Re: password protecting files rather than web pages ...

From: Date: Thu, 27 Jul 2000 16:19:01 +0000
Subject: Re: password protecting files rather than web pages ...
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-8581@lists.php.net to get a copy of this message
paul@pinnacle.net.uk ("Paul Dalton") wrote:
Hi,
    I would like to be able to protect files that are downloaded by users. A colleague of mine sort of got this to work with perl. The script is handed the filename as an arg and the script then opens the file and sends it to stdout (i.e. the user) after setting the content type to binary. This works, however the file that the user ends up with always has the name of the script that was used to give them the file. This makes sense I suppose. So, the question is, is there a way of specifying the filename, or some other way of doing this (I'm hoping to use PHP btw)?
I struggled with this one for some time. There is no header that can be sent to provide the browser with the filename for the save dialog (I am assuming this is what you are talking about). It is useful, however, to note just how the browser is getting its filename information for that dialog. Basically (in Netscape, anyway) the last part of the path is used: /blah/script.php?file=filename ...will cause Netscape to name it "script.php" because that is the last part of the path before the query parameters. However, /blah/script.php/filename ...will cause netscape to name it "filename" instead of "script.php" because it thinks that "script.php" is a directory. So, the way to get a file to download and to have the right name is to use the $PATH_INFO global variable. This will pass in everything after the script name when it is treated as just another item in the path, as above. So, in the above example, $PATH_INFO has the string 'filename' in it. In the following example... /blah/script.php/dirname/filename.ext ...$PATH_INFO has this string: 'dirname/filename.ext' However, when you do the download, Netscape will only use the "filename.ext" part of the path to give the file a name, which is usually what you want anyway. So, in your PHP code, you could notice that the $PATH_INFO variable is set, and assume that means you need to download a file. You then do your authentication, or whatever, and send the file as follows: $parentpath = "/home/httpd/docs"; # or whatever $filename = "$parentpath/$PATH_INFO"; header( "Content-type: application/octet-stream" ); header( "Content-length: " . filesize( $filename ) ); # Now just open the file and pump it out to stdout: readfile( $filename ); Note that you must make sure that the $PATH_INFO variable doesn't have any "../" stuff in it, or you will be allowing people to potentially view files that you don't want them to see. Chris

« previous php.general (#8581) next »