您最好徹底檢查 $_FILES 結構和值。
以下程式碼絕對不會造成任何錯誤。
範例
<?php
header('Content-Type: text/plain; charset=utf-8');
try {
if (
!isset($_FILES['upfile']['error']) ||
is_array($_FILES['upfile']['error'])
) {
throw new RuntimeException('無效的參數。');
}
switch ($_FILES['upfile']['error']) {
case UPLOAD_ERR_OK:
break;
case UPLOAD_ERR_NO_FILE:
throw new RuntimeException('未傳送檔案。');
case UPLOAD_ERR_INI_SIZE:
case UPLOAD_ERR_FORM_SIZE:
throw new RuntimeException('超出檔案大小限制。');
default:
throw new RuntimeException('未知的錯誤。');
}
if ($_FILES['upfile']['size'] > 1000000) {
throw new RuntimeException('超出檔案大小限制。');
}
$finfo = new finfo(FILEINFO_MIME_TYPE);
if (false === $ext = array_search(
$finfo->file($_FILES['upfile']['tmp_name']),
array(
'jpg' => 'image/jpeg',
'png' => 'image/png',
'gif' => 'image/gif',
),
true
)) {
throw new RuntimeException('無效的檔案格式。');
}
if (!move_uploaded_file(
$_FILES['upfile']['tmp_name'],
sprintf('./uploads/%s.%s',
sha1_file($_FILES['upfile']['tmp_name']),
$ext
)
)) {
throw new RuntimeException('無法移動上傳的檔案。');
}
echo '檔案上傳成功。';
} catch (RuntimeException $e) {
echo $e->getMessage();
}
?>