2016-02-13 179 views
0

我试图使用由互联网提供的SmartFile下载提供的代码。在代码中,我使用登录ID检查文件名,以避免用户直接在URL中提供不同的文件名。 (因为他很容易猜到,因为文件名的第一部分是来自登录ID) 。我在代码中检查它是否相等,然后允许PDF下载,否则显示访问冲突。 到目前为止每件事情都很好。但下载后,我收到文件已损坏或文件已损坏的消息(它是作为电子邮件附件发送的,未正确解码)。 我找不出问题所在。任何帮助赞赏。谢谢php pdf下载文件损坏

<?php 
session_start(); 
include_once('header.php'); 
if(!$_SESSION['username']) 
{ 

    header("Location: index.php");//redirect to login page to secure the welcome page without login access. 
} 
else 
{ 
$user = $_SESSION['username']; 

// Allow direct file download (hotlinking)? 
// Empty - allow hotlinking 
// If set to nonempty value (Example: example.com) will only allow downloads when referrer contains this text 
define('ALLOWED_REFERRER', ''); 

// Download folder, i.e. folder where you keep all files for download. 
// MUST end with slash (i.e. "/") 
define('BASE_DIR','../../downloads/'); 

// log downloads? true/false 
define('LOG_DOWNLOADS',true); 

// log file name 
define('LOG_FILE','downloads.log'); 

// Allowed extensions list in format 'extension' => 'mime type' 
// If myme type is set to empty string then script will try to detect mime type 
// itself, which would only work if you have Mimetype or Fileinfo extensions 
// installed on server. 
$allowed_ext = array (


    // documents 
    'pdf' => 'application/pdf' 
); 



#################################################################### 
### DO NOT CHANGE BELOW 
#################################################################### 

// If hotlinking not allowed then make hackers think there are some server problems 
if (ALLOWED_REFERRER !== '' 
&& (!isset($_SERVER['HTTP_REFERER']) || strpos(strtoupper($_SERVER['HTTP_REFERER']),strtoupper(ALLOWED_REFERRER)) === false) 
) { 
die("Internal server error. Please contact system administrator."); 
} 

// Make sure program execution doesn't time out 
// Set maximum script execution time in seconds (0 means no limit) 
//set_time_limit(0); 

if (!isset($_GET['f']) || empty($_GET['f'])) { 
    die("Please specify file name for download."); 
} 

// Nullbyte hack fix 
if (strpos($_GET['f'], "\0") !== FALSE) die(''); 

// Get real file name. 
// Remove any path info to avoid hacking by adding relative path, etc. 
$fname = basename($_GET['f']); 
if ($fname == $user."IN".".pdf") 
{ 
// Check if the file exists 
// Check in subfolders too 
function find_file ($dirname, $fname, &$file_path) { 

    $dir = opendir($dirname); 

    while ($file = readdir($dir)) { 
    if (empty($file_path) && $file != '.' && $file != '..') { 
     if (is_dir($dirname.'/'.$file)) { 
     find_file($dirname.'/'.$file, $fname, $file_path); 
     } 
     else { 
     if (file_exists($dirname.'/'.$fname)) { 
      $file_path = $dirname.'/'.$fname; 
      return; 
     } 
     } 
    } 
    } 

} // find_file 

// get full file path (including subfolders) 
$file_path = ''; 
find_file(BASE_DIR, $fname, $file_path); 

if (!is_file($file_path)) { 
    die("File does not exist. Make sure you specified correct file name."); 
} 

// file size in bytes 
$fsize = filesize($file_path); 

// file extension 
$fext = strtolower(substr(strrchr($fname,"."),1)); 

// check if allowed extension 
if (!array_key_exists($fext, $allowed_ext)) { 
    die("Not allowed file type."); 
} 

// get mime type 
if ($allowed_ext[$fext] == '') { 
    $mtype = ''; 
    // mime type is not set, get from server settings 
    if (function_exists('mime_content_type')) { 
    $mtype = mime_content_type($file_path); 
    } 
    else if (function_exists('finfo_file')) { 
    $finfo = finfo_open(FILEINFO_MIME); // return mime type 
    $mtype = finfo_file($finfo, $file_path); 
    finfo_close($finfo); 
    } 
    if ($mtype == '') { 
    $mtype = "application/force-download"; 
    } 
} 
else { 
    // get mime type defined by admin 
    $mtype = $allowed_ext[$fext]; 
} 

// Browser will try to save file with this filename, regardless original filename. 
// You can override it if needed. 

if (!isset($_GET['fc']) || empty($_GET['fc'])) { 
    $asfname = $fname; 
} 
else { 
    // remove some bad chars 
    $asfname = str_replace(array('"',"'",'\\','/'), '', $_GET['fc']); 
    if ($asfname === '') $asfname = 'NoName'; 
} 

// set headers 
header("Pragma: public"); 
header("Expires: 0"); 
header("Cache-Control: must-revalidate, post-check=0, pre-check=0"); 
header("Cache-Control: public"); 
header("Content-Description: File Transfer"); 
header("Content-Type: $mtype"); 
header("Content-Disposition: attachment; filename=\"$asfname\""); 
header("Content-Transfer-Encoding: binary"); 
header("Content-Length: " . $fsize); 

// download 
// @readfile($file_path); 
$file = @fopen($file_path,"rb"); 
if ($file) { 
    while(!feof($file)) { 
    print(@fread($file, 1024*8)); 
    flush(); 
    if (connection_status()!=0) { 
     @fclose($file); 
     die(); 
    } 
    } 
    @fclose($file); 
} 

// log downloads 
if (!LOG_DOWNLOADS) die(); 

$f = @fopen(LOG_FILE, 'a+'); 
if ($f) { 
    @fputs($f, date("m.d.Y g:ia")." ".$_SERVER['REMOTE_ADDR']." ".$fname."\n"); 
    @fclose($f); 
} 
} 
else 
{ 
        echo '<script type="text/javascript">alert("Access Violation !")header("Location: index.php");</script>'; 
} 
} 
?> 
+2

可能有些输出打印在标题之前。要检查它,尝试在第一个'header'调用之前放置'die()',然后检查结果是否完全**为空(请参阅浏览器的源代码页)。如果什么都没有发生,请检查标题中的变量是否已更正($ mtype,$ asfname等);还检查下载文件的文件大小。 – fusion3k

+1

如果您已经有位了,请去掉“标题”调用并直接访问该页面。如果这没有帮助,请从'fopen,fputs,fclose'中删除抑制'@'的错误,看看你看到了什么 – Terminus

+0

谢谢老人。但没有人工作。请帮助 – suresh

回答

0

输出缓冲区在发送任何头文件之前应该被清除,否则文件将被损坏。 ob_end_clean()应该照顾它。