Re: File Upload: Temporary File Location
| From: | James Lyon | Date: | Tue, 30 May 2000 07:32:16 +0000 |
| Subject: | Re: File Upload: Temporary File Location | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-588@lists.php.net to get a copy of this message | ||
> > My proposal: create a separate php/webserver tmp dir with with read&write, but
> > without executable privileges.
>
> Yep, good plan.
On second thoughts, if you're on Unix, then you want the directory to have write and
execute, but not read. The FILES in the directory should have read and write but not
execute.
If the directory has permission's "w", "x", then it can have new directory
entries
written to it (creating files etc.) and files that you know the name of can be
accessed ... but you can't read the directory to find what files are there!
Hope this helps,
James.