note 27358 added to features.file-upload

From: Date: Tue, 03 Dec 2002 10:40:20 +0000
Subject: note 27358 added to features.file-upload
Groups: php.notes 
Request: Send a blank email to php-notes+get-40292@lists.php.net to get a copy of this message
Here is how I currently do file uploads (you can obviously ignore the display formatting for the form) ... Form code ======== <form name="photoform" action="photos.php" method="post" enctype="multipart/form-data"> <input type="hidden" name="MAX_FILE_SIZE" value="40960"> <table border="0" cellspacing="0" cellpadding="2"> <tr> <td colspan="2" class="emphasis">Use this form to upload your new photographs. Note: only JPEG (.jpg) and PNG (.png) files allowed. Maximimum allowed file size is 40KB.</td> </tr> <tr> <td>Photograph: </td> <td><input type="file" name="photo" /></td> </tr> <tr> <td>Description: </td> <td> <textarea name="photodesc" rows="3" cols="30"><?php echo $_POST["photodesc"] ?></textarea> </td> </tr> <tr> <td colspan="2" align="center"><input type="submit" name="fileupload" value="Upload" /></td> </tr> </table> </form> PHP code ======= if ($_POST["fileupload"] == "Upload") { $errormsg = ""; $filename = $_FILES['photo']['name']; $filetype = $_FILES['photo']['type']; $filesize = (int) $_FILES['photo']['size']; if ($filetype == "image/jpeg" || $filetype == "image/pjpeg" || $filetype == "image/png" || $filetype == "image/x-png") { if ($filesize < 40960 && $filesize > 0) { $storename = $uniqueid = md5 (uniqid (rand)); if ($filetype == "image/jpeg" || $filetype == "image/pjpeg") $storename .= ".jpg"; if ($filename == "image/png" || $filetype == "image/x-png") $storename .= ".png"; $desc = $_POST["photodesc"]; // Store the file in the photos folder and add record to database if (is_uploaded_file ($_FILES['photo']['tmp_name'])) { if (!@move_uploaded_file ($_FILES['photo']['tmp_name'], $photospath.$storename)) { $errormsg .= " Problem uploading the file. Please try again. If the problem persists please email support@huntclubservices.com to report the error."; } else { @chmod ($photospath.$storename, 0644); $sql = "INSERT INTO hcs_photos (clientID,photoName,photoTitle,uploadTimeStamp) VALUES ('". $_SESSION["clientID"] ."','$storename','$desc','$timestamp')"; $db->Query ($sql, $conn); } } else { $errormsg .= "Possible file upload attack. Filename: ". $_FILES['photo']['name']; } } else { $errormsg .= "Invalid file size. Maximum of 40KB allowed"; } } else { $errormsg .= "Invalid file type. Only JPEG and PNG files allowed"; } if (strlen ($errormsg) < 5) { header ("Location: ". $baseurl ."photos.php"); } } Maybe someone will find it useful. Ian. http://www.siteguru.co.uk -- http://www.php.net/manual/en/features.file-upload.php http://master.php.net/manage/user-notes.php?action=edit+27358 http://master.php.net/manage/user-notes.php?action=delete+27358 http://master.php.net/manage/user-notes.php?action=reject+27358

« previous php.notes (#40292) next »