Skip to Content
PHP编程:第4版
book

PHP编程:第4版

by Kevin Tatroe, Peter MacIntyre
January 2021
Intermediate to advanced
505 pages
9h 45m
Chinese
Publishing House of Electronics Industry
Content preview from PHP编程:第4版
324
14
安全
php.ini
文件中的
post_max_size
(以字节为单位)配置选项可设置你希望的文件的最大
大小
post_max_size = 1024768; //1MB
PHP
将会忽略数据量超过这个大小的请求。默认
10MB
可能能满足大多数网站的需要。
考虑
EGPCS
设置
默认的
variables_order
EGPCS
environment
GET
POST
cookie
server
)配置先
cookie
处理
GET
POST
参数。这有可能让用户发送
cookie
覆盖你认为包含上传文件
信息的全局变量。为了避免这种欺骗,可使用
is_uploaded_file()
来检查文件是否真正
地上传了。例如
$uploadFilepath = $_FILES['uploaded']['tmp_name'];
if (is_uploaded_file($uploadFilepath)) {
$fp = fopen($uploadFilepath, 'r');
if ($fp) {
$text = fread($fp, filesize($uploadFilepath));
fclose($fp);
//
使用文件内容做一些事
}
}
PHP
提供了
move_uploaded_file()
函数专门用来移动上传的文件。这比用系统级函数或
PHP
copy()
函数直接移动文件要好。例如,下面的代码不可能被
cookie
欺骗
move_uploaded_file($_REQUEST['file'], ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

解密金融数据

解密金融数据

Justin Pauley
算法技术手册(原书第2 版)

算法技术手册(原书第2 版)

George T.Heineman, Gary Pollice, Stanley Selkow
Java持续交付

Java持续交付

Daniel Bryant, Abraham Marín-Pérez

Publisher Resources

ISBN: 9787121404634