note 25319 deleted from features.file-upload by vincent

From: Date: Thu, 11 Sep 2003 12:07:02 +0000
Subject: note 25319 deleted from features.file-upload by vincent
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-56099@lists.php.net to get a copy of this message
Note Submitter: martellare@hotmail.com ---- [EDITOR'S NOTE] It is unsafe to trust a browser in such cases. Instead of using: <input type="hidden" name="MAX_FILE_SIZE" value="1"> You should use (after upload): if($_FILES['userfile']['size'] <= 1){ // do stuff }else{ echo 'file too big'; } [/NOTE] Just to note... I've found that it is very import where you place your <INPUT type="hidden" name="MAX_FILE_SIZE"> tag in your <FORM>. It must be before your <INPUT type="file">, or else it won't be accepted. I found that this would affect code danCabral@lycos.com's (above). The following form... <form ENCTYPE="multipart/form-data" method="POST"> <input TYPE="FILE" NAME="userfile"> <input type="hidden" name="MAX_FILE_SIZE" value="1"> <input type="submit"> </form> ... Will accept ANY file up to the the MAX_FILE_SIZE directive in php.ini. If you move things around like this <form ENCTYPE="multipart/form-data" method="POST"> <input type="hidden" name="MAX_FILE_SIZE" value="1"> <input TYPE="FILE" NAME="userfile"> <input type="submit"> </form> ...it will then restrict files to <= 1 byte. (I experienced this issue on IE 6.0 and Netscape 4.08, PHP 4.2.2, running Win XP)

« previous php.notes (#56099) next »