Validate uploads¶
An uploaded file can be checked — and rejected — before it is accepted into the library. This is how you stop users from uploading content that is dangerous when a browser serves it back from your media domain.
Register a validator¶
FINDER_PAYLOAD_VALIDATORS maps a MIME type to the validators that run for it:
FINDER_PAYLOAD_VALIDATORS = [
('image/svg+xml', 'finder.contrib.image.svg.validators.svg_validator'),
('image/svg+xml', 'finder.contrib.image.svg.validators.xml_validator'),
]
Write your own¶
A validator is a callable taking four arguments. Raise to reject the file:
def no_huge_pdfs(file_name, file, owner, mime_type):
if file.size > 50 * 1024 * 1024:
raise ValueError(f'{file_name} is larger than 50 MB')
The value in the settings may be a dotted path, a callable, or a class — a class is instantiated once and its instance called.
Bundled validators¶
finder.contrib.image.svg.validators.svg_validatorRejects an SVG that
py-svg-hushconsiders malicious. Does nothing ifpy-svg-hushis not installed.finder.contrib.image.svg.validators.xml_validatorRejects XML that
defusedxmlrefuses to parse — XXE, entity expansion. Does nothing ifdefusedxmlis not installed.
Warning
FINDER_PAYLOAD_VALIDATORS is empty by default, so a stock installation validates
nothing. SVG files in particular are served from your media domain and executed by the
browser without warning.
Todo
This page describes the finder branch. The feat/validator-compat branch changes it
substantially: validators run before the payload reaches storage and may rewrite it in
place, rejection is signalled with finder.exceptions.FileValidationError, MIME
wildcards work, the setting also accepts a {mime_type: [...]} mapping, and a set of
default validators is applied unless removed with FINDER_REMOVE_PAYLOAD_VALIDATORS.
Rewrite this page and Settings when that branch lands.