 recca0120    /
                    laravel-elfinder
                      recca0120    /
                    laravel-elfinder
                
                            This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
                                via PHP's auto-loading mechanism.
                                                    These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
| 1 | <?php | ||
| 2 | |||
| 3 | namespace Recca0120\Elfinder; | ||
| 4 | |||
| 5 | use Closure; | ||
| 6 | use ArrayObject; | ||
| 7 | use Illuminate\Support\Arr; | ||
| 8 | use Illuminate\Http\Request; | ||
| 9 | use Illuminate\Filesystem\Filesystem; | ||
| 10 | use Illuminate\Contracts\Routing\UrlGenerator; | ||
| 11 | |||
| 12 | class Options extends ArrayObject | ||
| 13 | { | ||
| 14 | /** | ||
| 15 | * $request. | ||
| 16 | * | ||
| 17 | * @var \Illuminate\Http\Request | ||
| 18 | */ | ||
| 19 | protected $request; | ||
| 20 | |||
| 21 | /** | ||
| 22 | * $files. | ||
| 23 | * | ||
| 24 | * @var \Illuminate\Filesystem\Filesystem | ||
| 25 | */ | ||
| 26 | protected $files; | ||
| 27 | |||
| 28 | /** | ||
| 29 | * $request. | ||
| 30 | * | ||
| 31 | * @var \Illuminate\Contracts\Routing\UrlGenerator | ||
| 32 | */ | ||
| 33 | protected $urlGenerator; | ||
| 34 | |||
| 35 | /** | ||
| 36 | * $config. | ||
| 37 | * | ||
| 38 | * @var array | ||
| 39 | */ | ||
| 40 | protected $config; | ||
| 41 | |||
| 42 | /** | ||
| 43 | * $options. | ||
| 44 | * | ||
| 45 | * @var array | ||
| 46 | */ | ||
| 47 | protected $options; | ||
| 48 | |||
| 49 | /** | ||
| 50 | * __construct. | ||
| 51 | * | ||
| 52 | * @param \Illuminate\Http\Request $request | ||
| 53 | * @param \Illuminate\Filesystem\Filesystem $files | ||
| 54 | * @param \Illuminate\Contracts\Routing\UrlGenerator $urlGenerator | ||
| 55 | * @param array $config | ||
| 56 | */ | ||
| 57 | 3 | public function __construct(Request $request, Filesystem $files, UrlGenerator $urlGenerator, $config = []) | |
| 0 ignored issues–
                            show             Bug
    
    
    
        introduced 
                            by  
  Loading history... | |||
| 58 |     { | ||
| 59 | 3 | $this->request = $request; | |
| 60 | 3 | $this->files = $files; | |
| 61 | 3 | $this->urlGenerator = $urlGenerator; | |
| 62 | 3 | $this->config = $config; | |
| 63 | 3 | $this->options = Arr::get($this->config, 'options', []); | |
| 0 ignored issues–
                            show It seems like  \Illuminate\Support\Arr:...ig, 'options', array())of type*is incompatible with the declared typearrayof property$options.Our type inference engine has found an assignment to a property that is incompatible with the declared type of that property. Either this assignment is in error or the assigned type should be added to the documentation/type hint for that property..  Loading history... | |||
| 64 | |||
| 65 | 3 | parent::__construct(array_merge($this->options, [ | |
| 66 | 3 | 'roots' => $this->getRoots(), | |
| 67 | 3 | ])); | |
| 68 | 3 | } | |
| 69 | |||
| 70 | /** | ||
| 71 | * getRoots. | ||
| 72 | * | ||
| 73 | * @return array | ||
| 74 | */ | ||
| 75 | 3 | protected function getRoots() | |
| 76 |     { | ||
| 77 | 3 | $accessControl = Arr::get($this->config, 'accessControl'); | |
| 78 | 3 | $roots = Arr::get($this->options, 'roots', []); | |
| 79 | 3 | $user = $this->request->user(); | |
| 80 | |||
| 81 | 3 |         return array_values(array_filter(array_map(function ($disk) use ($user, $accessControl) { | |
| 82 | 2 | $disk['driver'] = empty($disk['driver']) === true ? 'LocalFileSystem' : $disk['driver']; | |
| 83 | |||
| 84 | 2 |             if (empty($disk['path']) === false && ($disk['path'] instanceof Closure) === true) { | |
| 85 | 1 | $disk['path'] = call_user_func($disk['path']); | |
| 86 | 1 | } | |
| 87 | 2 | $method = 'create'.$disk['driver'].'Driver'; | |
| 88 | 2 | $method = method_exists($this, $method) === true ? $method : 'createDefaultDriver'; | |
| 89 | |||
| 90 | 2 | return call_user_func_array([$this, $method], [$disk, $user, $accessControl]); | |
| 91 | 3 | }, $roots))); | |
| 92 | } | ||
| 93 | |||
| 94 | /** | ||
| 95 | * createDefaultDriver. | ||
| 96 | * | ||
| 97 | * @param array $disk | ||
| 98 | * @param mixed $user | ||
| 99 | * @param mixed $accessControl | ||
| 100 | * @param bool $makeDirectory | ||
| 101 | * @return array | ||
| 102 | */ | ||
| 103 | 2 | protected function createDefaultDriver($disk, $user, $accessControl = null, $makeDirectory = false) | |
| 104 |     { | ||
| 105 | 2 |         if (strpos($disk['path'], '{user_id}') !== false) { | |
| 106 | 2 |             if (is_null($user) === true) { | |
| 107 | 1 | return; | |
| 108 | } | ||
| 109 | |||
| 110 | 1 | $userId = $user->id; | |
| 111 | 1 |             $disk['path'] = str_replace('{user_id}', $userId, $disk['path']); | |
| 112 | 1 |             $disk['URL'] = str_replace('{user_id}', $userId, $disk['URL']); | |
| 113 | 1 | } | |
| 114 | |||
| 115 | 2 |         if ($makeDirectory === true && $this->files->exists($disk['path']) === false) { | |
| 116 | 2 | $this->files->makeDirectory($disk['path'], 0755, true); | |
| 117 | 2 | } | |
| 118 | |||
| 119 | 2 | $disk['URL'] = $this->urlGenerator->to($disk['URL']); | |
| 120 | |||
| 121 | 2 | return array_merge([ | |
| 122 | 2 | 'accessControl' => $accessControl, | |
| 123 | 2 | 'autoload' => true, | |
| 124 | 2 | 'mimeDetect' => 'internal', | |
| 125 | 2 | 'tmbBgColor' => 'transparent', | |
| 126 | 2 | 'tmbCrop' => false, | |
| 127 | 2 | 'utf8fix' => true, | |
| 128 | 2 | ], $disk); | |
| 129 | } | ||
| 130 | |||
| 131 | /** | ||
| 132 | * createLocalFileSystemDriver. | ||
| 133 | * | ||
| 134 | * @param array $disk | ||
| 135 | * @param mixed $user | ||
| 136 | * @param mixed $accessControl | ||
| 137 | * @return array | ||
| 138 | */ | ||
| 139 | 2 | protected function createLocalFileSystemDriver($disk, $user, $accessControl = null) | |
| 140 |     { | ||
| 141 | 2 | return $this->createDefaultDriver($disk, $user, $accessControl, true); | |
| 142 | } | ||
| 143 | |||
| 144 | /** | ||
| 145 | * createTrashDriver. | ||
| 146 | * | ||
| 147 | * @param array $disk | ||
| 148 | * @param mixed $user | ||
| 149 | * @param mixed $accessControl | ||
| 150 | * @return array | ||
| 151 | */ | ||
| 152 | 2 | protected function createTrashDriver($disk, $user, $accessControl = null) | |
| 153 |     { | ||
| 154 | 2 | return $this->createDefaultDriver(array_merge([ | |
| 155 | 2 | 'id' => 1, | |
| 156 | 2 | ], $disk), $user, $accessControl, true); | |
| 157 | } | ||
| 158 | } | ||
| 159 | 
