Re: File_Upload and Image_Upload

From: Date: Sun, 15 Jul 2001 12:31:56 +0000
Subject: Re: File_Upload and Image_Upload
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-772@lists.php.net to get a copy of this message
Hi Thomas > - People would need to use printForm for building the form, so for > example it can not be integrated with templates. I'd thought about extending HTML/Form for this? > - It relies in the information given from the form (easy to forge) > rather than in Web server env vars. > - It detect errors at "uploading" time, so you need to do the final > upload to know if the file was an error or not. Noted > - It doesn't do needed checks about the destination dir or file, and > won't return any information about the error if the destination is > unusable. It does a check for is_writeable and I'm intending to add file renaming for overwrites > - It doesn't gives to the developer information about the uploaded file. If UPLOAD_DEBUG_OUTPUT is true the developer gets info regarding everything that was uploaded, is this what you mean? > - The idea of extending the upload class to treat some kind of files, > seems for me far from the concept of "upload files". Also the API for > extending is not very well defined as it needs to repeat almost all the > code of the base class. I had major concerns with the way I'd extended it, now I know that they were valid, however regarding the principle of extending for different file types, I see no problem with specific Methods for Certain file types in separate classes. > - It doesn't provides a method to protect file names, so people could > upload files with special formatted names that can open a security hole. Noted > - Perhaps I'm wrong, but I think that the mime type is sent by the > browser, and as it could be forge, the system to deny certain files > becomes very weak. I think you're right about the MIME type, but how else does one check the uploaded file type? I'm using $HTTP_POST_FILES[xxx]['type'] as a check to see that the user doesn't upload a word doc to a place where the developer wanted a gif or whatever > - It hasn't good documentation and examples of use. Well, I finished it @ 1.30am last night so I'm not going to feel too bad about that ;) > (http://vulcanonet.com/soft/index.php?pack=uploader) I wish I'd known that this was in existence before I started writing it, I probably would have directed my energies elsewhere. thanks for the feedback ;D -- Darren Beale mail@bealers.com Who wants the rewind?

« previous php.pear.dev (#772) next »