分类信息 image调用的丢失问题
首先是页面中对于分类信息的调用方式。如此如此这般,网上多如牛毛,本人用得尚浅,不做过多说明,今天的主角是分类信息diy image的调用问题。
如果在最新版(2013-2-28:以当前时间为准),的discuz中
新的image的获取方式里。因为漏洞问题,修改了生成key的方式 function_core.php:getforumimg
生成key的函数由md5 改成dsign
(因为这个是md5这个是漏洞问题导致容易被别人爆菊花,就是改参数,让服务器生成,这样对服务器来说有危险,看哪个站不爽,可以用此招爆他。。)
后来改了。生成的加密串里,用到的key有两个新的,一个是系统的密钥,一个是uid.
问题来了。在我生成时没有问题。
详见:
/source/module/forum/forum_image.php
但是,如是是系统自己生成的,即更新时,使用的是别人的uid,这样,我下次访问时,因为检查用的是我的uid.导致了不通过。造成图片无法读取的小bug了。
转发请注明出处http://blog.martoo.cn
如有漏缺,请联系我 QQ 243008827
It is perfect time to make some plans for the future and it’s time to be happy. I’ve read this post and if I could I want to suggest you few interesting things or advice. Maybe you can write next articles referring to this article. I wish to read even more things about it!
Hello! This post could not be written any better!
Reading this post reminds me of my old room mate!
He always kept chatting about this. I will forward this post to him.
Pretty sure he will have a good read. Many thanks for sharing!
I enjoy what you guys tend to be up too. This type of clever work and exposure!
Keep up the awesome works guys I’ve incorporated you guys to my blogroll.
It’s in point of fact a great and useful piece of information. I am satisfied that you just shared this useful info with us. Please stay us informed like this. Thank you for sharing.