Skip to content

Feature/secure upload and helper#109

Merged
benkhalife merged 5 commits into
masterfrom
feature/secure-upload-and-helper
Jun 18, 2026
Merged

Feature/secure upload and helper#109
benkhalife merged 5 commits into
masterfrom
feature/secure-upload-and-helper

Conversation

@benkhalife

Copy link
Copy Markdown
Member

No description provided.

…ME data

Hand-curated extension→MIME map, dangerous-extension blacklist, and category
groupings (image, video, audio, pdf, document, archive) shared by Upload and
UploadHelper.
…sanitization

Add an extension↔MIME consistency check (anti-spoofing), a dangerous-extension
blacklist with explicit opt-out, an empty-file guard, and stronger filename
sanitization (null bytes, control chars, leading/trailing dots, double-extension
collapse). Extract the upload check into a protected isUploadedFile() seam for
testability without changing production behaviour.
…ad types

Pre-configured Upload instances per category (image, video, audio, pdf,
document, archive) with sensible size caps and security flags on by default.
SVG is excluded from image(). All defaults remain overridable via the fluent API.
Cover construction, metadata, validation, size/extension/MIME rules, the
dangerous-extension blacklist, anti-spoofing consistency checks, and filename
sanitization. Uses a local UploadStub that overrides only isUploadedFile().
Verify each factory wires the correct extension list, default size cap, and
security flags, that SVG is excluded from images, and that defaults stay
overridable.
@benkhalife
benkhalife merged commit 3017268 into master Jun 18, 2026
1 check passed
@benkhalife
benkhalife deleted the feature/secure-upload-and-helper branch June 21, 2026 12:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant