Re: Re: file downloads (again)
| From: | Justin French | Date: | Tue, 18 Jun 2002 02:28:12 +0000 |
| Subject: | Re: Re: file downloads (again) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-102634@lists.php.net to get a copy of this message | ||
Okay, I'm getting pretty close now.
Taking little snippets of everyone's advice, I've got this far:
1. start session, validate user
2. make sure the file exists
3a. if yes to both, header(Location something.mp3)
3b. if no to either, show a HTML page with errors
Now the next step is to change 3a to passthru() the file instead, so that
people don't know where the file actually is in the heirachy. In theory it
sounds pretty easy, but I'm concerned about one bit:
If the user saves the file (a likely occurrence), the file will be named
download.php, not something.mp3. My worry is that this may play havoc on
systems which rely on the extension to determine file type (Win 9x for
starters!).
Any ideas on how to get around this?
My only thought was to use a .htaccess file to ensure that "download.mp3
should be parsed through PHP... so at least the saved file has the right
extension.
From there, maybe have a directory of PHP files called song1.mp3, song2.mp3,
etc etc, but instead of them being MP3's, they're a PHP file that determines
if the user is valid, THEN pumps out the MP3 data. So when they save the
file, it has the correct file name and extension.
Justin French