note 68659 deleted from function.header by tularis
| From: | tularis@php.net | Date: | Fri, 20 Apr 2007 14:22:18 +0000 |
| Subject: | note 68659 deleted from function.header by tularis | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-125640@lists.php.net to get a copy of this message | ||
Note Submitter: admin at commoncents dot net dot au
----
Thanks for everyones help with this guy's,
I am using session_start and need to have files available for users to download whilst ensuring that
only users who are logged in can download the files.
The other priority is that I needed to make sure that users cannot type something like
download.php?dl=index.php or ../index.php
I have taken the best points from everything above and now use:
<?php
include "config.php"; \\ config.php contains the session information
header('Cache-Control: public');
if ( $_SESSION["logged_in"] == 1){
$dir="downloadfolder/";
$file=$dir.$_GET["dl"];
if (isset($_REQUEST['dl']) && file_exists($file) ) {
header('Pragma: anytextexeptno-cache', true);
header('Content-type: application/force-download');
header('Content-Transfer-Encoding: Binary');
header('Content-length: '.filesize($file));
header('Content-disposition: attachment;
filename='.basename($file));
readfile($file);
} else {
echo 'No file with this name for download.';
}
}else{
echo "You are not logged in<br>";
}
?>