note 69735 deleted from function.getimagesize by colder
| From: | colder@php.net | Date: | Tue, 19 Sep 2006 01:59:08 +0000 |
| Subject: | note 69735 deleted from function.getimagesize by colder | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-117299@lists.php.net to get a copy of this message | ||
Note Submitter: scottayy at gmail dot com
Reason: bad code
----
If you're not doing any error checking and are expecting a user to upload an image.. it can
pass! Even if it's not an image.
Basic error checking would look like this
<?php
if(!$img_info = getimagesize($some_image))
{
die('You did not upload an image!');
}
?>
However, this will generate a warning, so use of the error supressing operator is advised.
<?php
if(!$img_info = @getimagesize($some_image))
{
die('You did not upload an image!');
}
?>
Seems elementary to some, but I remember this getting me back in the day, when users could upload
straight text files to my database. (i've since learned better security.. heh ;))
Hope that helps a few of the newbies out there. Good luck!