(['error'=>0,'size'=>$abc]));
153 } else {
154 exit(json_encode(['error'=>1,'size'=>1,'msg'=>'上传成功!']));
155 }
156}
157if($egn=='listfile') {
158 $sorting=($_POST['sortOrder']??'')=='asc' ? 'False' : 'True';
159 //顺序或倒序
160 $paixu=$_POST['sort']??'';
161 $paixu=$paixu=='type' ? 'name' : $paixu;
162 //排序字段
163 $pagesize=$_POST['limit']??'';
164 $page=$_POST['page']??'';
165 $path=$_POST['path']??'';
166 if(substr($path,0,1)!='/')exit('{"code":"目录格式错误!"}');
167 include("../class.php");
168 $api = new bt_api($btipe,$btkeye);
169 $contents=$api->GetLogshqwjlo($os_xt.$yhc['sqldz'].$path,$sorting,$paixu,$pagesize,$page) ?: [];
170
171 //当前目录下所有文件
172 if(($contents['PATH']??'')==$conf['hxi'] || ($contents['PATH']??'')==$conf['hxo']) {
173 $contents=$api->GetLogshqwjlo($os_xt.$yhc['sqldz'],$sorting,$paixu,$pagesize,$page);
174 $paths='/';
175 } else {
176 $paths=$path;
177 }
178 $dir=dirfiles($contents['DIR']??[],'dir');
179 $file=dirfiles($contents['FILES']??[],'file');
180 $dirfile=array_merge($dir['file'],$file['file']);
181 //合并数组
182 $zzbds=preg_match('/共(\d+)条/', $contents['PAGE']??'', $matches);
183 $val=(int)($matches[1]??0);
184 if($val===1 && empty($dirfile))$val=0;
185 $data=array("total"=>$val,"path"=>$paths);
186 $data["rows"]=$dirfile;
187 exit(json_encode($data,256));
188 return;
189}
190if($egn=='filecp') {
191 //这里不使用宝塔自带的多文件复制,因为标记功能1个主机复制文件另外一个主机粘贴文件会出现跨站点复制文件
192 $yfile=$_POST['yfile'] ?? [];
193 $ypath=$_POST['ypath'] ?? '';
194 $xpath=$_POST['xpath'] ?? '';
195 $type=$_POST['type'] ?? '';
196 //1为复制,2为剪切
197 if(empty($yfile))exit('{"qk":"4","code":"错误!您未选择任何文件!"}');
198 if(substr($ypath,0,1)!='/')exit('{"qk":"4","code":"原目录格式错误!"}');
199 if(substr($xpath,0,1)!='/')exit('{"qk":"4","code":"新的目录格式错误!"}');
200 if(in_array('.user.ini',$yfile))exit('{"qk":"4","code":"错误!您在操作根目录的配置文件(.user.ini)!这是不被允许的!"}');
201 if(empty($yfile) || empty($ypath) || empty($xpath) || empty($type))exit('{"qk":"4","code":"错误!禁止留空!"}');
202 if($ypath==$xpath)exit('{"qk":"4","code":"错误!原目录与粘贴目录不能相同!"}');
203 if($xpath!='/') {
204 foreach ($yfile as $val) {
205 if(substr($xpath,0,mb_strlen($ypath.$val.'/'))==$ypath.$val.'/')exit('{"qk":"4","code":"错误的逻辑,从'.$ypath.$val.'粘贴到'.$xpath.'有包含关系,存在无限循环复制风险!"}');
206 }
207 }
208 include("../class.php");
209 $yes=0;
210 $no=0;
211 $api = new bt_api($btipe,$btkeye);
212 foreach ($yfile as $val) {
213 $abc=$api->filecopy($os_xt.$yhc['sqldz'].$ypath.$val,$os_xt.$yhc['sqldz'].$xpath.$val) ?: [];
214 if($abc['status']??false) {
215 $yes++;
216 } else {
217 $no++;
218 }
219 }
220 if($type==2) {
221 $api->xzdelwj($ypath,json_encode($yfile,256),[$yhc['btid'],$os_xt.$yhc['sqldz']]);
222 //删除原文件
223 $czname='剪切';
224 } else {
225 $czname='复制';
226 }
227 if($no==0) {
228 $msg=$czname.'成功!';
229 $qk=1;
230 } else {
231 $msg="<span class='text-success'>{$czname}成功{$yes}个文件,</span>{$czname}失败{$no}个文件";
232 $qk=4;
233 }
234 exit('{"qk":"'.$qk.'","code":"'.$msg.'"}');
235 logjl($yhc['user'],'文件操作',$czname.'了'.count($yfile).'个文件',($no==0?'操作成功':'部分失败'),$DB);
236 return;
237}
238if($egn=='fileys') {
239 //文件压缩
240 $filename=$_POST['file'] ?? [];
241 $dpath=$_POST['dpath'] ?? '';
242 $type=$_POST['type'] ?? '';
243 $path=$_POST['path'] ?? '';
244 if(substr($dpath,0,1)!='/')exit('{"qk":"4","code":"目录格式错误!"}');
245 if(substr($path,0,1)!='/')exit('{"qk":"4","code":"目录格式错误!"}');
246 if(empty($filename) || empty($dpath) || empty($type) || empty($path))exit('{"qk":"4","code":"错误!禁止留空!"}');
247 include("../class.php");
248 $api = new bt_api($btipe,$btkeye);
249 $zfc='';
250 foreach ($filename as $val) {
251 if($zfc=='') {
252 $zfc.=$val;
253 } else {
254 $zfc.=','.$val;
255 }
256 }
257 $data=$api->fileysr($zfc,$os_xt.$yhc['sqldz'].$dpath,$type,$os_xt.$yhc['sqldz'].$path) ?: [];
258 if($data['status']??false) {
259 $qk=1;
260 } else {
261 $qk=4;
262 }
263 exit('{"qk":"'.$qk.'","code":"'.($data['msg']??'').'"}');
264 logjl($yhc['user'],'文件压缩','压缩了文件到'.$dpath,(($data['status']??false)?'压缩成功':'压缩失败'),$DB);
265 return;
266}