1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92
| def is_pdf(file): try: original_position = file.tell() file_content = BytesIO(file.read()) file.seek(original_position) pdf_reader = PdfReader(file_content) len(pdf_reader.pages) return True except Exception as e: return False
@page_blueprint.route("/upload", methods=['GET', 'POST']) @authed_only def UserUpload(): if request.method == "POST": if ctf_started() is False: if current_user.is_admin() is False: return redirect(url_for("challenges.listing"))
if get_config("writeup:enabled"): filename_for_store = "" user = current_user.get_current_user() try: filename_for_store = get_config("writeup:name").format(user=user) except Exception as e: log_simple("writeup", "[{date}] [Writeup] 用户上传writeup时格式化名称出错,请检查后台文件名配置!:{e}", e=str(e)) return { 'success': False, 'message': '后端处理失败,请联系管理员!' }, 500 upload_folder = os.path.join( os.path.normpath(app.root_path), app.config.get("UPLOAD_FOLDER") ) writeup_folder = os.path.join(upload_folder, "writeups") os.makedirs(writeup_folder, exist_ok=True)
if 'writeup' not in request.files: return { 'success': False, 'message': '题解文件不存在' }, 400 file = request.files['writeup'] if file.filename == '': return { 'success': False, 'message': '题解文件为空' }, 400
if file: try: if not is_pdf(file): log_simple("writeup", "[{date}] [Writeup] pdf校验失败,可能用户{name}上传的是恶意文件!", name=user.name) return {'success': False, 'message': "文件未通过校验!"}, 400 except: log_simple("writeup", "[{date}] [Writeup] pdf校验失败,可能用户{name}上传的是恶意文件!", name=user.name) return {'success': False, 'message': "文件未通过校验!"}, 400 try: filepath = os.path.join(writeup_folder, filename_for_store) file.save(filepath) log_simple("writeup", "[{date}] [Writeup] 用户{name}成功上传了writeup:[{filename}]。", name=user.name, filename=file.filename) except Exception as e: log_simple("writeup", "[{date}] [Writeup] 用户{name}上传writeup:[{filename}]时出错{e}", name=user.name, filename=file.filename, e=str(e)) return {'success': False, 'message': "上传失败"}, 500
return {'success': True, 'message': "上传成功"}, 200 else: return redirect(url_for("challenges.listing")) else: if ctf_started() is False: if current_user.is_admin() is False: return redirect(url_for("challenges.listing"))
if get_config("writeup:enabled"): return render_template("writeup_upload.html") else: return redirect(url_for("challenges.listing"))
app.register_blueprint(page_blueprint)
|