Practical guides

Prepare useful, controlled website file uploads

An attachment introduces an entire journey: selection, transfer, checking, viewing and deletion. It needs a precise purpose and an identified person able to operate the workflow.

Go to the method

Handle uploads deliberately

Justify the request and show limits

Explain which document is needed and what decision it supports. Consider simple fields if they can achieve the same result. Before selection, state formats, count and size limits and an alternative for unsuitable documents.

Do not require unnecessary personal information. Use synthetic files for acceptance testing. Separate publication approval from receipt: receiving a photograph does not automatically establish permission to publish it.

Check content on the server

OWASP describes complementary controls including allowed formats, type validation, controlled storage names, limits and protected storage. A browser-supplied type alone does not establish file content. Interface checks supplement rather than replace server checks.

Have the software owner review processing. Define handling for files requiring analysis, damaged documents and rejected content. A scan or recognised extension should not be presented as an absolute safety guarantee.

Test the journey to its recipient

Try an allowed file, oversized file, rejected format, accented name and interrupted transfer. Verify that users understand acceptance and required corrections. Do not display success when transfer has not completed.

Check arrival in the correct work queue and access by an authorised person. Also test a different account and a direct download address. The file should remain inaccessible to someone without the service’s required permissions.

Manage storage and deletion

Document storage, access, backups and retention justified by the need and applicable context. Arrange removal of abandoned temporary files as well as processed documents. Notifications can point to secure storage instead of copying every attachment to multiple inboxes.

Repeat boundary tests after form changes and check historical files. Deliver allowed formats, understandable errors, a permissions matrix and an owner-assigned deletion procedure.

Primary documentation : OWASP — File Upload Cheat Sheet.

Acceptance matrix to adapt to your project

These proposed checks use synthetic cases. Decide the required behaviour with the team, record the result and assign unresolved gaps before release.

Test cases, expected outcomes and useful evidence
CaseExpected outcomeEvidence to retain
Allowed fileReceipt and advertised status match the file actually processed.Displayed name, size and confirmed receipt result in the test environment.
Refused type or sizeThe server refuses the file and the form permits correction.Server result and accessible message presented to the person submitting the file.
Unexpected filename charactersThe name does not select a storage destination or command.Original name, assigned storage name and check in an isolated environment.
Interrupted or repeated uploadStatus never claims completion without a complete received file.Network sequence and items actually retained after both controlled attempts.

Frequently asked questions

Are JavaScript file checks sufficient?

No. They help users choose files, but the server must enforce its own rules. Test requests bypassing the usual interface in an authorised environment.

Should every attachment be emailed?

Choose the workflow actually needed. Copying a document into multiple inboxes multiplies storage to manage. Secure folder access may fit better when permissions, tracking and deletion need control.