note 18336 added to function.filesize

From: Date: Fri, 18 Jan 2002 19:29:43 +0000
Subject: note 18336 added to function.filesize
Groups: php.notes 
Request: Send a blank email to php-notes+get-25056@lists.php.net to get a copy of this message
Always, always use this function to compliment (and validate) the HTML hidden field, "MAX_FILE_SIZE", even though it can be bypassed. The reason this is necessary is because when you use filesize(), it uploads the file to the server first, then determines the size (because, of course, server-side processing happens on said server end), before returning with an error (if too large) or submitting the file, if the conditions are met. I discovered this simply testing a PHP-based file sharing application I wrote, by trying to upload a 20MB+ PSD file and ensuring my error message came up properly. It took about ten minutes just to realise that I had better use MAX_FILE_SIZE in all my upload forms, and in fact is still testing while I am typing this. // two mins later ... and my error message didn't work, back to the drawing board. -- http://www.php.net/manual/en/function.filesize.php http://master.php.net/manage/user-notes.php?action=edit+18336 http://master.php.net/manage/user-notes.php?action=delete+18336 http://master.php.net/manage/user-notes.php?action=reject+18336

« previous php.notes (#25056) next »