Re: File_Upload and Image_Upload
| From: | Bealers | Date: | Sun, 15 Jul 2001 12:31:56 +0000 |
| Subject: | Re: File_Upload and Image_Upload | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-772@lists.php.net to get a copy of this message | ||
Hi Thomas
> - People would need to use printForm for building the form, so for
> example it can not be integrated with templates.
I'd thought about extending HTML/Form for this?
> - It relies in the information given from the form (easy to forge)
> rather than in Web server env vars.
> - It detect errors at "uploading" time, so you need to do the final
> upload to know if the file was an error or not.
Noted
> - It doesn't do needed checks about the destination dir or file, and
> won't return any information about the error if the destination is
> unusable.
It does a check for is_writeable and I'm intending to add file renaming for
overwrites
> - It doesn't gives to the developer information about the uploaded file.
If UPLOAD_DEBUG_OUTPUT is true the developer gets info regarding everything
that was uploaded, is this what you mean?
> - The idea of extending the upload class to treat some kind of files,
> seems for me far from the concept of "upload files". Also the API for
> extending is not very well defined as it needs to repeat almost all the
> code of the base class.
I had major concerns with the way I'd extended it, now I know that they were
valid, however regarding the principle of extending for different file
types, I see no problem with specific Methods for Certain file types in
separate classes.
> - It doesn't provides a method to protect file names, so people could
> upload files with special formatted names that can open a security hole.
Noted
> - Perhaps I'm wrong, but I think that the mime type is sent by the
> browser, and as it could be forge, the system to deny certain files
> becomes very weak.
I think you're right about the MIME type, but how else does one check the
uploaded file type?
I'm using $HTTP_POST_FILES[xxx]['type'] as a check to see that the user
doesn't upload a word doc
to a place where the developer wanted a gif or whatever
> - It hasn't good documentation and examples of use.
Well, I finished it @ 1.30am last night so I'm not going to feel too bad
about that ;)
> (http://vulcanonet.com/soft/index.php?pack=uploader)
I wish I'd known that this was in existence before I started writing it, I
probably would have directed my energies elsewhere.
thanks for the feedback
;D
--
Darren Beale
mail@bealers.com
Who wants the rewind?