--- loncom/publisher/loncfile.pm 2002/09/10 02:31:26 1.18 +++ loncom/publisher/loncfile.pm 2002/11/27 17:05:50 1.20 @@ -10,7 +10,7 @@ # # -# $Id: loncfile.pm,v 1.18 2002/09/10 02:31:26 foxr Exp $ +# $Id: loncfile.pm,v 1.20 2002/11/27 17:05:50 albertel Exp $ # # Copyright Michigan State University Board of Trustees # @@ -493,10 +493,11 @@ sub Rename1 { my $newfilename = $ENV{'form.newfilename'}; $request->print(&checksuffix($filename, $newfilename)); $request->print(&exists($user, $domain, $dir, $newfilename)); + my $dest=&SimplifyDir($dir,$newfilename); $request->print('

Rename '.$filename.' to '. - $dir.'/'.$newfilename.'?

'); + '">

Rename '.$filename.'
to '. + $dest.'?

'); &CloseForm1($request, $cancelurl); } else { $request->print('

No new filename specified

'); @@ -587,14 +588,14 @@ sub Copy1 { $cancelurl =~ s/\/public_html//; - if(-e $filename) { $request->print(&checksuffix($filename,$newfilename)); $request->print(&exists($user, $domain, $dir, $newfilename)); + my $dest=&SimplifyDir($dir,$newfilename); $request->print('

Copy '.$filename.' to'. - ''.$dir.'/'.$newfilename.'/?

'); + '">

Copy '.$filename.'
to '. + ''.$dest.'?

'); &CloseForm1($request, $cancelurl); } else { $request->print('

No such file '.$filename.'

'); @@ -603,6 +604,34 @@ sub Copy1 { =pod +=item SimplifyDir + + Removes all extra / and all .. references + +Parameters: + +=over 4 + +=item $dir - string [in] a directory name + +=item $file - string [in] a file reference relative to $dir + +=back + +Results: the concatenated path. + +=cut + +sub SimplifyDir { + my ($dir,$file) = @_; + my $location = $dir. '/'.$file; + $location=~s://+:/:g; # remove duplicate / + while ($location=~m:/\.\./:) {$location=~s:/[^/]+/\.\./:/:g;}#remove dir/.. + return $location; +} + +=pod + =item NewDir1 Does all phase 1 processing of directory creation: @@ -988,7 +1017,7 @@ sub phasetwo { # Once a resource is deleted, we just list the directory that # previously held it. # - $dest = $dir."/"; # Parent dir. + $dest = $dir."/."; # Parent dir. } elsif ($ENV{'form.action'} eq 'copy') { if($ENV{'form.newfilename'}) { if(!&Copy2($r, $uname, $dir, $fn, $ENV{'form.newfilename'})) { @@ -1017,11 +1046,12 @@ sub phasetwo { # construction space path. # &Debug($r, "Final url is: $dest"); - $dest =~ s/\/home\//\/priv\//; - $dest =~ s/\/public_html//; + $dest =~ s|/home/|/priv/|; + $dest =~ s|/public_html||; my $base = &File::Basename::basename($dest); my $dpath= &File::Basename::dirname($dest); + if ($base eq '.') { $base=''; } $dest = &HTML::Entities::encode($dpath.'/'.$base);