【发布时间】:2015-01-17 11:12:44
【问题描述】:
我正在使用Plupupload 上传文件。如果我尝试使用 IE9 加载 exe 并且文件大小超过 upload_max_filesize 或 post_max_size 设置,则上传的文件已损坏。
这是我正在使用的 PHP 脚本:
<?php
/**
* upload.php
*
* Copyright 2013, Moxiecode Systems AB
* Released under GPL License.
*
* License: http://www.plupload.com/license
* Contributing: http://www.plupload.com/contributing
*/
// Make sure file is not cached (as it happens for example on iOS devices)
header("Expires: Mon, 26 Jul 1997 05:00:00 GMT");
header("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT");
header("Cache-Control: no-store, no-cache, must-revalidate");
header("Cache-Control: post-check=0, pre-check=0", false);
header("Pragma: no-cache");
// 5 minutes execution time
@set_time_limit(5 * 60);
// Settings
$targetDir = __DIR__ . DIRECTORY_SEPARATOR . "upload";
// Create target dir
if (!file_exists($targetDir)) {
@mkdir($targetDir);
}
// Get a file name
if (isset($_REQUEST["name"])) {
$fileName = $_REQUEST["name"];
} elseif (!empty($_FILES)) {
$fileName = $_FILES["file"]["name"];
} else {
$fileName = uniqid("file_");
}
$filePath = $targetDir . DIRECTORY_SEPARATOR . $fileName;
// Chunking might be enabled
$chunk = isset($_REQUEST["chunk"]) ? intval($_REQUEST["chunk"]) : 0;
$chunks = isset($_REQUEST["chunks"]) ? intval($_REQUEST["chunks"]) : 0;
// Open temp file
if (!$out = @fopen("{$filePath}.part", $chunks ? "ab" : "wb")) {
die('{"jsonrpc" : "2.0", "error" : {"code": 102, "message": "Failed to open output stream."}, "id" : "id"}');
}
if (!empty($_FILES)) {
if ($_FILES["file"]["error"] || !is_uploaded_file($_FILES["file"]["tmp_name"])) {
die('{"jsonrpc" : "2.0", "error" : {"code": 103, "message": "Failed to move uploaded file."}, "id" : "id"}');
}
// Read binary input stream and append it to temp file
if (!$in = @fopen($_FILES["file"]["tmp_name"], "rb")) {
die('{"jsonrpc" : "2.0", "error" : {"code": 101, "message": "Failed to open input stream."}, "id" : "id"}');
}
} else {
if (!$in = @fopen("php://input", "rb")) {
die('{"jsonrpc" : "2.0", "error" : {"code": 101, "message": "Failed to open input stream."}, "id" : "id"}');
}
}
while ($buff = fread($in, 4096)) {
fwrite($out, $buff);
}
@fclose($out);
@fclose($in);
// Check if file has been uploaded
if (!$chunks || $chunk == $chunks - 1) {
// Strip the temp .part suffix off
rename("{$filePath}.part", $filePath);
}
// Return Success JSON-RPC response
die('{"jsonrpc" : "2.0", "result" : null, "id" : "id"}');
通过html页面上传:
<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr">
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8"/>
<title>Plupload - Custom example</title>
<!-- production -->
<script type="text/javascript" src="../js/plupload.full.min.js"></script>
</head>
<body style="font: 13px Verdana; background: #eee; color: #333">
<h1>Custom example</h1>
<p>Shows you how to use the core plupload API.</p>
<div id="filelist">Your browser doesn't have Flash, Silverlight or HTML5 support.</div>
<br />
<div id="container">
<a id="pickfiles" href="javascript:;">[Select files]</a>
<a id="uploadfiles" href="javascript:;">[Upload files]</a>
</div>
<br />
<pre id="console"></pre>
<script type="text/javascript">
// Custom example logic
var uploader = new plupload.Uploader({
runtimes : 'html5,flash,silverlight,html4',
browse_button : 'pickfiles', // you can pass in id...
container: document.getElementById('container'), // ... or DOM Element itself
url : 'upload.php',
flash_swf_url : '../js/Moxie.swf',
silverlight_xap_url : '../js/Moxie.xap',
chunk_size : '2mb',
filters : {
max_file_size : '100mb',
mime_types: [
{title : "Image files", extensions : "jpg,gif,png"},
{title : "Zip files", extensions : "zip"},
{title : "Exe files", extensions : "exe"}
]
},
init: {
PostInit: function() {
document.getElementById('filelist').innerHTML = '';
document.getElementById('uploadfiles').onclick = function() {
uploader.start();
return false;
};
},
FilesAdded: function(up, files) {
plupload.each(files, function(file) {
document.getElementById('filelist').innerHTML += '<div id="' + file.id + '">' + file.name + ' (' + plupload.formatSize(file.size) + ') <b></b></div>';
});
},
UploadProgress: function(up, file) {
document.getElementById(file.id).getElementsByTagName('b')[0].innerHTML = '<span>' + file.percent + "%</span>";
},
Error: function(up, err) {
document.getElementById('console').innerHTML += "\nError #" + err.code + ": " + err.message;
}
}
});
uploader.init();
</script>
</body>
</html>
当exe 损坏时,如果我尝试用notepad++ 打开它们,我会发现:
我的设置:
PHP Version 5.5.9
System Windows NT PC-XXX 6.0 build 6002 (Windows Vista Service Pack 2) i586
Compiler MSVC11 (Visual C++ 2012)
Architecture x86
Server API Apache 2.0 Handler
php.ini
max_execution_time=30
max_input_time=60
memory_limit=128M
max_file_uploads=20
附加信息
- 所有 Plupupload 方法(html5、flash、silverlight、html4)都有问题
- 已禁用防病毒软件
- UAC 已禁用
尝试自己发行
我已经为任何想尝试的人创建了一个包。
下载包:http://www.sndesign.it/shared/stackoverflow/plupload-2.1.2.zip
我的plupload-2.1.2.zip 在plupload-2.1.2/examples/upload/file_54c4c1d05c2ef 文件夹中还包含一个损坏的上传文件,以及要尝试上传plupload-2.1.2/examples/TryMe.exe 的文件
准备测试(我使用XAMPP Version 1.8.3):
- 在你的
htdocs中解压plupload-2.1.2.zip - 设置
php.iniupload_max_filesize=22Mpost_max_size=22M(小于TryMe.exe文件大小23MB),重启Apache - 打开 IE9(IE9 总是失败),然后转到:
http://localhost/plupload-2.1.2/examples/custom.html - 选择
%YourHtdocs%/plupload-2.1.2/examples/TryMe.exe中的文件并上传 - 进入
%YourHtdocs%/plupload-2.1.2/examples/upload/,找到上传的文件 - 上传的文件已损坏。
- 设置
php.iniupload_max_filesize=24Mpost_max_size=24M(最大TryMe.exe文件大小23MB),重启Apache - 选择
%YourHtdocs%/plupload-2.1.2/examples/TryMe.exe中的文件并上传 - 进入
%YourHtdocs%/plupload-2.1.2/examples/upload/,找到上传的文件 - 上传的文件没问题。
【问题讨论】:
-
@maytham 用于收集由开发人员上传的独立软件的服务。
-
@maytham 您遇到了什么问题?我用图片和 zip 试了一下,效果很好
-
@maytham 我什至在 github plupupload project 上也报告了这个问题。敬请期待,也许有人找到解决方案...
-
@maytham 我开始赏金了。如果你对这个问题感兴趣,你可以添加赏金或投票给这个问题以提高知名度。
-
每次使用一种上传方式(html5、flash等)定位您的问题
标签: javascript php plupload chunked-encoding