Uploads and .htaccess

Contents
The $_FILES array
Validate and move
Clean URLs with rewrite
Safe rule patterns

The $_FILES array

A form with a file input arrives in $_FILES, not $_POST. Each entry carries five keys: name, type, tmp_name, error, and size. Check error first - it tells whether a file arrived at all.

if ($_FILES["photo"]["error"] === UPLOAD_ERR_OK) { echo $_FILES["photo"]["size"]; }

Validate and move

Uploaded files sit in a temp folder and vanish at the end of the request. Keep them with move_uploaded_file(), but only after checks: a real upload, a sane size, an allowed extension. Never trust the client name - build the target name yourself.

$ext = strtolower(pathinfo($_FILES["photo"]["name"], PATHINFO_EXTENSION)); if ($ext === "png" || $ext === "jpg") { $target = "/srv/www/uploads/img_" . time() . "." . $ext; move_uploaded_file($_FILES["photo"]["tmp_name"], $target); }

Clean URLs with rewrite

Clean URLs turn post.php?id=7 into post/7. Apache does it with rewrite rules in .htaccess: match the pretty path, silently serve the real file. PHP keeps reading $_GET like nothing changed.

RewriteEngine On RewriteRule ^post/([0-9]+)$ post.php?id=$1 [L]

Safe rule patterns

Order rules from specific to general, anchor both ends, and end each rule so matching stops after the first hit. Test with curl after every edit - one greedy rule can swallow the whole site. The full rule reference is Creating rules in .htaccess.

RewriteRule ^about$ about.php [L] RewriteRule ^post/([0-9]+)$ post.php?id=$1 [L]

Next: Lint like a pro

Article author: Arthur Isaev

Related articles
Development with PHP
PHP course: zero to hero in 50 lessons
What is PHP and where it runs
Install PHP 8.5 and run your first command
Your first PHP script
Comments in PHP
Variables and constants
Types in PHP
Strings in PHP
Numbers in PHP
Operators
if and else
switch and match
Ternary, null coalescing and nullsafe
Loops
Arrays
Associative arrays
Functions
Variable scope
include and require
Namespaces
Composer and autoloading
Everyday string functions
Dates and time
JSON in PHP
Reading and writing files
Errors: read, reproduce, fix
Classes and objects
Constructors and promotion
Inheritance
Interfaces and traits
Enums
Magic methods
Attributes
Exceptions
Strict types
Closures and arrow functions
Generators with yield
Forms: GET and POST
HTTP: headers and status codes
Cookies
Sessions
Login with sessions
JSON REST endpoint
Database with PDO
Uploads and .htaccess
Lint like a pro
Clean functions
Debugging
Modern PHP tour: 5 to 8.4
PHP 8.5 for busy developers
Hero roadmap: the whole course on one page
Install PHP 8.5 on Windows 11
Install PHP 8.5 on Ubuntu
Install PHP 8.5 on Rocky Linux
Install PHP 8.5 on macOS
Install PHP 8.5 on FreeBSD
PHP 8.5 in Docker

Search this site

Channel @aofeed Chat @aofeedchat

Contacts and cooperation:
I recommend our hosting beget.ru
Write to info@urn.su if you:
1. Want to write an article for our site or translate an article into your native language.
2. Want to place thematically relevant ads on the site.
3. Ads on my site pass maximum censorship. If you see an ad block unsuitable for school-age children, shocking or misleading - please contact us by e-mail
4. Found a mistake, inaccuracy, bug, etc. on the site. ... .......
5. Articles can be shared on social media by clicking a network icon: