मुख्य सामग्री पर जाएँ

SaaS में secure file uploads: validation, storage और download checklist

Allowlisted formats, size limits, quarantine scan, private storage और tenant-checked downloads से SaaS file-upload flow सुरक्षित करें।

इस मार्गदर्शिका में

SaaS में file-upload feature जोखिम भरा क्यों हो सकता है?

Uploaded file untrusted input है जो storage, parsers, दूसरे users या shared infrastructure को निशाना बना सकती है। Secure design जाँचता है कि कौन upload कर सकता है, feature को किन formats की जरूरत है, file कितनी बड़ी हो सकती है और उसे कैसे store तथा serve किया जाएगा। OWASP कई layers वाले controls सुझाता है क्योंकि filename, extension, MIME type या antivirus scan में से कोई अकेला file सुरक्षित होने का प्रमाण नहीं है।

केवल product को जरूरी formats की अनुमति दें

हर upload feature के लिए छोटी allowlist तय करें और बाकी सब reject करें। Extension जाँचने से पहले filename decode और normalize करें; content type के साथ file signature भी जाँचें क्योंकि browser का MIME header भरोसेमंद नहीं। केवल इसलिए executable या active format स्वीकार न करें कि भविष्य में product उसे support कर सकता है।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

Size, count और processing पर limits रखें

Bytes per file, request में files की संख्या, archive expansion, image dimensions, processing time और concurrent jobs सीमित करें। Edge और application, दोनों पर limit लागू करें ताकि reverse proxy या worker बड़ी या बहुत compressed file से exhaust न हो। साफ error दें और सुरक्षित retry route रखें।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

User filename की जगह generated storage identifier रखें

Request से आए नाम और path को केवल display metadata मानें। Random storage key बनाएँ, path traversal और overwrite रोकें, और length तथा character जाँच के बाद मूल display name अलग रखें। User के नियंत्रित नाम को filesystem path, object key या executable response header न बनाएँ।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload
File-upload threat और control worksheet
Upload use case और allowed typesSize / count / processing capStorage और scan statusTenant download checkOwner / test date
Profile image
Customer document
Bulk archive या export

SaaS product uploaded files को कैसे store और scan करे?

जाँच पूरी होने तक नई files private और quarantine में रखें

Uploads को public web root के बाहर या private object bucket में store करें। Malware scan, content disarm या format-specific validation के समय file को pending रखें। अपेक्षित checks सफल होने पर ही उपलब्ध करें; scan failure या password-protected document को कैसे संभालेंगे, तय करें।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

Format के अनुसार layered scanning अपनाएँ

जहाँ उपयुक्त हो malware detection या sandboxing करें और समर्थित document types के लिए content disarm तथा reconstruction पर विचार करें। Images, PDFs और archives को maintained libraries, isolated workers और resource limits के साथ parse करें। साफ scan एक संकेत है, file के harmless या share करने योग्य होने का प्रमाण नहीं।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

Customer filename और served content को अलग रखें

File लौटाते समय सोचकर content type और सुरक्षित Content-Disposition दें। Untrusted HTML या SVG को मुख्य application origin पर inline render न करें। Public access की जरूरत न हो तो अलग content origin और छोटी अवधि वाला signed download URL अपनाएँ।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

SaaS files का cross-tenant access कैसे रोकें?

हर upload और download को tenant के विरुद्ध authorize करें

Authenticated user का tenant trusted server-side state से निकालें और हर object को read, replace, list या delete करने से पहले ownership या स्पष्ट share grant verify करें। अंदाजा लगाना कठिन object key या छिपे link को authorization न मानें। दो tenants के बीच direct-object access test करें।

Thumbnail, preview और background job पर भी वही जाँच लगाएँ

जब मुख्य object private हो तब derived file मूल data उजागर कर सकती है। Image resizing, OCR, preview generation, exports, backups और deletion tasks में tenant तथा object ownership साथ रखें। Temporary URLs expire हों और उनसे दूसरे tenant की object fetch न हो।

Release से पहले malicious और unusual inputs test करें

Double extension, spoofed content type, path traversal, duplicate filename, बहुत बड़ी image, compressed archive, corrupted document और बिना अनुमति वाली requests test करें। Stored object, browser response headers, scan status और logs जाँचें। सुरक्षित test files isolated environment में चलाएँ।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

SaaS file upload से जुड़े सवाल

क्या file extension जाँचना पर्याप्त है?

नहीं। Extension भ्रामक हो सकती है या सरल जाँच को bypass करने के लिए बनाई जा सकती है। संकरी allowlist, decoded और normalized filename, expected signature, resource limits, private storage और उचित isolation में scan या processing अपनाएँ।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

क्या browser के Content-Type header पर भरोसा कर सकते हैं?

नहीं। यह client देता है और spoof किया जा सकता है। इसे expected extension और file signature से मिलाएँ तथा documented policy के अनुसार mismatch या unsupported format reject करें।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload

क्या uploaded files को उसी database में रखना चाहिए?

यह product और architecture की जरूरतों पर निर्भर है। बड़ी files के लिए object storage आम है, लेकिन वहाँ भी private access, generated keys, encryption, lifecycle rules और tenant-aware authorization चाहिए। अलग storage service अपने-आप data exposure नहीं रोकती।

क्या antivirus scan से downloads सुरक्षित हो जाते हैं?

नहीं। Scan कुछ जोखिम घटाता है पर नए या file-specific खतरे छूट सकते हैं। इसे format limits, private storage, safe parsing, tenant checks, response headers तथा quarantine और suspicious files की प्रक्रिया के साथ इस्तेमाल करें।

इस बिंदु के स्रोत: OWASP Cheat Sheet: file upload