
时间:2011-04-06 19:58:39

标签: php permissions upload


//define a maxim size for the uploaded images in Kb
 define ("MAX_SIZE","5000"); 

//This function reads the extension of the file. It is used to determine if the file  is an image by checking the extension.
 function getExtension($str) {
         $i = strrpos($str,".");
         if (!$i) { return ""; }
         $l = strlen($str) - $i;
         $ext = substr($str,$i+1,$l);
         return $ext;

//This variable is used as a flag. The value is initialized with 0 (meaning no error  found)  
//and it will be changed to 1 if an errro occures.  
//If the error occures the file will not be uploaded.

    //reads the name of the file the user submitted for uploading

    //if it is not empty
    if ($image) 
    //get the original name of the file from the clients machine
        $filename = stripslashes($_FILES['image']['name']);
    //get the extension of the file in a lower case format
        $extension = getExtension($filename);
        $extension = strtolower($extension);
    //if it is not a known extension, we will suppose it is an error and will not  upload the file,  
    //otherwise we will do more tests
 if (($extension != "jpg") && ($extension != "jpeg") && ($extension != "png")) 
        //print error message
            echo '<h1>Nepoznata vrsta fajla!</h1>';
//get the size of the image in bytes
 //$_FILES['image']['tmp_name'] is the temporary filename of the file
 //in which the uploaded file was stored on the server

//compare the size with the maxim size we defined and print error if bigger
if ($size > MAX_SIZE*1024)
    echo '<h1>To large file!</h1>';

//we will give an unique name, for example the time in unix time format
//the new name will be containing the full path where will be stored (images folder)
//we verify if the image has been uploaded, and print error instead
//$copied = copy($_FILES['image']['tmp_name'], $newname);

$copied = copy('$_FILES['image']['tmp_name'], $newname);

//echo $_FILES['image']['tmp_name'].'<br/>';
//echo $_FILES['image']['name'];

if (!$copied) 
    echo '<h1>Error occurred!</h1>';

//If no errors registred, print the success message
 /*if(isset($_POST['Submit']) && !$errors) 
    echo "<h1>You have successfully uploaded image.</h1>";




5 个答案:

答案 0 :(得分:14)

确保将保存文件(tmp)的文件夹权限设置为777。 在终端上输入chmod -R 777 path

答案 1 :(得分:1)


drwxrwxr-x root root应用程序
drwxrwxr-x apache apache FilesystemDir

答案 2 :(得分:1)




  • /路径
  • /路径/到
  • 和/path/to/test-in.txt
  • 的读取权限

在此查看更多详情 fopen() fails to open stream: permission denied, yet permissions should be valid

答案 3 :(得分:0)


$copied = copy('$_FILES['image']['tmp_name'], $newname);
               ^--- extra quote?


$copied = copy("$_FILES['image']['tmp_name']", $newname);

它无论如何都行不通。 PHP的解析器不是很好,并且会将其视为

$_FILES['image'] -> array
['tmp_name'] -> string


$copied = copy("Array['tmp_name']" ....);

在任何情况下,您都应该使用move_uploaded_file()来处理移动的上传文件,而不是copy()。 m_u_l有额外的检查,以确保在上传完成和脚本试图移动之间没有人篡改文件。

答案 4 :(得分:0)

以上内容都无法解决我的问题。 实际上,目录和文件对用户php(=='www-data')具有良好的权利。 但是

dump(exec("whoami")); // returns 'another'

帮助确定php用户不是等待已久的用户(“ www-data”),而是“另一个”。

某些程序已编辑/ etc / apache2 / envvars

export APACHE_RUN_USER=another
export APACHE_RUN_GROUP=another


export APACHE_RUN_USER=www-data
export APACHE_RUN_GROUP=www-data


sudo service apache2 restart
