note 27358 deleted from features.file-upload by philip
| From: | philip@php.net | Date: | Sat, 18 Jan 2003 08:41:09 +0000 |
| Subject: | note 27358 deleted from features.file-upload by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-42338@lists.php.net to get a copy of this message | ||
Here is how I currently do file uploads (you can obviously ignore the display formatting for the
form) ...
Form code
========
<form name="photoform" action="photos.php" method="post"
enctype="multipart/form-data">
<input type="hidden" name="MAX_FILE_SIZE" value="40960">
<table border="0" cellspacing="0" cellpadding="2">
<tr>
<td colspan="2" class="emphasis">Use this form to upload your new
photographs. Note: only JPEG (.jpg) and PNG (.png) files allowed. Maximimum allowed file size is
40KB.</td>
</tr>
<tr>
<td>Photograph: </td>
<td><input type="file" name="photo" /></td>
</tr>
<tr>
<td>Description: </td>
<td>
<textarea name="photodesc" rows="3" cols="30"><?php echo
$_POST["photodesc"] ?></textarea>
</td>
</tr>
<tr>
<td colspan="2" align="center"><input type="submit"
name="fileupload" value="Upload" /></td>
</tr>
</table>
</form>
PHP code
=======
if ($_POST["fileupload"] == "Upload") {
$errormsg = "";
$filename = $_FILES['photo']['name'];
$filetype = $_FILES['photo']['type'];
$filesize = (int) $_FILES['photo']['size'];
if ($filetype == "image/jpeg" || $filetype == "image/pjpeg" || $filetype ==
"image/png" || $filetype == "image/x-png") {
if ($filesize < 40960 && $filesize > 0) {
$storename = $uniqueid = md5 (uniqid (rand));
if ($filetype == "image/jpeg" || $filetype == "image/pjpeg") $storename .=
".jpg";
if ($filename == "image/png" || $filetype == "image/x-png") $storename .=
".png";
$desc = $_POST["photodesc"];
// Store the file in the photos folder and add record to database
if (is_uploaded_file ($_FILES['photo']['tmp_name'])) {
if (!@move_uploaded_file ($_FILES['photo']['tmp_name'],
$photospath.$storename)) {
$errormsg .= " Problem uploading the file. Please try again. If the problem persists
please email support@huntclubservices.com to report the error.";
} else {
@chmod ($photospath.$storename, 0644);
$sql = "INSERT INTO hcs_photos (clientID,photoName,photoTitle,uploadTimeStamp) VALUES
('". $_SESSION["clientID"]
."','$storename','$desc','$timestamp')";
$db->Query ($sql, $conn);
}
} else {
$errormsg .= "Possible file upload attack. Filename: ".
$_FILES['photo']['name'];
}
} else {
$errormsg .= "Invalid file size. Maximum of 40KB allowed";
}
} else {
$errormsg .= "Invalid file type. Only JPEG and PNG files allowed";
}
if (strlen ($errormsg) < 5) {
header ("Location: ". $baseurl ."photos.php");
}
}
Maybe someone will find it useful.
Ian.
http://www.siteguru.co.uk