Re: choosing the name to save a file as in a script
| From: | Michael Kimsal | Date: | Wed, 27 Dec 2000 00:22:35 +0000 |
| Subject: | Re: choosing the name to save a file as in a script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-31893@lists.php.net to get a copy of this message | ||
Don't bother with the 'filename.ext' part - just get the ID parameter.
Look up the filename in a database of what the filename.ext should
be for file ID xxxxxx.
Then send
header("Content-type: ".$db->Record["filemime"]." ;
filename=".$db->Record["filename"]);
header("Content-Disposition: attachment;
filename=".$db->Record["fullfilename"] );
$f = fopen($db->Record["localfilename"],"r");
$x = fread($f,filesize($db->Record["localfilename"]));
fclose($f);
echo $x;
exit();
well - don't use $db->Record, etc. This is code we use to send
a file down to someone who sends in a particular string ID. We control
the filename, the MIME type, and who gets access to what file. Haven't
tried it under IIS using PHP, but I'd think the underpinnings are
pretty much the same across the board.
Blaster wrote:
> Hi everyone,
>
> I've seen something very interesting on some site that would allow me to use
> PHP-authentification to allow download of certain files.... Here's what the
> link on the site looks like:
>
> http://www.whatever.com/view.php3/filename.ext?id=17982
>
> Now, the script that sends the file is view.php3. What this does is get a
> file with id 17982, either by reading it from a database or something (not
> important) and sends it back to the browser and the browser thinks it is
> actually file "filename.ext"...
>
> What I don't get is how can you pass "/filename.ext?id=17982" as an
> argument? I tried it and the web server will of course look for file
> "filename.ext", but it doesn't exist since view.php3 is obviously not a
> directory...
>
> Any ideas how this can be achieved? I thought it could be some kind of 404
> error redirection to a php script, but then all bad links on the whole site
> would be sent to that script and they don't appear to be (at least I get a
> normal 404 error everywhere else)
>
> Thanks for your time