According to php.net, it has this to say about the contents of the $_FILES array:
$_FILES[’userfile’][’type’]
The mime type of the file, if the browser provided this information. An example would be "image/gif". This mime type is however not checked on the PHP side and therefore don’t take its value for granted.
As such, I think a possible solution would be to change the code to this in the MODx Reseource Wizard, of course this would also apply to SkinGraft:
// <-- Error if the package is not uploaded as 'application/zip'. -->
$this->resource_pkgfile = $_FILES['userfile']['name'];
if (!(strpos($this->resource_pkgfile,'zip',strlen($this->resource_pkgfile)-3))) {
$this->evalErrArray = array(''=>$main_button);
$this->evalErr = "<h2>$not_valid</h2>\n";
echo $this->resource_pkgfile.'<BR>';
echo strpos($this->resource_pkgfile, '.zip');
$this->evalErr .= $this->wizard_buildForm();
$this->evalErr .= $this->wizard_getFoot($this->evalErrArray);
unlink($this->eval_path.$this->resource_pkgfile) or die('Could not remove upload from '.$this->eval_path.$this->resource_pkgfile);
return $this->evalErr;
}
Now as long as the file ends in .zip, it will allow the file to go through to the other checks. The strange thing is that I was having the error with the MRW, until I commented it out, but I didn’t have the problems with SkinGraft. And even more weird is that the problem went away when I uncommented his code after I was able to install my first resource package. All throughout I was using the same browser, so I thought this was interesting.