Field Manual PHP / Laravel reference
← Security

File upload security

Uploads introduce untrusted bytes, names, and storage paths.

What it is

Uploads introduce untrusted bytes, names, and storage paths.

When to use it

Validate size/type and store privately with generated names.

Syntax

// Bad: trust original filename and extension
// Good:
$request->validate(["document" => "required|file|mimes:pdf|max:2048"]);

Example

$file = $request->file("document");
$path = $file->store("documents", "local");
// Persist generated path and original name as metadata only.
// Authorize downloads; serve as attachment from private storage.
// Quarantine/scan files where required before release.

Common mistakes

MIME validation is not malware scanning; never make uploaded PHP executable; original filenames can contain hostile characters.

Related topics

10. Identify security requirements15. Review security