[Patch] Quickform File maxFileSize rule
| From: | Jeroen Houben | Date: | Tue, 25 May 2004 11:44:07 +0000 |
| Subject: | [Patch] Quickform File maxFileSize rule | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-29622@lists.php.net to get a copy of this message | ||
Hi,
Short summary:
The _ruleCheckMaxFileSize() method did not check for upload errors.
Consider the following configuration:
- Your INI only accepts 40MB
- You set maxfilesize of a QF file element to 35MB
- Somebody uploads a file that is 60MB.
The form will validate because effectively the filesize of the temp file
is 0 (it's not there). This is unexpected behaviour. This patch will
check to see if the filesize does not exceed the INI max value or the
hidden form variable MAX_FILE_SIZE.
If it does exceed one of these, it will return false. The patched method
uses constants available from PHP 4.3.0, but they can be replaced by
integers (1 and 2, see:
http://nl3.php.net/manual/en/features.file-upload.errors.php)
Jeroen