Insights / Security
A secure file-upload pipeline for web applications
File uploads combine untrusted bytes, storage, access control, and background processing. Validate each boundary instead of trusting the filename or browser.
Kiran Bandarupalli · 2 Oct 2026 · 2 min read

A file upload is not just a form field. It gives an untrusted client a path to consume storage, trigger parsers, and possibly expose content to other users. Security depends on the complete lifecycle from upload through download and deletion.
Authorize and bound the request
Check that the user may upload to the specific record before accepting bytes. Enforce a request-size limit at the proxy and application layers; do not rely only on a browser-side limit. Apply per-user or per-tenant quotas if the product needs them. Stream large files rather than buffering unbounded content in memory.
Do not trust the filename or MIME header
Generate an opaque storage key on the server. Treat the original name as display metadata and escape it wherever it is rendered. Browser-provided content type is a hint, not proof. Inspect file signatures and allow only formats the product needs. For documents that require parsing or conversion, run that work in a constrained worker with time, memory, and filesystem limits.
Store privately by default
Keep uploads outside the public web root or in a private object store. To download, authorize access to the underlying record and issue a short-lived URL or stream the file through a checked endpoint. Set safe content disposition and avoid serving active content from the same origin as the application when possible.
Scan and process safely
Use malware scanning where the threat model and file types warrant it. Treat archive extraction as especially sensitive: defend against path traversal, excessive expansion, and nested archives. Make processing asynchronous for expensive operations, and track a clear state such as received, scanning, available, rejected, or failed.
- Use CSRF protection where cookie authentication is in play.
- Log an opaque file ID and processing outcome, not file contents.
- Define retention and deletion behavior, including backups.
- Test oversized files, spoofed types, duplicate names, and unauthorized downloads.
Security is not achieved by a single antivirus call. It comes from minimizing accepted formats, isolating parsers, enforcing access at every stage, and giving operators a way to investigate failures without exposing private files.