Resources · 95

File uploads: validate before processing or publishing

Control format, resources, access and states from receipt to download.

· 3 min

Laptop displaying code on a desk Illustration · fictional scene

What this guide helps achieve

  • Define needs and limits
  • Validate on the server
  • Isolate received files
  • Bound processing
  • Control release and removal

Quick check

  • Is a valid extension enough?
  • Is antivirus sufficient?
  • What should pending analysis show?

Step-by-step method

  1. 01

    Define needs and limits

    Allow only formats needed for the task. Specify size, dimensions, duration, page or file count as appropriate. Bound processing time and memory as well as transfer size.

    Output: Format and resource contract.

  2. 02

    Validate on the server

    Browser accept hints assist selection but do not secure receipt. Check extension, declared type and content using maintained tools. No single signal establishes file safety.

    Output: Server-validation tests.

  3. 03

    Isolate received files

    Assign server identifiers rather than constructing paths from user filenames. Keep files outside the public document root with restricted access. Show a pending state until checks finish.

    Output: Isolated storage and explicit states.

  4. 04

    Bound processing

    Scan, convert or reconstruct permitted formats with suitable limits and isolation. Do not send sensitive documents to a public scanner without an explicit data-sharing decision. Scanner failure does not imply approval.

    Output: Bounded processing and failure scenario.

  5. 05

    Control release and removal

    Check access rights on every read. Trace rejection, approval, publication and deletion. Test limits, interruption, corrupt files and recovery without exposing quarantined content.

    Output: Access and removal acceptance tests.

Receipt is not publication

Each step produces a distinct state. Failure leaves the file isolated.

  1. Receipt

    Server identifier, permissions and limits.

  2. Validation

    Format, content and resources checked.

  3. Decision

    Approved, rejected or still pending.

  4. Release

    Access checked; removal and deletion traceable.

Fictional example: the scanner is unavailable. The file stays pending and no public link is created.

Fictional acceptance-test scenarios

These proposed cases are not client observations. Adapt data, permissions and acceptance criteria to your authorised environment.

Situation to exerciseResult to checkEvidence to retain
A file has an allowed extension but incompatible content.Reject or isolate according to server checks; do not trust only the filename or client-declared type.Validation result and no unauthorised processing or publication.
A large file or archive exceeds limits after decompression.Apply defined quotas and processing limits, with an understandable rejection and released resources.Sizes, duration, triggered limit and processing cleanup.
Two users upload the same filename.Use suitable storage identifiers and check access, replacement and downloads across accounts.Cross-account tests showing no overwrite or improper access.

Reusable worksheet

Complete with your authorised observations. These fields are a working template, not observed results.

FieldInformation to record
ContractFormats, limits and upload rights
StorageIdentifier, location and access
ProcessingTools, isolation and failure behaviour
OutputDecision, download and deletion

Worked example

Illustrative situation

Fictional example: an image has an accepted extension but cannot be decoded.

Decision and expected evidence

It remains isolated, processing returns a recoverable rejection and no public link is issued.

Distinguish the mechanisms

MechanismPurposeCheck or limitation
Browser selectionGuide file choiceCan be bypassed
Server validationCheck the contractNeeds multiple signals
QuarantineAwait a decisionMust block normal reading

Management indicators

IndicatorWhat it measuresFirst action
Explained rejectionsRejected cases with reasonsImprove help and limits
Pending timeTime without final decisionInvestigate stalled processing
Denied accessReads rejected outside scopeReplay cross-account cases

Common pitfalls

  • Can be bypassed
  • Needs multiple signals
  • Must block normal reading

Frequently asked questions

Is a valid extension enough?

No. It proves neither content nor safety for processing and readers.

Is antivirus sufficient?

No. It is one layer alongside format, resource, access and publication controls.

What should pending analysis show?

An explicit pending or failed state. Receipt is not completed publication.

Official references

References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.