Secure File Uploads in Laravel
Check file types and sizes, store them in the right place, and avoid the common pitfalls.
C Codesakura 2分 コメント0件
目次
File uploads are a frequent entry point for security problems. Three things must be guarded: the file type, its size, and where it is stored.
Validate type and size
$request->validate([
'document' => ['required', 'file', 'mimes:pdf,zip', 'max:5120'],
]);Store outside the public folder
Files that should not be open to everyone go on a private disk, and are handed out by a controller that checks permissions.
$path = $request->file('document')->store('documents');
return Storage::download($path);Never trust the file name from the user
Let Laravel generate a random name. Keep the original name in the database just for display.
コメント0件
コメントするにはログインしてください。 ログイン