Uploads and .htaccess
| The $_FILES array | |
| Validate and move | |
| Clean URLs with rewrite | |
| Safe rule patterns |
The $_FILES array
A form with a file input arrives in $_FILES, not $_POST. Each entry carries five keys: name, type, tmp_name, error, and size. Check error first - it tells whether a file arrived at all.
if ($_FILES["photo"]["error"] === UPLOAD_ERR_OK) { echo $_FILES["photo"]["size"]; }
Validate and move
Uploaded files sit in a temp folder and vanish at the end of the request. Keep them with move_uploaded_file(), but only after checks: a real upload, a sane size, an allowed extension. Never trust the client name - build the target name yourself.
$ext = strtolower(pathinfo($_FILES["photo"]["name"], PATHINFO_EXTENSION)); if ($ext === "png" || $ext === "jpg") { $target = "/srv/www/uploads/img_" . time() . "." . $ext; move_uploaded_file($_FILES["photo"]["tmp_name"], $target); }
Clean URLs with rewrite
Clean URLs turn post.php?id=7 into post/7. Apache does it with rewrite rules in .htaccess: match the pretty path, silently serve the real file. PHP keeps reading $_GET like nothing changed.
RewriteEngine On RewriteRule ^post/([0-9]+)$ post.php?id=$1 [L]
Safe rule patterns
Order rules from specific to general, anchor both ends, and end each rule so matching stops after the first hit. Test with curl after every edit - one greedy rule can swallow the whole site. The full rule reference is Creating rules in .htaccess.
RewriteRule ^about$ about.php [L] RewriteRule ^post/([0-9]+)$ post.php?id=$1 [L]
Next: Lint like a pro
Article author: Arthur Isaev