note 68659 deleted from function.header by tularis

From: Date: Fri, 20 Apr 2007 14:22:18 +0000
Subject: note 68659 deleted from function.header by tularis
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-125640@lists.php.net to get a copy of this message
Note Submitter: admin at commoncents dot net dot au ---- Thanks for everyones help with this guy's, I am using session_start and need to have files available for users to download whilst ensuring that only users who are logged in can download the files. The other priority is that I needed to make sure that users cannot type something like download.php?dl=index.php or ../index.php I have taken the best points from everything above and now use: <?php include "config.php"; \\ config.php contains the session information header('Cache-Control: public'); if ( $_SESSION["logged_in"] == 1){ $dir="downloadfolder/"; $file=$dir.$_GET["dl"]; if (isset($_REQUEST['dl']) && file_exists($file) ) { header('Pragma: anytextexeptno-cache', true); header('Content-type: application/force-download'); header('Content-Transfer-Encoding: Binary'); header('Content-length: '.filesize($file)); header('Content-disposition: attachment; filename='.basename($file)); readfile($file); } else { echo 'No file with this name for download.'; } }else{ echo "You are not logged in<br>"; } ?>

« previous php.notes (#125640) next »