note 25319 deleted from features.file-upload by vincent
| From: | vincent@php.net | Date: | Thu, 11 Sep 2003 12:07:02 +0000 |
| Subject: | note 25319 deleted from features.file-upload by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-56099@lists.php.net to get a copy of this message | ||
Note Submitter: martellare@hotmail.com
----
[EDITOR'S NOTE]
It is unsafe to trust a browser in such cases. Instead of using:
<input type="hidden" name="MAX_FILE_SIZE" value="1">
You should use (after upload):
if($_FILES['userfile']['size'] <= 1){
// do stuff
}else{
echo 'file too big';
}
[/NOTE]
Just to note... I've found that it is very import where you place your <INPUT
type="hidden" name="MAX_FILE_SIZE"> tag in your <FORM>. It must be
before your <INPUT type="file">, or else it won't be accepted. I found that
this would affect code danCabral@lycos.com's (above). The following form...
<form ENCTYPE="multipart/form-data" method="POST">
<input TYPE="FILE" NAME="userfile">
<input type="hidden" name="MAX_FILE_SIZE" value="1">
<input type="submit">
</form>
... Will accept ANY file up to the the MAX_FILE_SIZE directive in php.ini. If you move things
around like this
<form ENCTYPE="multipart/form-data" method="POST">
<input type="hidden" name="MAX_FILE_SIZE" value="1">
<input TYPE="FILE" NAME="userfile">
<input type="submit">
</form>
...it will then restrict files to <= 1 byte.
(I experienced this issue on IE 6.0 and Netscape 4.08, PHP 4.2.2, running Win XP)