All packages
Media Library for Laravel
Upload safety
Every name and type that reaches storage is treated as untrusted:
- The mime type is sniffed from the bytes (ext-fileinfo) — never taken from the client, a remote Content-Type header or a disk’s stored metadata.
- The stored name is one safe path segment. Directory parts, separators and control characters are stripped from a client’s name and from usingFileName(), so a name can never reach outside the media’s own directory.
- The extension can’t lie about active content. An extension a web server may execute (.php, .phtml, .shtml, …) is never stored, and one a browser runs (.html, .svg, .js, …) is kept only when the bytes really are that type — a PNG uploaded as x.html is stored as x.png. Truthful or harmless extensions (IMG_0001.JPG, data.csv) are kept.
- addFromUrl() only fetches http/https URLs, honours media.remote.timeout and refuses a body over the size cap. It fetches whatever host it is given: when the URL comes from a user, check the host against an allowlist first — otherwise it can be pointed at your internal network (SSRF).
- A bucket without acceptsMimeTypes() accepts any type, HTML and SVG included. Give every bucket that holds user uploads an allowlist.
Serving is hardened the same way — see URLs, streaming & downloads for which types the streaming route serves inline, and why private media needs a private disk.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.