Laravel MySQL

Secure File Uploads in Laravel

Check file types and sizes, store them in the right place, and avoid the common pitfalls.

C Codesakura 2分 コメント0件

目次

File uploads are a frequent entry point for security problems. Three things must be guarded: the file type, its size, and where it is stored.

Validate type and size

$request->validate([
  'document' => ['required', 'file', 'mimes:pdf,zip', 'max:5120'],
]);

Store outside the public folder

Files that should not be open to everyone go on a private disk, and are handed out by a controller that checks permissions.

$path = $request->file('document')->store('documents');

return Storage::download($path);

Never trust the file name from the user

Let Laravel generate a random name. Keep the original name in the database just for display.

共有 X Facebook WhatsApp Telegram

コメント0件

コメントするにはログインしてください。 ログイン

関連チュートリアル

Laravel

Building a REST API with Laravel from Scratch

2分 シリーズ · 第3回(全3回)

Laravel

Getting to Know Routing and Controllers in Laravel

2分 シリーズ · 第2回(全3回)

Laravel

Setting Up Your First Laravel Project

1分 シリーズ · 第1回(全3回)