Re: protecting downloadable files
| From: | Thomas Deliduka | Date: | Thu, 27 Jul 2000 13:58:52 +0000 |
| Subject: | Re: protecting downloadable files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-8552@lists.php.net to get a copy of this message | ||
I found it interesting that on 7/27/00 9:54 AM Paul Dalton said:
> I would like to be able to protect files that are downloaded by
> users. A colleague of mine sort of got this to work with perl. The
> script is handed the filename as an arg and the script then opens the
> file and sends it to stdout (i.e. the user) after setting the content
> type to binary. This works, however the file that the user ends up with
> always has the name of the script that was used to give them the file.
> This makes sense I suppose. So, the question is, is there a way of
> specifying the filename, or some other way of doing this (I'm hoping to
> use PHP btw)?
>
> Hope I'm making myself clear here.
I don't know if this was fixed in IE 5 or not but in IE 4 the
content-disposition header wouldn't be recognized so you couldn't specify
the filename correctly. Here is what I use in a perl script for sending a
PDF document:
print "Content-type: application/octet-stream; name=$filename\n";
print "Content-Disposition: attachment; filename=$filename\n";
print "Content-Length: $size\n\n";
It's debated on the newsgroups whether you use:
Content-Disposition: inline; ....
Content-Disposition: attachment; ....
or I've seen people use:
Content-disposition: download; .... and they say it works.
I use application/octet-stream rather than application/pdf because some
people had trouble downloading the file if they didn't already have Acrobat
installed (yes, some people don't) so octet-stream worked for both of those
who have it installed and those who don't.
--
Thomas Deliduka
IT Manager
-------------------------
New Eve Media
The Solution To Your Internet Angst
http://www.neweve.com/