X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;f=admin%2Fattachments.php;h=7e6ba95545251f3ddb379ce47e46652369ab6897;hb=231a58e6564fc927a2f38c9a45871df43da14420;hp=d3f491ace3a08898d022d6509f03ee07749e068c;hpb=0057896b8b8abb1e74091f56a2946b6d3b557e82;p=fa-stable.git diff --git a/admin/attachments.php b/admin/attachments.php index d3f491ac..7e6ba955 100644 --- a/admin/attachments.php +++ b/admin/attachments.php @@ -83,7 +83,10 @@ if ($Mode == 'ADD_ITEM' || $Mode == 'UPDATE_ITEM') $filename = basename($_FILES['filename']['name']); if (!transaction_exists($_POST['filterType'], $_POST['trans_no'])) display_error(_("Selected transaction does not exists.")); - elseif ($Mode == 'ADD_ITEM' && !isset($_FILES['filename'])) + elseif ($Mode == 'ADD_ITEM' && !in_array(strtoupper(substr($filename, strlen($filename) - 3)), array('JPG','PNG','GIF', 'PDF', 'DOC', 'ODT'))) + { + display_error(_('Only graphics,pdf,doc and odt files are supported.')); + } elseif ($Mode == 'ADD_ITEM' && !isset($_FILES['filename'])) display_error(_("Select attachment file.")); elseif ($Mode == 'ADD_ITEM' && ($_FILES['filename']['error'] > 0)) { if ($_FILES['filename']['error'] == UPLOAD_ERR_INI_SIZE)