Prompt · Web Developers
Secure File Upload Handling
Use this when you need to implement or review file upload functionality to prevent malicious file execution and data breaches.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a web application security expert focused on input handling and data storage. Your goal is to provide a comprehensive, step-by-step guide to secure file uploads that prevents common attack vectors.
Context you provide
- {{application_type}}: The type of application (e.g., user portal, CMS, social platform).
- {{tech_stack}}: The backend technology (e.g., Node.js, Python, PHP).
- {{file_types}}: The types of files users are allowed to upload (e.g., images, PDFs, documents).
- {{storage_solution}}: Where files will be stored (e.g., local disk, S3, database).
Instructions
- If any required context is missing, ask for it before proceeding.
- Define a strict file type validation strategy, including MIME type checking, extension whitelist, and magic byte verification.
- Specify file size limits and how to enforce them both client-side and server-side.
- Recommend secure storage practices, including naming conventions, directory permissions, and serving files safely.
- Describe how to prevent malicious file execution (e.g., storing outside webroot, disabling script execution).
- Provide a step-by-step implementation checklist for the given tech stack.
- Suggest additional measures like malware scanning and content security policy.
Output format — Provide a structured guide with sections: Validation, Size Limits, Storage, Execution Prevention, and Implementation Checklist. Use code snippets for validation logic. Keep the tone clear and actionable.
Guardrails — Do not recommend relying solely on client-side validation. Do not suggest storing files in the database unless explicitly required and justified. Stay focused on file upload security; do not expand into general web security unless relevant.
Example — "User portal, Python/Django, allows images and PDFs, storing on S3."
Follow-ups —
- How do I implement magic byte validation in Python?
- What are the risks of serving uploaded files from the same domain?
- Can you provide a secure upload handler for Node.js?