AWS Amplify Upload files | Best Practices

Viewed 143

If I'm not mistaken, to be able to upload a file to S3 you have to use a similar code:

await Storage.put(
    e.target.files[0].name, 
    e.target.files[0], 
    { contentType: e.target.files[0].type }
);

Is that way best and secure way? Are you sure?
Indeed, imagine I have the following scenario:

Scenario 1: Files must be uploaded in specific folders

Example:

const user_id = '30e29fc1-4718-4f35-9908-729d63477114';
await Storage.put(
    user_id + '/' + e.target.files[0].name, 
    e.target.files[0], 
    { contentType: e.target.files[0].type }
);

Anyone can override this condition by changing the path.

Example:

await Storage.put(
    'other_path/' + e.target.files[0].name, 
    e.target.files[0], 
    { contentType: e.target.files[0].type }
);

--> How to force users' files to be uploaded to their own folder?

Scenario 2: Upload the file then save the path in the DynamoDB database

Example:

const { key } = await Storage.put(
    e.target.files[0].name, 
    e.target.files[0], 
    { contentType: e.target.files[0].type }
);

const inputPost = {
    id: uuid(),
    title: 'My title',
    content: 'My content',
    filePath: key
};

await API.graphql(graphqlOperation(createPost, {input: inputPost}));

Anyone can override this condition by setting the filePath parameter.

Example:

const inputPost = {
    id: uuid(),
    title: 'My title',
    content: 'My content',
    filePath: 'perfume.jpg' // the file path of a file that does not belong to me
};
    
await API.graphql(graphqlOperation(createPost, {input: inputPost}));

--> How to prevent this kind of thing? I show many many video tutorial with that practices. Are there ok?

Best Regard

Thank you

MEMO:
With Firebase, I have the same problem but I can set some Rules: https://firebase.google.com/docs/storage/security
https://firebase.google.com/docs/reference/security/storage

0 Answers
Related