Upload validation boundaries
Assess whether uploads are constrained by extension, content signature, storage location, retrieval headers, and authorization. Use tiny inert fixtures and an account you control; never upload executable or active content.
Tags: upload, validation, storage, authorized-testing
Techniques
Type validation
Compare declared content type, filename extension, and actual benign file bytes to identify which signal the service trusts.
hello.txt containing plain UTF-8 textimage.png containing a known-valid 1x1 PNG
Serving boundary
After a permitted upload, inspect download headers, origin, and cache controls. The safe outcome is attachment delivery or a non-executable media context.
Verify Content-Disposition, Content-Type, and X-Content-Type-OptionsUse a unique benign filename for retrieval tracing
Access control
Confirm another controlled account cannot list, fetch, replace, or delete the test upload without permission.
two-account access check on an owned upload IDdelete attempt only where the program permits controlled state changes