A couple of days ago I asked how I might be able to password protect files that people download. The best solution seemed to be to get a script to fetch the file, hence hinding its location from users. This is a good thing. We can do it in perl ok, but the one problem is that when you open a file, and then print it back to the client, the file you send ends up having the same name as the script. So, someone (Jurian) suggested something like this:
<?
$filename = "c:\\downloads\\file.exe";
header("Content-Type: application/octet-stream");
header("Content-Disposition: attachment; filename=$filename");
?>
Unfortunately, this just generates a blank screen. I've had a look at the RFC for http 1.1, but its a bit over my head. As far as I can tell Content-Disposition: is experimental, or at least it was.
So, any ideas people? I'd like to be able to send a file back to the client, preserving the original filename.
You will notice that I posted a reply that tells you how to do this without adjusting any http headers.
Instead of passing the filename as a script parameter, like this...
/blah/myscript.php?file=name
...do it like this...
/blah/mydownloadscript.php/relativefilepath
...and get the relative file path out of the $PATH_INFO variable. Search the discussion for my name and you'll see many more details on the matter.
Chris