I`m using custom form request to validate all input data to store users.
I need validate the input before send to form request, and get all validated data in my controller.
I have a regex function ready to validate this input, removing unwanted characters, spaces, allow only numbers and etc.
Would to get all data validated in controller, but still have no success.
Input example:
$cnpj= 29.258.602/0001-25
How i need in controller:
$cnpj= 29258602000125
class UsuarioController extends BaseController
public function cadastrarUsuarioExterno(UsuarioStoreFormRequest $request)
//Would to get all input validated - no spaces, no!##$%^&*, etc
$validated = $request->validated();
namespace App\Http\Requests;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Http\Request;
class UsuarioStoreFormRequest extends FormRequest
* Determine if the user is authorized to make this request.
* #return bool
public function authorize()
return true;
* Get the validation rules that apply to the request.
* #return array
public function rules()
return [
'cnpj' => 'required|numeric|digits:14',
Custom function to validate cnpj
function validar_cnpj($cnpj)
$cnpj = preg_replace('/[^0-9]/', '', (string) $cnpj);
// Valida tamanho
if (strlen($cnpj) != 14)
return false;
// Valida primeiro dígito verificador
for ($i = 0, $j = 5, $soma = 0; $i < 12; $i++)
$soma += $cnpj{$i} * $j;
$j = ($j == 2) ? 9 : $j - 1;
$resto = $soma % 11;
if ($cnpj{12} != ($resto < 2 ? 0 : 11 - $resto))
return false;
// Valida segundo dígito verificador
for ($i = 0, $j = 6, $soma = 0; $i < 13; $i++)
$soma += $cnpj{$i} * $j;
$j = ($j == 2) ? 9 : $j - 1;
$resto = $soma % 11;
return $cnpj{13} == ($resto < 2 ? 0 : 11 - $resto);

You could use the prepareForValidation method in your FormRequest. This way your input would be modified and replaced in the request before it is validated and you can normally retrieve it in the controller with $request->get('cnpj'); after the validation was successful.
public function prepareForValidation()
$input = $this->all();
if ($this->has('cnpj')) {
$input['cnpj'] = $this->get('cnpj'); // Modify input here

You could extend the validated function in UsuarioStoreFormRequest as follows
* Get the validated data from the request.
* #return array
public function validated()
$validated = parent::validated();
//Add here more characters to remove or use a regex
$validated['cnpj'] = str_replace(['-', '/', ' ', '.'], '', $validated['cnpj']);
return $validated;

Do it like this:
$string = "29.258.602/0001-25";
preg_match_all('!\d+!', $string, $matches);
return (implode("",$matches[0]));
Hope its help


Sorting League Standings table

Am doing a league management system where the system generates fixtures and assign each match to an official who later enters results. Now when i have set everything possible for the log table but when i pass the results, am getting the some few errors : Too few arguments to function App\Models\Gamescores::updateStandings(), 0 passed in E:\Video\laraVids\laraProjects\HAM\app\Models\Gamescores.php on line 28 and exactly 1 expected
here is my code for the sorting of the league
class Gamescores extends Model
use HasFactory;
protected $table = 'gamescores';
protected $fillable = [
public function game()
return $this->belongsTo(Game::class, 'games_id');
public static function boot()
static::created(function ($gamescore) {
public function updateStandings($league_id)
// Get all gamescores for the specified league
$gameScores = Gamescores::whereHas('game', function ($query) use ($league_id) {
$query->where('league_id', $league_id);
// Loop through each gamescore and update the log table for each team
foreach ($gameScores as $gameScore) {
$game = Games::find($gameScore->games_id);
$league_id = $game->league_id;
$home_team_id = $game->home_team;
$away_team_id = $game->away_team;
$home_team_log = Logtable::where('team_id', $home_team_id)->first();
if ($home_team_log !== null) {
$home_team_log->played += 1;
if ($gameScore->home_score > $gameScore->away_score) {
$home_team_log->won += 1;
$home_team_log->points += 3;
} else if ($gameScore->home_score == $gameScore->away_score) {
$home_team_log->drawn += 1;
$home_team_log->points += 1;
} else {
$home_team_log->lost += 1;
$home_team_log->goals_for += $gameScore->home_score;
$home_team_log->goals_against += $gameScore->away_score;
$home_team_log->goal_difference = $home_team_log->goals_for - $home_team_log->goals_against;
$away_team_log = Logtable::where('team_id', $away_team_id)->first();
if ($away_team_log !== null) {
$away_team_log->played += 1;
if ($gameScore->away_score > $gameScore->home_score) {
$away_team_log->won += 1;
$away_team_log->points += 3;
} else if ($gameScore->home_score == $gameScore->away_score) {
$away_team_log->drawn += 1;
$away_team_log->points += 1;
} else {
$away_team_log->lost += 1;
$away_team_log->goals_for += $gameScore->away_score;
$away_team_log->goals_against += $gameScore->home_score;
$away_team_log->goal_difference = $away_team_log->goals_for - $away_team_log->goals_against;
thats my model where am passing the method to genererate the results
public function fixtureToView($league)
// Fetch all rows from the games table, including the related official model
$games = Games::where('league_id', $league)->get();
// Extract the values for the role column as an array
$pluckedFixtures = $games->pluck('Fixture')->toArray();
// Count the number of occurrences of each value in the array
$counts = array_count_values($pluckedFixtures);
// Initialize an empty array to store the duplicate keys and values
$fixtures = collect([]);
// Iterate over the counts array
foreach ($counts as $key => $count) {
// If the count is greater than 1, add the key and value to the duplicates array
$fixtures->push($games->where('Fixture', $key));
// In your controller
$gamescores = Gamescores::all();
foreach ($gamescores as $gamescore) {
$game = Games::find($gamescore->games_id);
$league_id = $game->league_id;
$game = Games::find($gamescore->games_id);
$league_id = $game->league_id;
$standings = Logtable::all();
$standings = $standings->sortByDesc('points');
// return view('standings', compact('standings'));
return view(
compact('fixtures', 'standings')
thats my controller where am passing the method to retrieve it in the view, what i want is the log table to get the Id of the league where the games/matches belong to
the error am getting this error

error in controller.php laravel (array_key_exists())

when I want to save changes in laravel, see this error :
* Store a newly created resource in storage.
* #param \Illuminate\Http\Request $request
* #return array|\Illuminate\Http\Response
public function arrangeRoleItem($content, $module_name)
if (array_key_exists(1, $content )) { //Module Show
$module_show = 1;
} else {
$module_show = 0;
if (array_key_exists(2, $content)) { // Show
$show = 1;
} else {
$show = 0;
if (array_key_exists(3, $content)) { // Create
$create = 1;
} else {
$create = 0;
if (array_key_exists(4, $content)) { // Edit
$edit = 1;
} else {
$edit = 0;
"array_key_exists() expects parameter 2 to be array, null given"
thanks for responses.
Your $content variable is null value but array_key_exists function expects second parameter is array
You need to set default value like this:
* Arrange role item
* #param array $content
* #param string $module_name
* #return boolean $bool
public function arrangeRoleItem($content = [], $module_name)

Migrate session from memcached to redis without logging users out in laravel

We're using Memcached to store Laravel's cookie-based session at the moment but want to use Redis throughout for session and cache for consistency.
Is there a way to migrate all user sessions from Memcached to Redis without logging out the users?
I was able to migrate the sessions without logging out the users. I created an artisan command for the purpose:
namespace App\Console\Commands;
use \Memcached;
use \Redis;
use Illuminate\Console\Command;
class MigrateSessionToRedis extends Command
* The name and signature of the console command.
* #var string
protected $signature = 'migrate:session';
* The console command description.
* #var string
protected $description = 'Migrate sessions from Memcached to Redis';
* Create a new command instance.
* #return void
public function __construct() #NOSONAR
* Execute the console command.
* #return mixed
public function handle()
$this->info('Starting session migration..');
$memcached = new Memcached();
$memcached->addServer(env('MEMCACHED_HOST'), 11211);
$sessions = $this->getMemcachedKeys(env('MEMCACHED_HOST'));
if (! is_array($sessions)) {
$this->error('Could not retrieve sessions from Memcached');
foreach ($sessions as $session) {
$value = $memcached->get($session);
if ($value) {
$object = unserialize($value);
$valueForRedis = serialize(serialize($object));
// Set session in Redis with session expiry lifetime
Redis::set("{$session}", $valueForRedis, 'EX', config('session.lifetime'));
$this->info('Finished session migration.');
* Get all memcached keys. Special function because getAllKeys() is broken since memcached 1.4.23.
* Should only be needed on php 5.6
* cleaned up version of code found on by Maduka Jayalath
* #return array|int - all retrieved keys (or negative number on error)
private function getMemcachedKeys($host = '', $port = 11211) #NOSONAR
$mem = #fsockopen($host, $port);
if ($mem === false) {
return -1;
// retrieve distinct slab
$r = #fwrite($mem, 'stats items' . chr(10));
if ($r === false) {
return -2;
$slab = [];
while (($l = #fgets($mem, 1024)) !== false) {
// finished?
$l = trim($l);
if ($l == 'END') {
$m = [];
// <STAT items:22:evicted_nonzero 0>
$r = preg_match('/^STAT\sitems\:(\d+)\:/', $l, $m);
if ($r != 1) {
return -3;
$a_slab = $m[1];
if (!array_key_exists($a_slab, $slab)) {
$slab[$a_slab] = [];
foreach ($slab as $a_slab_key => &$a_slab) {
$r = #fwrite($mem, 'stats cachedump ' . $a_slab_key . ' 100' . chr(10));
if ($r === false) {
return -4;
while (($l = #fgets($mem, 1024)) !== false) {
// finished?
$l = trim($l);
if ($l == 'END') {
$m = [];
// ITEM 42 [118 b; 1354717302 s]
$r = preg_match('/^ITEM\s([^\s]+)\s/', $l, $m);
if ($r != 1) {
return -5;
$a_key = $m[1];
$a_slab[] = $a_key;
// close the connection
$keys = [];
foreach ($slab as &$a_slab) {
foreach ($a_slab as &$a_key) {
$keys[] = $a_key;
return $keys;
Hope it can help others.
Below just example how to make this kind of migration. Try it that way:
$host = '';
$port = null;
$oldPrefix = 'sess_';
$newPrefix = 'sess_';
$sessionDir = '/var/lib/php/session/';
$m = new \Redis();
$m->connect($host, $port);
// $m = new \Memcached();
// $m->addServer($host, $port);
$sessions = scandir($sessionDir);
if (!$sessions) {
die('nothing to migrate');
foreach ($sessions as $s) {
if (in_array($s, ['.', '..'])) {
$sessionName = str_replace($oldPrefix, '', $s);
$sessionContents = file_get_contents($sessionDir.$s);
if (!$m->set($newPrefix.$sessionName, $sessionContents)) {
die(sprintf('Could not migrate session %s'.PHP_EOL, $newPrefix.$sessionName));
echo '.';
But I guess hat users will be logged out.

Logical algorithm to generate paths

I'm trying to develop an algorithm to create a symfony template service.
I want to check if a template exists in a subset of paths, ordered.
Given an array of parameter like this (already ordered like I want):
$params = ['O', 'U', 'W', 'P']
How can I output this array?
$urls = [
I can perform for a little list of parameters (like everyone can do it I suppose) with a code like this :
private function getPaths($template, $params)
$urls = [];
$alreadyPerform = [];
$paramsCounter = count($params);
for ($i = 0; $i < $paramsCounter; $i++) {
for ($j = 0; $j < $paramsCounter; $j++) {
if ($i !== $j && !in_array($params[$j], $alreadyPerform, true)) {
$urls[] = sprintf(
'/%s/%s/%s.html.twig', $params[$i], $params[$j], $template
$alreadyPerform[] = $params[$i];
$urls[] = sprintf('/%s/%s.html.twig', $params[$i], $template);
$urls[] = sprintf('%s.html.twig', $template);
return $urls;
This function work like I wanted until today (max 3 parameters), but I want to add one parameters today, maybe more after.
Thank you very much for your help !
Using recursion, you can do the following:
* #param array $elements
* #param array $extra
* #return Generator
function gen(array $elements, array $extra = []): \Generator {
foreach ($elements as $i => $head) {
foreach (gen(array_slice($elements, $i + 1), $extra) as $tail) {
yield array_merge([$head], $tail);
yield $extra;
Or without recursion:
* #param array $elements
* #return Generator
function gen2(array $elements): \Generator {
for ($num = count($elements), $i = pow(2, $num) - 1; $i >= 1; $i -= 2) {
$r = [];
for ($j = 0; $j < $num; $j += 1) {
if ($i & (1 << ($num - $j - 1))) {
$r[] = $elements[$j];
yield $r;
Consider using the following package:
Just a very basic example of what it can do:
$permutations = new \drupol\phpermutations\Generators\Permutations(['A', 'B', 'C'], 2);
foreach ($permutations->generator() as $permutation) {
echo implode('/', $permutation);
echo "\n";

How to set minimum upload size in codeigniter

I want to set minimum width and height for uploading images in codeigniter.
The code is shown below.
$config['max_width'] = '480';
$config['max_height'] = '270';
I have set maximum cut off for this but how to set minimum ??
Copy your Upload.php from system/libraries and paste on application/libraries. Then,
introduce 2 new variables.
public $max_width = 0;
public $max_height = 0;
public $min_width = 0; // new
public $min_height = 0; // new
Add these to the initialize function so that you can pass values through a $config variable.
Locate is_allowed_dimensions function and modify it.
if ($this->min_width > 0 AND $D['0'] < $this->min_width)
return FALSE;
if ($this->min_height > 0 AND $D['1'] < $this->min_height)
return FALSE;
Check the upload language file and alter the upload_invalid_dimensions key accordingly to fit your case.
Have not tested this, but should work :)
Go to system/validation. And then open file FileRules.php
Paste this code :
public function min_dims(?string $blank, string $params): bool
// Grab the file name off the top of the $params
// after we split it.
$params = explode(',', $params);
$name = array_shift($params);
if (! ($files = $this->request->getFileMultiple($name))) {
$files = [$this->request->getFile($name)];
foreach ($files as $file) {
if ($file === null) {
return false;
if ($file->getError() === UPLOAD_ERR_NO_FILE) {
return true;
// Get Parameter sizes
$allowedWidth = $params[0] ?? 0;
$allowedHeight = $params[1] ?? 0;
// Get uploaded image size
$info = getimagesize($file->getTempName());
$fileWidth = $info[0];
$fileHeight = $info[1];
if ($fileWidth < $allowedWidth || $fileHeight < $allowedHeight) {
return false;
return true;
And, in your controller use min_dims[field_name,1100,1100]. The first
parameter is the field name. The second is
the width, and the third is the height
Good Luck!
Here is the working fix, additionally you need to specify min_height and min_width while you init
<?php if ( ! defined('BASEPATH')) exit('No direct script access allowed');
class CI_Upload {
public $max_size = 0;
public $max_width = 0;
public $max_height = 0;
public $min_width = 0;
public $min_height = 0;
public $max_filename = 0;
public $allowed_types = "";
public $file_temp = "";
public $file_name = "";
public $orig_name = "";
public $file_type = "";
public $file_size = "";
public $file_ext = "";
public $upload_path = "";
public $overwrite = FALSE;
public $encrypt_name = FALSE;
public $is_image = FALSE;
public $image_width = '';
public $image_height = '';
public $image_type = '';
public $image_size_str = '';
public $error_msg = array();
public $mimes = array();
public $remove_spaces = TRUE;
public $xss_clean = FALSE;
public $temp_prefix = "temp_file_";
public $client_name = '';
protected $_file_name_override = '';
* Constructor
* #access public
public function __construct($props = array())
if (count($props) > 0)
log_message('debug', "Upload Class Initialized");
// --------------------------------------------------------------------
* Initialize preferences
* #param array
* #return void
public function initialize($config = array())
$defaults = array(
'max_size' => 0,
'max_width' => 0,
'max_height' => 0,
'min_width' => 0,
'min_height' => 0,
'max_filename' => 0,
'allowed_types' => "",
'file_temp' => "",
'file_name' => "",
'orig_name' => "",
'file_type' => "",
'file_size' => "",
'file_ext' => "",
'upload_path' => "",
'overwrite' => FALSE,
'encrypt_name' => FALSE,
'is_image' => FALSE,
'image_width' => '',
'image_height' => '',
'image_type' => '',
'image_size_str' => '',
'error_msg' => array(),
'mimes' => array(),
'remove_spaces' => TRUE,
'xss_clean' => FALSE,
'temp_prefix' => "temp_file_",
'client_name' => ''
foreach ($defaults as $key => $val)
if (isset($config[$key]))
$method = 'set_'.$key;
if (method_exists($this, $method))
$this->$key = $config[$key];
$this->$key = $val;
// if a file_name was provided in the config, use it instead of the user input
// supplied file name for all uploads until initialized again
$this->_file_name_override = $this->file_name;
// --------------------------------------------------------------------
* Perform the file upload
* #return bool
public function do_upload($field = 'userfile')
// Is $_FILES[$field] set? If not, no reason to continue.
if ( ! isset($_FILES[$field]))
return FALSE;
// Is the upload path valid?
if ( ! $this->validate_upload_path())
// errors will already be set by validate_upload_path() so just return FALSE
return FALSE;
// Was the file able to be uploaded? If not, determine the reason why.
if ( ! is_uploaded_file($_FILES[$field]['tmp_name']))
$error = ( ! isset($_FILES[$field]['error'])) ? 4 : $_FILES[$field]['error'];
default : $this->set_error('upload_no_file_selected');
return FALSE;
// Set the uploaded data as class variables
$this->file_temp = $_FILES[$field]['tmp_name'];
$this->file_size = $_FILES[$field]['size'];
$this->file_type = preg_replace("/^(.+?);.*$/", "\\1", $this->file_type);
$this->file_type = strtolower(trim(stripslashes($this->file_type), '"'));
$this->file_name = $this->_prep_filename($_FILES[$field]['name']);
$this->file_ext = $this->get_extension($this->file_name);
$this->client_name = $this->file_name;
// Is the file type allowed to be uploaded?
if ( ! $this->is_allowed_filetype())
return FALSE;
// if we're overriding, let's now make sure the new name and type is allowed
if ($this->_file_name_override != '')
$this->file_name = $this->_prep_filename($this->_file_name_override);
// If no extension was provided in the file_name config item, use the uploaded one
if (strpos($this->_file_name_override, '.') === FALSE)
$this->file_name .= $this->file_ext;
// An extension was provided, lets have it!
$this->file_ext = $this->get_extension($this->_file_name_override);
if ( ! $this->is_allowed_filetype(TRUE))
return FALSE;
// Convert the file size to kilobytes
if ($this->file_size > 0)
$this->file_size = round($this->file_size/1024, 2);
// Is the file size within the allowed maximum?
if ( ! $this->is_allowed_filesize())
return FALSE;
// Are the image dimensions within the allowed size?
// Note: This can fail if the server has an open_basdir restriction.
if ( ! $this->is_allowed_dimensions())
return FALSE;
// Sanitize the file name for security
$this->file_name = $this->clean_file_name($this->file_name);
// Truncate the file name if it's too long
if ($this->max_filename > 0)
$this->file_name = $this->limit_filename_length($this->file_name, $this->max_filename);
// Remove white spaces in the name
if ($this->remove_spaces == TRUE)
$this->file_name = preg_replace("/\s+/", "_", $this->file_name);
* Validate the file name
* This function appends an number onto the end of
* the file if one with the same name already exists.
* If it returns false there was a problem.
$this->orig_name = $this->file_name;
if ($this->overwrite == FALSE)
$this->file_name = $this->set_filename($this->upload_path, $this->file_name);
if ($this->file_name === FALSE)
return FALSE;
* Run the file through the XSS hacking filter
* This helps prevent malicious code from being
* embedded within a file. Scripts can easily
* be disguised as images or other file types.
if ($this->xss_clean)
if ($this->do_xss_clean() === FALSE)
return FALSE;
* Move the file to the final destination
* To deal with different server configurations
* we'll attempt to use copy() first. If that fails
* we'll use move_uploaded_file(). One of the two should
* reliably work in most environments
if ( ! #copy($this->file_temp, $this->upload_path.$this->file_name))
if ( ! #move_uploaded_file($this->file_temp, $this->upload_path.$this->file_name))
return FALSE;
* Set the finalized image dimensions
* This sets the image width/height (assuming the
* file was an image). We use this information
* in the "data" function.
return TRUE;
// --------------------------------------------------------------------
* Finalized Data Array
* Returns an associative array containing all of the information
* related to the upload, allowing the developer easy access in one array.
* #return array
public function data()
return array (
'file_name' => $this->file_name,
'file_type' => $this->file_type,
'file_path' => $this->upload_path,
'full_path' => $this->upload_path.$this->file_name,
'raw_name' => str_replace($this->file_ext, '', $this->file_name),
'orig_name' => $this->orig_name,
'client_name' => $this->client_name,
'file_ext' => $this->file_ext,
'file_size' => $this->file_size,
'is_image' => $this->is_image(),
'image_width' => $this->image_width,
'image_height' => $this->image_height,
'image_type' => $this->image_type,
'image_size_str' => $this->image_size_str,
// --------------------------------------------------------------------
* Set Upload Path
* #param string
* #return void
public function set_upload_path($path)
// Make sure it has a trailing slash
$this->upload_path = rtrim($path, '/').'/';
// --------------------------------------------------------------------
* Set the file name
* This function takes a filename/path as input and looks for the
* existence of a file with the same name. If found, it will append a
* number to the end of the filename to avoid overwriting a pre-existing file.
* #param string
* #param string
* #return string
public function set_filename($path, $filename)
if ($this->encrypt_name == TRUE)
$filename = md5(uniqid(mt_rand())).$this->file_ext;
if ( ! file_exists($path.$filename))
return $filename;
$filename = str_replace($this->file_ext, '', $filename);
$new_filename = '';
for ($i = 1; $i < 100; $i++)
if ( ! file_exists($path.$filename.$i.$this->file_ext))
$new_filename = $filename.$i.$this->file_ext;
if ($new_filename == '')
return FALSE;
return $new_filename;
// --------------------------------------------------------------------
* Set Maximum File Size
* #param integer
* #return void
public function set_max_filesize($n)
$this->max_size = ((int) $n < 0) ? 0: (int) $n;
// --------------------------------------------------------------------
* Set Maximum File Name Length
* #param integer
* #return void
public function set_max_filename($n)
$this->max_filename = ((int) $n < 0) ? 0: (int) $n;
// --------------------------------------------------------------------
* Set Maximum Image Width
* #param integer
* #return void
public function set_max_width($n)
$this->max_width = ((int) $n < 0) ? 0: (int) $n;
public function set_min_width($n)
$this->min_width = ((int) $n < 0) ? 0: (int) $n;
// --------------------------------------------------------------------
* Set Maximum Image Height
* #param integer
* #return void
public function set_max_height($n)
$this->max_height = ((int) $n < 0) ? 0: (int) $n;
public function set_min_height($n)
$this->min_height = ((int) $n < 0) ? 0: (int) $n;
// --------------------------------------------------------------------
* Set Allowed File Types
* #param string
* #return void
public function set_allowed_types($types)
if ( ! is_array($types) && $types == '*')
$this->allowed_types = '*';
$this->allowed_types = explode('|', $types);
// --------------------------------------------------------------------
* Set Image Properties
* Uses GD to determine the width/height/type of image
* #param string
* #return void
public function set_image_properties($path = '')
if ( ! $this->is_image())
if (function_exists('getimagesize'))
if (FALSE !== ($D = #getimagesize($path)))
$types = array(1 => 'gif', 2 => 'jpeg', 3 => 'png');
$this->image_width = $D['0'];
$this->image_height = $D['1'];
$this->image_type = ( ! isset($types[$D['2']])) ? 'unknown' : $types[$D['2']];
$this->image_size_str = $D['3']; // string containing height and width
// --------------------------------------------------------------------
* Set XSS Clean
* Enables the XSS flag so that the file that was uploaded
* will be run through the XSS filter.
* #param bool
* #return void
public function set_xss_clean($flag = FALSE)
$this->xss_clean = ($flag == TRUE) ? TRUE : FALSE;
// --------------------------------------------------------------------
* Validate the image
* #return bool
public function is_image()
// IE will sometimes return odd mime-types during upload, so here we just standardize all
// jpegs or pngs to the same file type.
$png_mimes = array('image/x-png');
$jpeg_mimes = array('image/jpg', 'image/jpe', 'image/jpeg', 'image/pjpeg');
if (in_array($this->file_type, $png_mimes))
$this->file_type = 'image/png';
if (in_array($this->file_type, $jpeg_mimes))
$this->file_type = 'image/jpeg';
$img_mimes = array(
return (in_array($this->file_type, $img_mimes, TRUE)) ? TRUE : FALSE;
// --------------------------------------------------------------------
* Verify that the filetype is allowed
* #return bool
public function is_allowed_filetype($ignore_mime = FALSE)
if ($this->allowed_types == '*')
return TRUE;
if (count($this->allowed_types) == 0 OR ! is_array($this->allowed_types))
return FALSE;
$ext = strtolower(ltrim($this->file_ext, '.'));
if ( ! in_array($ext, $this->allowed_types))
return FALSE;
// Images get some additional checks
$image_types = array('gif', 'jpg', 'jpeg', 'png', 'jpe');
if (in_array($ext, $image_types))
if (getimagesize($this->file_temp) === FALSE)
return FALSE;
if ($ignore_mime === TRUE)
return TRUE;
$mime = $this->mimes_types($ext);
if (is_array($mime))
if (in_array($this->file_type, $mime, TRUE))
return TRUE;
elseif ($mime == $this->file_type)
return TRUE;
return FALSE;
// --------------------------------------------------------------------
* Verify that the file is within the allowed size
* #return bool
public function is_allowed_filesize()
if ($this->max_size != 0 AND $this->file_size > $this->max_size)
return FALSE;
return TRUE;
// --------------------------------------------------------------------
* Verify that the image is within the allowed width/height
* #return bool
public function is_allowed_dimensions()
if ( ! $this->is_image())
return TRUE;
if (function_exists('getimagesize'))
$D = #getimagesize($this->file_temp);
if ($this->max_width > 0 AND $D['0'] > $this->max_width)
return FALSE;
if ($this->max_height > 0 AND $D['1'] > $this->max_height)
return FALSE;
if ($D['0'] < $this->min_width)
return FALSE;
if ($D['1'] < $this->min_height)
return FALSE;
return TRUE;
return TRUE;
// --------------------------------------------------------------------
* Validate Upload Path
* Verifies that it is a valid upload path with proper permissions.
* #return bool
public function validate_upload_path()
if ($this->upload_path == '')
return FALSE;
if (function_exists('realpath') AND #realpath($this->upload_path) !== FALSE)
$this->upload_path = str_replace("\\", "/", realpath($this->upload_path));
if ( ! #is_dir($this->upload_path))
return FALSE;
if ( ! is_really_writable($this->upload_path))
return FALSE;
$this->upload_path = preg_replace("/(.+?)\/*$/", "\\1/", $this->upload_path);
return TRUE;
// --------------------------------------------------------------------
* Extract the file extension
* #param string
* #return string
public function get_extension($filename)
$x = explode('.', $filename);
return '.'.end($x);
// --------------------------------------------------------------------
* Clean the file name for security
* #param string
* #return string
public function clean_file_name($filename)
$bad = array(
"%3c", // <
"%253c", // <
"%3e", // >
"%0e", // >
"%28", // (
"%29", // )
"%2528", // (
"%26", // &
"%24", // $
"%3f", // ?
"%3b", // ;
"%3d" // =
$filename = str_replace($bad, '', $filename);
return stripslashes($filename);
// --------------------------------------------------------------------
* Limit the File Name Length
* #param string
* #return string
public function limit_filename_length($filename, $length)
if (strlen($filename) < $length)
return $filename;
$ext = '';
if (strpos($filename, '.') !== FALSE)
$parts = explode('.', $filename);
$ext = '.'.array_pop($parts);
$filename = implode('.', $parts);
return substr($filename, 0, ($length - strlen($ext))).$ext;
// --------------------------------------------------------------------
* Runs the file through the XSS clean function
* This prevents people from embedding malicious code in their files.
* I'm not sure that it won't negatively affect certain files in unexpected ways,
* but so far I haven't found that it causes trouble.
* #return void
public function do_xss_clean()
$file = $this->file_temp;
if (filesize($file) == 0)
return FALSE;
if (function_exists('memory_get_usage') && memory_get_usage() && ini_get('memory_limit') != '')
$current = ini_get('memory_limit') * 1024 * 1024;
// There was a bug/behavioural change in PHP 5.2, where numbers over one million get output
// into scientific notation. number_format() ensures this number is an integer
$new_memory = number_format(ceil(filesize($file) + $current), 0, '.', '');
ini_set('memory_limit', $new_memory); // When an integer is used, the value is measured in bytes. -
// If the file being uploaded is an image, then we should have no problem with XSS attacks (in theory), but
// IE can be fooled into mime-type detecting a malformed image as an html file, thus executing an XSS attack on anyone
// using IE who looks at the image. It does this by inspecting the first 255 bytes of an image. To get around this
// CI will itself look at the first 255 bytes of an image to determine its relative safety. This can save a lot of
// processor power and time if it is actually a clean image, as it will be in nearly all instances _except_ an
// attempted XSS attack.
if (function_exists('getimagesize') && #getimagesize($file) !== FALSE)
if (($file = #fopen($file, 'rb')) === FALSE) // "b" to force binary
return FALSE; // Couldn't open the file, return FALSE
$opening_bytes = fread($file, 256);
// These are known to throw IE into mime-type detection chaos
// <a, <body, <head, <html, <img, <plaintext, <pre, <script, <table, <title
// title is basically just in SVG, but we filter it anyhow
if ( ! preg_match('/<(a|body|head|html|img|plaintext|pre|script|table|title)[\s>]/i', $opening_bytes))
return TRUE; // its an image, no "triggers" detected in the first 256 bytes, we're good
return FALSE;
if (($data = #file_get_contents($file)) === FALSE)
return FALSE;
$CI =& get_instance();
return $CI->security->xss_clean($data, TRUE);
// --------------------------------------------------------------------
* Set an error message
* #param string
* #return void
public function set_error($msg)
$CI =& get_instance();
if (is_array($msg))
foreach ($msg as $val)
$msg = ($CI->lang->line($val) == FALSE) ? $val : $CI->lang->line($val);
$this->error_msg[] = $msg;
log_message('error', $msg);
$msg = ($CI->lang->line($msg) == FALSE) ? $msg : $CI->lang->line($msg);
$this->error_msg[] = $msg;
log_message('error', $msg);
// --------------------------------------------------------------------
* Display the error message
* #param string
* #param string
* #return string
public function display_errors($open = '<p>', $close = '</p>')
$str = '';
foreach ($this->error_msg as $val)
$str .= $open.$val.$close;
return $str;
// --------------------------------------------------------------------
* List of Mime Types
* This is a list of mime types. We use it to validate
* the "allowed types" set by the developer
* #param string
* #return string
public function mimes_types($mime)
global $mimes;
if (count($this->mimes) == 0)
if (defined('ENVIRONMENT') AND is_file(APPPATH.'config/'.ENVIRONMENT.'/mimes.php'))
elseif (is_file(APPPATH.'config/mimes.php'))
return FALSE;
$this->mimes = $mimes;
return ( ! isset($this->mimes[$mime])) ? FALSE : $this->mimes[$mime];
// --------------------------------------------------------------------
* Prep Filename
* Prevents possible script execution from Apache's handling of files multiple extensions
* #param string
* #return string
protected function _prep_filename($filename)
if (strpos($filename, '.') === FALSE OR $this->allowed_types == '*')
return $filename;
$parts = explode('.', $filename);
$ext = array_pop($parts);
$filename = array_shift($parts);
foreach ($parts as $part)
if ( ! in_array(strtolower($part), $this->allowed_types) OR $this->mimes_types(strtolower($part)) === FALSE)
$filename .= '.'.$part.'_';
$filename .= '.'.$part;
$filename .= '.'.$ext;
return $filename;
// --------------------------------------------------------------------
* File MIME type
* Detects the (actual) MIME type of the uploaded file, if possible.
* The input array is expected to be $_FILES[$field]
* #param array
* #return void
protected function _file_mime_type($file)
// We'll need this to validate the MIME info string (e.g. text/plain; charset=us-ascii)
$regexp = '/^([a-z\-]+\/[a-z0-9\-\.\+]+)(;\s.+)?$/';
/* Fileinfo extension - most reliable method
* Unfortunately, prior to PHP 5.3 - it's only available as a PECL extension and the
* more convenient FILEINFO_MIME_TYPE flag doesn't exist.
if (function_exists('finfo_file'))
$finfo = finfo_open(FILEINFO_MIME);
if (is_resource($finfo)) // It is possible that a FALSE value is returned, if there is no magic MIME database file found on the system
$mime = #finfo_file($finfo, $file['tmp_name']);
/* According to the comments section of the PHP manual page,
* it is possible that this function returns an empty string
* for some files (e.g. if they don't exist in the magic MIME database)
if (is_string($mime) && preg_match($regexp, $mime, $matches))
$this->file_type = $matches[1];
/* This is an ugly hack, but UNIX-type systems provide a "native" way to detect the file type,
* which is still more secure than depending on the value of $_FILES[$field]['type'], and as it
* was reported in issue #750 ( - it's better
* than mime_content_type() as well, hence the attempts to try calling the command line with
* three different functions.
* Notes:
* - the DIRECTORY_SEPARATOR comparison ensures that we're not on a Windows system
* - many system admins would disable the exec(), shell_exec(), popen() and similar functions
* due to security concerns, hence the function_exists() checks
$cmd = 'file --brief --mime ' . escapeshellarg($file['tmp_name']) . ' 2>&1';
if (function_exists('exec'))
/* This might look confusing, as $mime is being populated with all of the output when set in the second parameter.
* However, we only neeed the last line, which is the actual return value of exec(), and as such - it overwrites
* anything that could already be set for $mime previously. This effectively makes the second parameter a dummy
* value, which is only put to allow us to get the return status code.
$mime = #exec($cmd, $mime, $return_status);
if ($return_status === 0 && is_string($mime) && preg_match($regexp, $mime, $matches))
$this->file_type = $matches[1];
if ( (bool) #ini_get('safe_mode') === FALSE && function_exists('shell_exec'))
$mime = #shell_exec($cmd);
if (strlen($mime) > 0)
$mime = explode("\n", trim($mime));
if (preg_match($regexp, $mime[(count($mime) - 1)], $matches))
$this->file_type = $matches[1];
if (function_exists('popen'))
$proc = #popen($cmd, 'r');
if (is_resource($proc))
$mime = #fread($proc, 512);
if ($mime !== FALSE)
$mime = explode("\n", trim($mime));
if (preg_match($regexp, $mime[(count($mime) - 1)], $matches))
$this->file_type = $matches[1];
// Fall back to the deprecated mime_content_type(), if available (still better than $_FILES[$field]['type'])
if (function_exists('mime_content_type'))
$this->file_type = #mime_content_type($file['tmp_name']);
if (strlen($this->file_type) > 0) // It's possible that mime_content_type() returns FALSE or an empty string
$this->file_type = $file['type'];
// --------------------------------------------------------------------
