I need to validate uploaded files against a whitelist of allowed extensions (e.g. png, .pdf etc) and also check whether the extension corresponds to the real file content in order to avoid malicious files.
For now file upload is done via fileUpload() directive that parses file metadata and provides file content as a Source[ByteString, Any] which then gets streamed directly to S3 storage:
def uploadFileRoute: Route =
path("files") {
post {
(withSizeLimit(documentSizeLimit) & fileUpload("file")) {
case (fileInfo: FileInfo, contentSource: Source[ByteString, Any]) =>
onSuccess(service.uploadToS3(fileInfo, contentSource)) {
completeDefault(_)
}
}
}
}
Is there any good solution on how to perform such validation and to keep using the streaming upload (e.g. not to store the whole file locally ) if possible? Any code examples are appreciated!