Urgent.News

What's breaking now, across thousands of outlets.

Tech

Image Upload Gatekeeping: 4 Metadata Checks for Early Express Rejection

Short answer: inspect the upload stream before durable storage, reject on byte count first, then parse trusted image metadata and enforce pixel limits. In a marketplace, that small gate catches oversized listings before moderation workers and object storage have to touch them. Gate What it proves Action Declared length A client-side hint only Never trust it alone Received bytes Transport size…

The recommended approach for an early rejection gate in an image upload system is to inspect the data stream before persisting it. Reject the request if the byte count exceeds a predetermined limit, then parse trusted image metadata to enforce pixel size restrictions. Implementing this gate before storing the file or enqueuing a moderation job can prevent oversized listings from consuming resources.

The gate should first count the bytes as they arrive, discarding the request and returning a 413 (Payload Too Large) error if the limit is exceeded. This byte count should be performed independently of any Content-Length header, as forged headers are not uncommon. After hitting the byte cap, the file signature should be verified. The filename extension and MIME header provide the client's claimed image type, but the actual bytes must be parsed to confirm the format.

A separate image parser can extract dimensions without fully decoding the pixel data, isolating metadata inspection from more resource-intensive operations like thumbnail generation. This separation is crucial for security and auditability. The gate should record the observed format and dimensions, even if the moderation queue experiences delays, allowing operators to distinguish between policy and parser-related rejections.

A TypeScript example is provided, utilizing an express server and image-size library. It maintains transport and metadata decisions separately. The gate checks the incoming data against maximum byte and pixel limits, returning appropriate error responses. By rejecting images at this early stage, the system can reduce moderation workload and protect resources.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Monday 28 September →