Upload validation
Does my upload form take what it should and turn the rest away?
The upload-validation preset builds a whole set of real test files for this question in one
command, and a manifest.json beside them saying how your system should react to each
file. Everything below is read from the program, at the defaults of this version.
What does it usually find?
- a limit enforced in the browser and not on the server
- an SVG or an HTML file taken for a picture or for plain text, which is a way to get a script past a form
- a file checked by its extension and never opened, so a PDF named .jpg goes through
- a form that reads the whole body into memory before it looks at how big it is
- an upload named PHOTO.JPG turned away where photo.jpg is taken, or the other way round
- a name with spaces, brackets or characters outside ASCII written to disk unchanged
What is in the set?
At its defaults, as tfg preset show upload-validation reports it:
| Files | 71 |
|---|---|
| Targets in its recipe | 22 |
| Total size | 120 639 488 B |
| Formats | html, jpg, pdf, png, svg, txt |
And what the manifest of that set expects from your system:
| Expected | Meaning | Files |
|---|---|---|
accept | Your system should take the file. | 56 |
reject | Your system should turn the file away. | 10 |
unspecified | It depends on the rules of your system. You decide, then check that what happens is what you meant. | 5 |
What can you change?
| Setting | Takes | Default | What it does |
|---|---|---|---|
--limit |
a size such as 2mb | 10mb |
The size limit your upload form declares. This set takes one step either side of it - for a file at every distance, run the size-boundaries preset. This default is our placeholder, not your system's value. Pass your own. |
--allow |
format ids separated by commas | jpg,png,pdf |
Which types your form is supposed to accept. Each one becomes a real file of that type, and they are the positive control of the whole set. |
--deny |
extensions separated by commas | svg,html,exe,sh |
Which extensions your form is supposed to turn away. An extension this build has no format for still gets a file under that name, holding plain text. |
--far-over |
10x, 2x, off | 2x |
How far past the limit the one big file goes. Turn it off where writing several times the limit is not worth the disk. |
--bulk |
0 - 10000 files | 50 |
How many files the mass upload holds. Nought leaves that group out of the set altogether. |
How do you run it?
See what the set would cost, build it, or take its recipe to edit:
tfg preset show upload-validation
tfg generate --preset upload-validation --limit 10mb --out ./upload-validation
tfg preset eject upload-validation > upload-validation.yaml
Or build on it in a recipe of your own, next to your tests:
version: 1
extends: preset:upload-validation
with:
limit: 10mb