PHP mkdir():权限被拒绝



我有一个简单的PHP/HTML/CSS应用程序,可以为新注册的用户创建一个文件夹。它在我的测试站点上运行得很好,并不是说我已经准备好"上线"了——我得到了"mkdir((:权限被拒绝"的错误。据我所知,两个网站的所有设置都是相同的,根文件夹和上传文件夹的文件权限设置为755。其他一切都按预期工作,接受下面的代码。。。

if (count($errors) == 0) {
$pword = md5($pword_1);//encrypt the pword before saving in the database
$rand = "ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890abcdefghijklmnopqrstuvwxyz";
$rand = str_shuffle($rand);
$folder = substr($rand, 0, 10);
$regDate = date("Y-m-d");
$token = 0;
$tokenExp = 0;
$curDir = getcwd();
if(mkdir($curDir . "/uploads/" . $folder, 0755)){
$query = "INSERT INTO users (uname, email, pword, folder, regDate, token, tokenExp) VALUES ('$uname', '$email', '$pword', '$folder', '$regDate', '$token', '$tokenExp')";
mysqli_query($db, $query);
$_SESSION['uname'] = $uname;
$_SESSION['success'] = "You are now logged in";
header('location: index.php');
}else{
array_push($errors, "An error occurred creating your account!!!");
}
}

据我所知,由于无法创建用户的文件夹,我无法上传文件。然而,在进行故障排除时,当我手动将文件夹添加到服务器时,我仍然会收到"未找到路径"的错误。这是上传文件的代码。。。

if(isset($_POST['uploads'])){
$uname = mysqli_real_escape_string($db, $_POST['uname']);
$name = $_FILES['file']['name'];
$size = $_FILES['file']['size'];
$type = $_FILES['file']['type'];
$tmp_name = $_FILES['file']['tmp_name'];
$extension = substr($name, strpos($name, '.') + 1);
$max_size = 2500000; //bytes
if(empty($name)) {
echo "<p class='error'>Please Select a File</p>";
}else{
if($extension == "jpg" || $extension == "jpeg" || $extension == "gif" || $extension == "tif" || $extension == "png" || $extension == "pdf"){
if($extension == $size<=$max_size){
$getFold = "SELECT * FROM users WHERE uname='$uname'";
$getFold = mysqli_query($db, $getFold);
while($for = mysqli_fetch_assoc($getFold)){
$folder = $for['folder'];
}
$location = "uploads/" . $folder . "/";
if(move_uploaded_file($tmp_name, $location . $name)){
$query = "INSERT INTO `upload` (name, size, type, location, uname, folder) VALUES ('$name', '$size', '$type', '$location', '$uname', '$folder')";
$result = mysqli_query($db, $query);
if($result){
echo "<p class='success'>File has been uploaded successfully!!!</p>";
}else{
echo "<p class='error'>Failed to upload file information to database!!! Filename already exist!</p>";
}               
}else{
echo "<p class='error'>Failed to Upload File</p>";
}
}else{
echo "<p class='error'>File size should be 3MB or less</p>";
}
}else{
echo "<p class='error'>The selected file is not a JPG, JPEG, GIF, TIF, PNG, or PDF file type!!!</p>";
}
}
}

您需要将尝试为用户创建子文件夹的文件夹的所有者更改为:

  1. apache-在CentOS服务器的情况下
  2. www-data-在Ubuntu服务器的情况下

您可以使用以下命令

sudo chown -R www-data /folder

-R标志意味着它是递归的,因此运行php的apache/httpd进程也将拥有您可能创建的所有子文件夹。

有关此命令的更多信息,请查看此SO post

您使用权限0755创建目录,这意味着所有者可以完全访问,其他所有者只能读取+执行。更改为07770766;对任何人的完全访问或对所有者的完全访问以及对任何人进行读写
这也适用于父文件夹。

感谢您的帮助,我听从了您的建议,结果发现我的主机提供商阻止了通过cPanel访问的模糊"设置"位置的功能。以前(即在我的旧测试服务器/帐户上(,帐户被自动设置为允许读/写访问,新帐户被设置为只读,并要求帐户所有者通过设置进行切换。

最新更新