in reply to Re: Non-Duplicate File Names, Security, and Self Cleaning
in thread Non-Duplicate File Names, Security, and Self Cleaning

Users don't log in. Really only one person is wanting some img files. Just my brain started spinning and thought I could do it this way to learn something in the process. If I wind up making something usefull that I or other people would want to use again later, great! I was wanting to make unique names, though, just because that would mean learning how to do something, and because someday if the code is good it might be used in a more trafficed scenario.

I thought letting users delete the file themselves could make for some big security holes, and there are also lazy users out there. I just didn't know that I could make the script delete the file, but it seemed like something I should be able to do (yep, I'm still quite the newbie!)

Thanks,
Petras
Don't worry about people stealing your ideas. If your ideas are any good, you'll have to ram them down people's throats.

-Howard Aiken
  • Comment on Re: Re: Non-Duplicate File Names, Security, and Self Cleaning

Replies are listed 'Best First'.
Re: Re: Re: Non-Duplicate File Names, Security, and Self Cleaning
by Skeeve (Parson) on Jun 06, 2003 at 07:28 UTC
    > Users don't log in. [...] I could do it this way to learn
    So this is another option for you to learn. ;-)

    > I thought letting users delete the file themselves could make for some big security holes
    It depends on how you do it. Each user should be able to delete just her own files. So if you make up some rally good random name this shouldn't be a problem. Just remember that your script should not allow any character in filenames to delete other than those characters you use in your generated filenames. Espacially no "/"!

    > and there are also lazy users out there
    That's why I said you should do it if you take the 10-minute-than-delete-way. So user can be gentle and delete the file after they used it.
    While I write it: Why don't you simply store the indices of the selected pictures in a cookie? If you don't have to many pictures this shouldn't be a problem. You could even save some space if you use a vec-tor to store which pics are choosen. When the user clicks on "download" the ZIP will be generated "on the fly" and will never appear in any direcory on the server.
    Just some more opportunities for you to learn from ;-)

      > > Users don't log in. ... I could do it this way to learn
      > So this is another option for you to learn. ;-)


      The difference is, with a check-box form my friend might look at it and say, "Hey, this is kinda cool." But if I make her log in she might say, "You geek! Why do I need to log in to something you set up for me to download images for a single presentation?" ;)

      Okay, so maybe I'm not that into learning right now. It's the Petras lazyness/ingenuity cycle. I should write an algorhythm about it someday....

      Where I've taken this idea/learning-experience is posted here if you are interested.
      Cheers!
      -P
      Don't worry about people stealing your ideas. If your ideas are any good, you'll have to ram them down people's throats.

      -Howard Aiken