If I'm not mistaken, to be able to upload a file to S3 you have to use a similar code:
await Storage.put(
e.target.files[0].name,
e.target.files[0],
{ contentType: e.target.files[0].type }
);
Is that way best and secure way? Are you sure?
Indeed, imagine I have the following scenario:
Scenario 1: Files must be uploaded in specific folders
Example:
const user_id = '30e29fc1-4718-4f35-9908-729d63477114';
await Storage.put(
user_id + '/' + e.target.files[0].name,
e.target.files[0],
{ contentType: e.target.files[0].type }
);
Anyone can override this condition by changing the path.
Example:
await Storage.put(
'other_path/' + e.target.files[0].name,
e.target.files[0],
{ contentType: e.target.files[0].type }
);
--> How to force users' files to be uploaded to their own folder?
Scenario 2: Upload the file then save the path in the DynamoDB database
Example:
const { key } = await Storage.put(
e.target.files[0].name,
e.target.files[0],
{ contentType: e.target.files[0].type }
);
const inputPost = {
id: uuid(),
title: 'My title',
content: 'My content',
filePath: key
};
await API.graphql(graphqlOperation(createPost, {input: inputPost}));
Anyone can override this condition by setting the filePath parameter.
Example:
const inputPost = {
id: uuid(),
title: 'My title',
content: 'My content',
filePath: 'perfume.jpg' // the file path of a file that does not belong to me
};
await API.graphql(graphqlOperation(createPost, {input: inputPost}));
--> How to prevent this kind of thing? I show many many video tutorial with that practices. Are there ok?
Best Regard
Thank you
MEMO:
With Firebase, I have the same problem but I can set some Rules:
https://firebase.google.com/docs/storage/security
https://firebase.google.com/docs/reference/security/storage