Ga naar hoofdinhoud

File Upload Security

Security controls for file uploads in Ever Gauzy.

File Validation​

File Type Restrictions​

Uploaded files are validated by:

  • MIME type β€” checked against an allowlist
  • File extension β€” validated against permitted extensions
  • File size β€” enforced maximum size limits

Allowed File Types​

CategoryExtensions
Images.jpg, .jpeg, .png, .gif, .svg, .webp
Documents.pdf, .doc, .docx, .xls, .xlsx
Archives.zip

Storage Security​

MeasureDescription
Tenant isolationFiles scoped to tenant directory
Unique namingFiles renamed to UUIDs
No executionUpload directories have no-exec
Access controlFiles served through API auth

Configuration​

VariableDescription
FILE_PROVIDERStorage backend
MAX_FILE_SIZEMaximum upload size (bytes)