RE: [PHP] choosing the name to save a file as in a script
| From: | Blaster | Date: | Wed, 27 Dec 2000 02:31:11 +0000 |
| Subject: | RE: [PHP] choosing the name to save a file as in a script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-31901@lists.php.net to get a copy of this message | ||
This is EXACTLY what I need to do :) I will have to give it a try tomorrow,
if it doesn't work, it'll have to be because of M$ II$... And then I'll have
to switch to Apache...
To clarify why I wanted to do that is because I'm building a site where each
user will have access to certain files and not to others. All the
authentification is done through PHP because users/passwords/groups/etc. are
stored in a MySQL database... And to restrict the access to files which are
not PHP scripts, I can't give direct access to it, I have to make a PHP
script that verifies if the user has the proper rights and if he does, I
simply read the file (in binary) and send it to the user... With the
"attachment header", I'll be able to send the file to the user with the
proper filename, instead of having him download a .php file and then he
would have to rename it or something... And we all know that the average
user is an idiot and he probably doesn't even know what an extension is
because they are hidden in his Windows Explorer window...
So, thanks a lot for your help Michael Kimsal, you perfectly understood the
problem and gave me the right solution. I can't wait to try it out tomorrow
at work, it better work on IIS too !
-----Original Message-----
From: Michael Kimsal [mailto:michael@tapinternet.com]
Sent: Tuesday, December 26, 2000 19:23
To: Blaster
Cc: php-general@lists.php.net
Subject: Re: [PHP] choosing the name to save a file as in a script
Don't bother with the 'filename.ext' part - just get the ID parameter.
Look up the filename in a database of what the filename.ext should
be for file ID xxxxxx.
Then send
header("Content-type: ".$db->Record["filemime"]." ;
filename=".$db->Record["filename"]);
header("Content-Disposition: attachment;
filename=".$db->Record["fullfilename"] );
$f = fopen($db->Record["localfilename"],"r");
$x = fread($f,filesize($db->Record["localfilename"]));
fclose($f);
echo $x;
exit();
well - don't use $db->Record, etc. This is code we use to send
a file down to someone who sends in a particular string ID. We control
the filename, the MIME type, and who gets access to what file. Haven't
tried it under IIS using PHP, but I'd think the underpinnings are
pretty much the same across the board.
Blaster wrote:
> Hi everyone,
>
> I've seen something very interesting on some site that would allow me to
use
> PHP-authentification to allow download of certain files.... Here's what
the
> link on the site looks like:
>
> http://www.whatever.com/view.php3/filename.ext?id=17982
>
> Now, the script that sends the file is view.php3. What this does is get a
> file with id 17982, either by reading it from a database or something (not
> important) and sends it back to the browser and the browser thinks it is
> actually file "filename.ext"...
>
> What I don't get is how can you pass "/filename.ext?id=17982" as an
> argument? I tried it and the web server will of course look for file
> "filename.ext", but it doesn't exist since view.php3 is obviously not a
> directory...
>
> Any ideas how this can be achieved? I thought it could be some kind of 404
> error redirection to a php script, but then all bad links on the whole
site
> would be sent to that script and they don't appear to be (at least I get a
> normal 404 error everywhere else)
>
> Thanks for your time