【发布时间】:2014-05-15 02:32:07
【问题描述】:
我正在尝试创建用户上传图像的 zip 文件,当用户单击按钮时将生成该文件以供下载。该按钮位于 Wordpress 管理员的页面上。该页面来自添加新管理部分的插件。单击按钮时,它会将表单提交到“themes/twentyfourteen/page-templates”目录中的页面。该页面名为 cartoon_zip.php,是通过管理中的 Pages 部分创建的,因此它的 url 为 http://www.sitename.com/cartoon-zip/。当我单击该文件时,它似乎可以工作。没有错误发生,并出现一个保存文件对话框。我将文件保存在本地并尝试解压缩,但收到消息“无法使用此程序提取文件“characters.zip”的内容。”我在 Mac 上,所以是 The Unarchiver 试图打开;它也不能在 PC 上运行。下面是我正在使用的代码;非常感谢任何帮助。
<?php
/*
Template name: Cartoon Zip
*/
if(isset($_REQUEST['order_id'])){
$order_id = $_REQUEST['order_id'];
$query = "SELECT optional_image FROM order_listing WHERE order_no = '".$order_id."'";
$query2 = "SELECT main_image FROM character_order WHERE order_id = '".$order_id."'";
$entries = $wpdb->get_results($query);
$entries2 = $wpdb->get_results($query2);
$error = ""; //error holder
if(extension_loaded('zip')){ // Checking ZIP extension is available
$zip = new ZipArchive(); // Load zip library
$zip_name = "characters.zip"; // Zip name
if($zip->open($zip_name, ZIPARCHIVE::CREATE)!==TRUE){ // Opening zip file to load files
$error .= "* Sorry ZIP creation failed at this time<br/>";
}
foreach( $entries as $entry ) {
$image=$entry->optional_image;
if(!empty($image)):
$url = 'wp-content/themes/twentyfourteen/upload/main/'.$image;
if(file_exists($url)){
$zip->addFile($url,$image); // Adding files into zip
}
endif;
}
foreach( $entries2 as $entry ) {
$image=$entry->main_image;
if(!empty($image)):
$url = 'wp-content/themes/twentyfourteen/upload/character/'.$image;
if(file_exists($url)){
$zip->addFile($url,$image); // Adding files into zip
}
endif;
}
if ($zip->close() === false) {
exit("Error creating ZIP file");
};
$filename = $zip_name;
// send $filename to browser
$finfo = finfo_open(FILEINFO_MIME_TYPE);
$mimeType = finfo_file($finfo, $filename);
$size = filesize($filename);
$name = basename($filename);
if (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] == 'on') {
// cache settings for IE6 on HTTPS
header('Cache-Control: max-age=120');
header('Pragma: public');
} else {
header('Cache-Control: private, max-age=120, must-revalidate');
header("Pragma: no-cache");
}
header("Expires: Sat, 26 Jul 1997 05:00:00 GMT"); // long ago
header("Content-Type: $mimeType");
header('Content-Disposition: attachment; filename="' . $name . '";');
header("Accept-Ranges: bytes");
header('Content-Length: ' . filesize($filename));
readfile($fullFilePath);
exit;
}else
$error .= "* You dont have ZIP extension<br/>";
}
?>
编辑:所以我设法通过下面的组合 doublesharp 的帮助以及将标题更改为以下内容来解决这个问题。
$file = $zip_name;
if (file_exists($file)) {
header('Content-Description: File Transfer');
header('Content-Type: application/octet-stream');
header('Content-Disposition: attachment; filename='.basename($file));
header('Expires: 0');
header('Cache-Control: must-revalidate');
header('Pragma: public');
header('Content-Length: ' . filesize($file));
ob_clean();
flush();
readfile($file);
exit;
}
这是完整的工作代码。
<?php
/*
Template name: Cartoon Zip
*/
if(isset($_REQUEST['order_id'])){
global $wpdb;
$order_id = isset( $_REQUEST['order_id'] )? $_REQUEST['order_id'] : 0;
$query = $wpdb->prepare( "SELECT optional_image FROM order_listing WHERE order_no = %s", $order_id );
$query2 = $wpdb->prepare( "SELECT main_image FROM character_order WHERE order_id = %s", $order_id );
$entries = $wpdb->get_results($query);
$entries2 = $wpdb->get_results($query2);
$error = ""; //error holder
if(extension_loaded('zip')){ // Checking ZIP extension is available
$zip = new ZipArchive(); // Load zip library
$zip_name = "characters.zip"; // Zip name
if($zip->open($zip_name, ZIPARCHIVE::CREATE)!==TRUE){ // Opening zip file to load files
$error .= "* Sorry ZIP creation failed at this time<br/>";
}
foreach( $entries as $entry ) {
$image=$entry->optional_image;
if( ! empty( $image ) ){
$filename = WP_CONTENT_DIR.'/themes/twentyfourteen/upload/main/'.$image;
if ( file_exists( $filename ) ){
// Adding files into zip
$zip->addFile( $filename, $image );
}
}
}
foreach( $entries2 as $entry ) {
$image=$entry->main_image;
if( ! empty( $image ) ){
$filename = WP_CONTENT_DIR.'/themes/twentyfourteen/upload/character/'.$image;
if ( file_exists( $filename ) ){
// Adding files into zip
$zip->addFile( $filename, $image );
}
}
}
if ($zip->close() === false) {
exit("Error creating ZIP file");
};
$file = $zip_name;
if (file_exists($file)) {
header('Content-Description: File Transfer');
header('Content-Type: application/octet-stream');
header('Content-Disposition: attachment; filename='.basename($file));
header('Expires: 0');
header('Cache-Control: must-revalidate');
header('Pragma: public');
header('Content-Length: ' . filesize($file));
ob_clean();
flush();
readfile($file);
exit;
}
}else
$error .= "* You dont have ZIP extension<br/>";
}
?>
【问题讨论】:
-
你有一个 SQL 注入漏洞,你应该在你的 SQL 中使用
$wpdb->prepare()on$order_id。 -
感谢您指出这一点。我通常不使用 PHP 或 Wordpress。
标签: php wordpress download ziparchive