File Uploads at Scale: Presigned URLs, Multipart, Real Type Validation and Safe Serving
A practical guide to getting file uploads out of your backend without opening holes along the way: what a presigned URL actually signs and what it leaves to the client, why a presigned PUT cannot enforce a maximum size while a presigned POST can with content-length-range, multipart uploads with presigned parts, a bounded concurrency pool and per-part retries with exponential backoff and jitter, the CORS configuration with ExposeHeaders ETag without which multipart fails even though every part returns 200, the AbortIncompleteMultipartUpload lifecycle rule that stops orphaned parts from billing for years without ever showing up in a ListObjects, why the ETag is not the MD5 for multipart objects and how to verify integrity properly with additional checksums (CRC64NVME by default since 2025), the pending → uploaded → ready state machine confirmed by s3:ObjectCreated notifications with an idempotent handler rather than by a client call that may never arrive, real type validation from magic bytes reading only the first 8 KB, image rewriting against EXIF metadata and decompression bombs, and serving user content safely (SVG and stored XSS, a separate cookie-less domain, nosniff, Content-Disposition and CSP). With production-ready code in Python, TypeScript, JSON and Bash, eight recurring mistakes, a production checklist and an FAQ.
Verificando acceso...