跳到主要内容

File Upload Security

Security controls for file uploads in Ever Gauzy.

File Validation

File Type Restrictions

Uploaded files are validated by:

  • MIME type — checked against an allowlist
  • File extension — validated against permitted extensions
  • File size — enforced maximum size limits

Allowed File Types

CategoryExtensions
Images.jpg, .jpeg, .png, .gif, .svg, .webp
Documents.pdf, .doc, .docx, .xls, .xlsx
Archives.zip

Storage Security

MeasureDescription
Tenant isolationFiles scoped to tenant directory
Unique namingFiles renamed to UUIDs
No executionUpload directories have no-exec
Access controlFiles served through API auth

Configuration

VariableDescription
FILE_PROVIDERStorage backend
MAX_FILE_SIZEMaximum upload size (bytes)