function ptg8_docmcu_upload($POST,$FILES) {
global $db,$ar;
$dt=[];
$uploadDir = $ar['core_path'].'dc/'.$POST['tahun']."/mcu/".$POST['petugas'];
// Create the directory if it does not exist
if (!is_dir($uploadDir)) {
mkdir($uploadDir, 0755, true);
}
// Get file information from the $_FILES superglobal
$fileTmpPath = $FILES['uploaded_file']['tmp_name'];
$fileName = $FILES['uploaded_file']['name'];
// Clean up filename to prevent path traversal vulnerabilities
$safeFileName = basename($fileName);
$targetFilePath = $uploadDir.'/'.$safeFileName;
// Check for PHP upload errors
if ($FILES['uploaded_file']['error'] === UPLOAD_ERR_OK) {
// Move the file from temporary system storage to your target folder
if (move_uploaded_file($fileTmpPath, $targetFilePath)) {
$udt=array(
'st_upload'=>1,
'filesize'=>$POST['file_size'],
'update_at'=>time(),
);
Update($db,"ptg8_docmcu",$udt,"`petugas`=".$POST['petugas']." and `jenis_dokumen`=".$POST['jenis_dokumen'],0);
$dt['text']="Success, saved: " . htmlspecialchars($targetFilePath);
} else {
$dt['text']="Error: There was an issue moving the uploaded file.";
}
} else {
$dt['text']="Error code: " . $FILES['uploaded_file']['error'];
}
return json_encode($dt);
}