note 69735 deleted from function.getimagesize by colder

From: Date: Tue, 19 Sep 2006 01:59:08 +0000
Subject: note 69735 deleted from function.getimagesize by colder
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-117299@lists.php.net to get a copy of this message
Note Submitter: scottayy at gmail dot com Reason: bad code ---- If you're not doing any error checking and are expecting a user to upload an image.. it can pass! Even if it's not an image. Basic error checking would look like this <?php if(!$img_info = getimagesize($some_image)) { die('You did not upload an image!'); } ?> However, this will generate a warning, so use of the error supressing operator is advised. <?php if(!$img_info = @getimagesize($some_image)) { die('You did not upload an image!'); } ?> Seems elementary to some, but I remember this getting me back in the day, when users could upload straight text files to my database. (i've since learned better security.. heh ;)) Hope that helps a few of the newbies out there. Good luck!

« previous php.notes (#117299) next »