@lyse@lyse.isobeef.org So to sanitize the files going thought upload.php is something like preg_replace(“/[^a-z0-9\.]/”, “”, strtolower($str)); // from:http://www.touchoftechnology.com/simple-way-to-clean-up-filenames-in-php/ enough or should I use this https://gist.github.com/sumanthkumarc/2de2e2cc06c648a9f52c121501a181df or something completely different?

I relation to checking if the uploaded files is in fact images it is this code from https://www.w3schools.com/php/php_file_upload.asp good?

@adi@twtxt.net and @prologic@twtxt.net to the question about PHP. My goal is to make something anyone with ftp access can deploy in a hour without having to use a command prompt. SSH access also often comes at a extra fee if available at all. I know PHP is not the most efficient out there compared to go and static site generators like pp, but my target users are not professional programmers like you guys - pixelblog - a twtxt frontend not just for hackers™

@lyse@lyse.isobeef.org in an easy to read twt you not only managed to explain to @darch@twtxt.net the issues his code has, and potential solutions, but by now he fully understands he shouldn’t be meddling with PHP programming, and instead use a solution provided by people who do that for a living. 🤣 It will not be fully fool proof, but certainly better than what he has right now.

