ostap

ostap

Is limiting access to user-uploaded static files worth it?

I’m building a file converter website which does not require an account. It stores all conversions in the database and assigns owned conversions to a session as a list of IDs.

I don’t use S3 yet, so all converted files are stored in a priv/static/uploads.

defmodule MyAppWeb do
    def static_paths, do: ~w(uploads

These files are mostly stored temporarily and deleted after 24 hours. But there would be the case when we store them longer if someone makes an account.

Is it acceptable to keep these files publicly exposed? Is it better to somehow authenticate access to these files? If so, is there an easy way to do so with Plug/Phoenix?

Marked As Solved

D4no0

D4no0

You can just use authentication plug for the static files?

The way I did it back in the day is that I would have a dedicated controller that would serve the files based on the authenticated user, as most probably you won’t want authenticated users to see each-other’s files.

Also Liked

ostap

ostap

Thank you! A dedicated controller for serving files seems to be what I want. I can also make it domain-specific so that it fetches the database record and checks the ownership to then decide whether to serve the file.

I now think my file-serving controller could benefit from utilizing Nginx’s X-Accel-Redirect header to send over large files.

garrison

garrison

You could give each file an unguessable “token” and allow download via that token. Depending on your use case this could be handy for allowing a user to send the download link to someone else (or another computer).

:crypto.strong_rand_bytes(32) |> Base.url_encode64(padding: false)

If a logged-in user wants a truly “private” (authenticated) upload then you could make the token optional in the schema (or better, a “visibility” field) and authenticate accordingly.

Last Post!

garrison

garrison

You could give each file an unguessable “token” and allow download via that token. Depending on your use case this could be handy for allowing a user to send the download link to someone else (or another computer).

:crypto.strong_rand_bytes(32) |> Base.url_encode64(padding: false)

If a logged-in user wants a truly “private” (authenticated) upload then you could make the token optional in the schema (or better, a “visibility” field) and authenticate accordingly.

Where Next?

Popular in Questions Top

rms.mrcs
Hi, I need to transform a list of numbers into a map where the keys are the indexes and the values are the original values of the list. ...
New
jononomo
I am trying to figure out how Mix knows whether the environment is test, dev, or prod – where is this set? Thanks.
New
Qqwy
Original source of discussion: This topic on the Pragmatic Programmers’ Functional Web Development with Elixir, OTP, and Phoenix forum. ...
New
Lily
In templates/appointment/index.html.eex: <%= for appointment <- @appointments do %> <tr> <td><%= appoi...
New
WestKeys
Currently suffering from paralysis by [HTTP client] analysis. This is rather unusual in Elixirland as there tends to be consensus on the ...
New
Harrisonl
We have an ECS cluster with 4 services, where each task joins a single cluster, via discovery ECS discovery service. Currently when I de...
New
jason.o
In the code below, if the create action is not set to accept “extra_key” as an input, it errors out with a message shown above. Is there ...
New

Other popular topics Top

electic
Hi, I am new to Elixir. I am trying to use the DateTime component to insert a date into MySQL however the there seems to be no way to fo...
New
stefanchrobot
What’s the safe way to decode a JSON string into a struct? I want to avoid calling String.to_atom. Jason.decode can give me a map with st...
New
Darmani72
If I have a post route which an argument: post /my_post_route/:my_param1, MyController.my_post_handler How would get the post params ...
New
joeerl
Hello again - after a longish gap I’ve decided I really must dig into Elixir and see what’s been happening here - so I have a few questio...
New
gshaw
What is the idiomatic way of matching for not nil in Elixir? E.g., First way: defp halt_if_not_signed_in(conn, signed_in_account) when...
New
AstonJ
Posting this to see if we can make things easier for people to get into Neovim. If you use Neovim and have a favourite distro please let ...
New

We're in Beta

About us Mission Statement