note 50348 added to function.header

From: Date: Fri, 25 Feb 2005 11:04:37 +0000
Subject: note 50348 added to function.header
Groups: php.notes 
Request: Send a blank email to php-notes+get-85528@lists.php.net to get a copy of this message
If you are building a download script and you are afraid of someone exploiting it, I got a solution. Store the information of the downloadable files into a (SQL or text file) database or even in array variable in the code if your list of files is very static. You should store at least the path & filename and unique id-number. You can be creative when thinking what info to store... Build a download script that GETs an id number and checks the database for the file with the given id. Then force download for that file, if it's found, otherwise print an error message. Example use: http://some.host.com/download.php?id=256 --> Downloading file... http://some.host.com/download.php?id=h4x.txt --> Error! File not found! The force-download script can be built many ways stated in this page (in the notes at least). Pick one that forces the download well. It does not need any extra security features, because we got them already. ---- Manual Page -- http://www.php.net/manual/en/function.header.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+50348 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+50348&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#85528) next »