WeAreDevelopers LIVE Mar 19, 2024

Full Spectrum File Uploads

Austin Gil

Are your file uploads vulnerable to memory exhaustion and payload spoofing? Move beyond basic HTML forms. Build secure, scalable pipelines using S3 storage and asynchronous malware scanning.

Pause
Mute Enter Fullscreen
#1 about 4 min

Native HTML and HTTP fundamentals for file uploads

Properly configuring HTTP post requests and multipart form data allows websites to send files natively without relying on scripts.

#2 about 5 min

Enhancing file upload user experience using vanilla JavaScript

Intercepting form submissions with JavaScript prevents disruptive page reloads while preserving progressive enhancement and accessibility fallbacks.

#3 about 5 min

Receiving and processing streaming file uploads in Node.js

Handling raw byte buffers manually exhausts server memory quickly, making streaming libraries essential for safely processing heavy uploads.

#4 about 9 min

Scaling persistent storage with S3 compatible object storage

Migrating from constrained local disks to dedicated object storage via signed URLs or proxy streams heavily reduces infrastructure costs.

#5 about 4 min

Decreasing global file latency using content delivery networks

Caching uploaded assets at the network edge avoids localized latency issues when serving media to a globally distributed audience.

#6 about 4 min

Securing uploads through filename sanitization and extension validation

Implementing basic validations for file names, maximum sizes, and content types mitigates rudimentary application vulnerabilities and reduces storage waste.

#7 about 7 min

Architecting asynchronous malware scanning for uploaded file contents

Decoupling malware scans into background database jobs prevents slow request cycles while actively protecting applications from malicious user payloads.

Matching moments

1:33 min

Scanning secure file uploads to prevent malware payloads

Chris Heilmann +3 · LIVE

5:03 min

Securing file upload features against path traversal

Sebastian Leuer Sebastian Leuer · WWC 2024

34 sec

Handling binary file downloads through appropriate architectural layers

Gregor Bauer Gregor Bauer · WWC 2024

2:39 min

Validating untrusted storage uploads with serverless cloud functions

Reinhard Kugler · LIVE

3:07 min

Managing heavy JavaScript and CSS resource payloads

Shem Magnezi Shem Magnezi · WWC 2025

3:23 min

Answering audience questions on application testing and browser adoption

Rowdy Rabouw Rowdy Rabouw · WWC 2021

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

From Cloud Native to Multi-Cloud Native: Write Once, Deploy Anywhere

Sandeep Pal

Principal Member of Technical Staff at Salesforce

Sandeep Pal
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova