diff --git a/kernel/api/system.go b/kernel/api/system.go index f9a04ffc0..d51f980b9 100644 --- a/kernel/api/system.go +++ b/kernel/api/system.go @@ -346,15 +346,15 @@ func importConf(c *gin.Context) { return } - tmpDir := filepath.Join(util.TempDir, "import") - if err = os.MkdirAll(tmpDir, 0755); err != nil { + importDir := filepath.Join(util.TempDir, "import") + if err = os.MkdirAll(importDir, 0755); err != nil { logging.LogErrorf("import conf failed: %s", err) ret.Code = -1 ret.Msg = err.Error() return } - tmp := filepath.Join(tmpDir, f.Filename) + tmp := filepath.Join(importDir, f.Filename) if err = os.WriteFile(tmp, data, 0644); err != nil { logging.LogErrorf("import conf failed: %s", err) ret.Code = -1 @@ -362,6 +362,7 @@ func importConf(c *gin.Context) { return } + tmpDir := filepath.Join(importDir, "conf") if err = gulu.Zip.Unzip(tmp, tmpDir); err != nil { logging.LogErrorf("import conf failed: %s", err) ret.Code = -1 @@ -369,7 +370,22 @@ func importConf(c *gin.Context) { return } - tmp = filepath.Join(tmpDir, f.Filename[:len(f.Filename)-4]) + entries, err := os.ReadDir(tmpDir) + if err != nil { + logging.LogErrorf("import conf failed: %s", err) + ret.Code = -1 + ret.Msg = err.Error() + return + } + + if 1 != len(entries) { + logging.LogErrorf("invalid conf package") + ret.Code = -1 + ret.Msg = "invalid conf package" + return + } + + tmp = filepath.Join(tmpDir, entries[0].Name()) data, err = os.ReadFile(tmp) if err != nil { logging.LogErrorf("import conf failed: %s", err)