Update: 2026-07-30 02:27:45
This commit is contained in:
@@ -18,7 +18,9 @@ $userId = $decoded['user_id'];
|
||||
|
||||
// 1. Validate request
|
||||
$batchId = $_POST['batch_id'] ?? null;
|
||||
$imageOrder = (int)($_POST['image_order'] ?? 0);
|
||||
// The mobile client sends 'order_index'; accept both spellings so every image
|
||||
// does not end up with order 0 (which also made every saved file img_000_*).
|
||||
$imageOrder = (int)($_POST['image_order'] ?? $_POST['order_index'] ?? 0);
|
||||
|
||||
if (!$batchId || !isset($_FILES['image']) || $_FILES['image']['error'] !== UPLOAD_ERR_OK) {
|
||||
$uploadError = $_FILES['image']['error'] ?? 'No file';
|
||||
@@ -46,11 +48,20 @@ if ($batch['status'] !== 'uploading') {
|
||||
json_error('لا يمكن إضافة صور لدفعة تمت معالجتها', 400);
|
||||
}
|
||||
|
||||
// 3. Validate file type
|
||||
$allowedTypes = ['image/jpeg', 'image/png', 'image/webp', 'image/heic', 'image/heif', 'application/pdf'];
|
||||
$mimeType = $_FILES['image']['type'];
|
||||
if (!in_array($mimeType, $allowedTypes)) {
|
||||
json_error('نوع الملف غير مدعوم. المسموح: صور و PDF', 422);
|
||||
// 3. Validate file type.
|
||||
// Sniff the real type off the temp file - $_FILES[...]['type'] is supplied by the
|
||||
// client and can claim anything.
|
||||
$allowedTypes = [
|
||||
'image/jpeg' => 'jpg',
|
||||
'image/png' => 'png',
|
||||
'image/webp' => 'webp',
|
||||
'image/heic' => 'heic',
|
||||
'image/heif' => 'heif',
|
||||
'application/pdf' => 'pdf',
|
||||
];
|
||||
$mimeType = @mime_content_type($_FILES['image']['tmp_name']) ?: '';
|
||||
if (!isset($allowedTypes[$mimeType])) {
|
||||
json_error('نوع الملف غير مدعوم. المسموح: صور (JPG, PNG, WEBP, HEIC) و PDF', 422);
|
||||
}
|
||||
|
||||
// 4. Validate file size (max 10MB)
|
||||
@@ -59,6 +70,16 @@ if ($_FILES['image']['size'] > $maxSize) {
|
||||
json_error('حجم الصورة أكبر من 10 ميغابايت', 422);
|
||||
}
|
||||
|
||||
// 4b. Enforce quota per image, not just once per batch. Checking only at
|
||||
// batches/create let a 50-image batch through on a single remaining credit.
|
||||
$queuedStmt = $db->prepare("SELECT COUNT(*) FROM invoice_processing_queue WHERE batch_id = ?");
|
||||
$queuedStmt->execute([$batchId]);
|
||||
$alreadyQueued = (int)$queuedStmt->fetchColumn();
|
||||
|
||||
if ($decoded['role'] !== 'super_admin') {
|
||||
\App\Middleware\QuotaMiddleware::checkInvoiceQuota($tenantId, $alreadyQueued + 1);
|
||||
}
|
||||
|
||||
// 5. Save file
|
||||
$companyId = $batch['company_id'];
|
||||
$uploadDir = STORAGE_PATH . '/invoices/' . $tenantId . '/' . $companyId . '/batches/' . $batchId;
|
||||
@@ -66,7 +87,7 @@ if (!is_dir($uploadDir)) {
|
||||
mkdir($uploadDir, 0755, true);
|
||||
}
|
||||
|
||||
$extension = pathinfo($_FILES['image']['name'], PATHINFO_EXTENSION) ?: 'jpg';
|
||||
$extension = $allowedTypes[$mimeType];
|
||||
$fileName = sprintf('img_%03d_%s.%s', $imageOrder, bin2hex(random_bytes(4)), $extension);
|
||||
$targetPath = $uploadDir . '/' . $fileName;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user