File upload security
Uploads introduce untrusted bytes, names, and storage paths.
What it is
Uploads introduce untrusted bytes, names, and storage paths.
When to use it
Validate size/type and store privately with generated names.
Syntax
// Bad: trust original filename and extension
// Good:
$request->validate(["document" => "required|file|mimes:pdf|max:2048"]);Example
$file = $request->file("document");
$path = $file->store("documents", "local");
// Persist generated path and original name as metadata only.
// Authorize downloads; serve as attachment from private storage.
// Quarantine/scan files where required before release.Common mistakes
MIME validation is not malware scanning; never make uploaded PHP executable; original filenames can contain hostile characters.