TechnicalCollectible prompt
Secure file uploads with access rules and expiring links
Add file uploads to {{page_or_feature}} in my {{tech_stack}} app. The roles are {{user_roles}}. Read the existing code, then show me a short plan, including who can upload, view, replace and delete, before changing anything.
Storage and access:
- A private bucket; no public URLs for private files
- Files stored under the owner's user or team ID, with storage and database access rules enforcing the plan
- Downloads via signed links that expire within 15 minutes, issued by the server after a permission check
- A files table with owner, name, size and type; deleting a row deletes the stored file too
Validation, on the server:
- An allowlist of file types, checked by the file's contents, not just its extension
- A size limit of 25 MB unless I say otherwise, plus a total per user
- Files renamed to random IDs, keeping the cleaned original name in the table
- Location data stripped from photos
Upload experience:
- Drag and drop plus a regular button that works by keyboard
- Progress, cancel and retry for each file, with plain-language errors
- Large files go straight to storage via a signed upload link
Prove that one user can't reach another user's files, even by guessing a path.
When you're done, list the files changed, how to test the access rules, and anything you assumed.
Technicalnvoka.com/library/nvoka-secure-file-uploads-with-access-rulesScan to open
Technical
Secure file uploads with access rules and expiring links
Add uploads that check type and size, keep files private and let only the right people open them.
Curated by Nvoka
Claude CodeCodexCursorLovable
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 3 filledYour prompt
Add file uploads to {{page_or_feature}} in my {{tech_stack}} app. The roles are {{user_roles}}. Read the existing code, then show me a short plan, including who can upload, view, replace and delete, before changing anything.
Storage and access:
- A private bucket; no public URLs for private files
- Files stored under the owner's user or team ID, with storage and database access rules enforcing the plan
- Downloads via signed links that expire within 15 minutes, issued by the server after a permission check
- A files table with owner, name, size and type; deleting a row deletes the stored file too
Validation, on the server:
- An allowlist of file types, checked by the file's contents, not just its extension
- A size limit of 25 MB unless I say otherwise, plus a total per user
- Files renamed to random IDs, keeping the cleaned original name in the table
- Location data stripped from photos
Upload experience:
- Drag and drop plus a regular button that works by keyboard
- Progress, cancel and retry for each file, with plain-language errors
- Large files go straight to storage via a signed upload link
Prove that one user can't reach another user's files, even by guessing a path.
When you're done, list the files changed, how to test the access rules, and anything you assumed.