Resources · 95
File uploads: validate before processing or publishing
Control format, resources, access and states from receipt to download.
· 3 min
What this guide helps achieve
- Define needs and limits
- Validate on the server
- Isolate received files
- Bound processing
- Control release and removal
Quick check
- Is a valid extension enough?
- Is antivirus sufficient?
- What should pending analysis show?
Step-by-step method
- 01
Define needs and limits
Allow only formats needed for the task. Specify size, dimensions, duration, page or file count as appropriate. Bound processing time and memory as well as transfer size.
Output: Format and resource contract.
- 02
Validate on the server
Browser accept hints assist selection but do not secure receipt. Check extension, declared type and content using maintained tools. No single signal establishes file safety.
Output: Server-validation tests.
- 03
Isolate received files
Assign server identifiers rather than constructing paths from user filenames. Keep files outside the public document root with restricted access. Show a pending state until checks finish.
Output: Isolated storage and explicit states.
- 04
Bound processing
Scan, convert or reconstruct permitted formats with suitable limits and isolation. Do not send sensitive documents to a public scanner without an explicit data-sharing decision. Scanner failure does not imply approval.
Output: Bounded processing and failure scenario.
- 05
Control release and removal
Check access rights on every read. Trace rejection, approval, publication and deletion. Test limits, interruption, corrupt files and recovery without exposing quarantined content.
Output: Access and removal acceptance tests.
Receipt is not publication
Each step produces a distinct state. Failure leaves the file isolated.
Receipt
Server identifier, permissions and limits.
Validation
Format, content and resources checked.
Decision
Approved, rejected or still pending.
Release
Access checked; removal and deletion traceable.
Fictional example: the scanner is unavailable. The file stays pending and no public link is created.
Fictional acceptance-test scenarios
These proposed cases are not client observations. Adapt data, permissions and acceptance criteria to your authorised environment.
| Situation to exercise | Result to check | Evidence to retain |
|---|---|---|
| A file has an allowed extension but incompatible content. | Reject or isolate according to server checks; do not trust only the filename or client-declared type. | Validation result and no unauthorised processing or publication. |
| A large file or archive exceeds limits after decompression. | Apply defined quotas and processing limits, with an understandable rejection and released resources. | Sizes, duration, triggered limit and processing cleanup. |
| Two users upload the same filename. | Use suitable storage identifiers and check access, replacement and downloads across accounts. | Cross-account tests showing no overwrite or improper access. |
Reusable worksheet
Complete with your authorised observations. These fields are a working template, not observed results.
| Field | Information to record |
|---|---|
| Contract | Formats, limits and upload rights |
| Storage | Identifier, location and access |
| Processing | Tools, isolation and failure behaviour |
| Output | Decision, download and deletion |
Worked example
Illustrative situation
Fictional example: an image has an accepted extension but cannot be decoded.
Decision and expected evidence
It remains isolated, processing returns a recoverable rejection and no public link is issued.
Distinguish the mechanisms
| Mechanism | Purpose | Check or limitation |
|---|---|---|
| Browser selection | Guide file choice | Can be bypassed |
| Server validation | Check the contract | Needs multiple signals |
| Quarantine | Await a decision | Must block normal reading |
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Explained rejections | Rejected cases with reasons | Improve help and limits |
| Pending time | Time without final decision | Investigate stalled processing |
| Denied access | Reads rejected outside scope | Replay cross-account cases |
Common pitfalls
- Can be bypassed
- Needs multiple signals
- Must block normal reading
Frequently asked questions
Is a valid extension enough?
No. It proves neither content nor safety for processing and readers.
Is antivirus sufficient?
No. It is one layer alongside format, resource, access and publication controls.
What should pending analysis show?
An explicit pending or failed state. Receipt is not completed publication.
Official references
References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.






