RE: [PHP] choosing the name to save a file as in a script

From: Date: Wed, 27 Dec 2000 02:31:11 +0000
Subject: RE: [PHP] choosing the name to save a file as in a script
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-31901@lists.php.net to get a copy of this message
This is EXACTLY what I need to do :) I will have to give it a try tomorrow, if it doesn't work, it'll have to be because of M$ II$... And then I'll have to switch to Apache... To clarify why I wanted to do that is because I'm building a site where each user will have access to certain files and not to others. All the authentification is done through PHP because users/passwords/groups/etc. are stored in a MySQL database... And to restrict the access to files which are not PHP scripts, I can't give direct access to it, I have to make a PHP script that verifies if the user has the proper rights and if he does, I simply read the file (in binary) and send it to the user... With the "attachment header", I'll be able to send the file to the user with the proper filename, instead of having him download a .php file and then he would have to rename it or something... And we all know that the average user is an idiot and he probably doesn't even know what an extension is because they are hidden in his Windows Explorer window... So, thanks a lot for your help Michael Kimsal, you perfectly understood the problem and gave me the right solution. I can't wait to try it out tomorrow at work, it better work on IIS too ! -----Original Message----- From: Michael Kimsal [mailto:michael@tapinternet.com] Sent: Tuesday, December 26, 2000 19:23 To: Blaster Cc: php-general@lists.php.net Subject: Re: [PHP] choosing the name to save a file as in a script Don't bother with the 'filename.ext' part - just get the ID parameter. Look up the filename in a database of what the filename.ext should be for file ID xxxxxx. Then send header("Content-type: ".$db->Record["filemime"]." ; filename=".$db->Record["filename"]); header("Content-Disposition: attachment; filename=".$db->Record["fullfilename"] ); $f = fopen($db->Record["localfilename"],"r"); $x = fread($f,filesize($db->Record["localfilename"])); fclose($f); echo $x; exit(); well - don't use $db->Record, etc. This is code we use to send a file down to someone who sends in a particular string ID. We control the filename, the MIME type, and who gets access to what file. Haven't tried it under IIS using PHP, but I'd think the underpinnings are pretty much the same across the board. Blaster wrote: > Hi everyone, > > I've seen something very interesting on some site that would allow me to use > PHP-authentification to allow download of certain files.... Here's what the > link on the site looks like: > > http://www.whatever.com/view.php3/filename.ext?id=17982 > > Now, the script that sends the file is view.php3. What this does is get a > file with id 17982, either by reading it from a database or something (not > important) and sends it back to the browser and the browser thinks it is > actually file "filename.ext"... > > What I don't get is how can you pass "/filename.ext?id=17982" as an > argument? I tried it and the web server will of course look for file > "filename.ext", but it doesn't exist since view.php3 is obviously not a > directory... > > Any ideas how this can be achieved? I thought it could be some kind of 404 > error redirection to a php script, but then all bad links on the whole site > would be sent to that script and they don't appear to be (at least I get a > normal 404 error everywhere else) > > Thanks for your time

« previous php.general (#31901) next »