Direct answer
File upload testing reviews how an application accepts, processes, stores, and serves user-controlled files. Use harmless fixtures to assess permitted formats and access rules, then follow the file through preview, download, and background processing.
Define the intended file contract
A profile image, document attachment, and data import have different allowed formats and processing needs. Document file types, size limits, ownership, and whether the content becomes public. This prevents a test from treating a deliberately supported format as a vulnerability.
- Create small harmless examples of each permitted format.
- Identify previewers, converters, scanners, and storage services.
- Agree separate limits for archives or expensive conversion jobs.
Review layered acceptance controls
Filename extensions and client-provided MIME types are insufficient as a single defense. Review type validation, safe naming, size restrictions, processing libraries, and where files are stored. The controls should reflect how the application will later interpret the file.
Reference: OWASP File Upload Cheat Sheet.
Test ownership after upload
Upload a known file as account A, then check its metadata, preview, and download routes from authorized test account B. Include generated thumbnails and extracted text when those are separate resources. Verify that public sharing is an explicit product action rather than a storage default.
- Record whether URLs are public, signed, or authorization-protected.
- Check access again after sharing is removed.
- Keep test filenames and content free of personal information.
Retest cleanup and serving behavior
Deletion can remove a database record while leaving the object or preview available. Check the product's retention policy and observed access after deletion. Review the download response's content type and disposition alongside the upload validation.
Assessment limits
Harmless fixtures can verify selected acceptance and access rules but cannot prove that every parser is safe. Malware samples, executable files, archive bombs, and resource exhaustion checks require a separate approved environment and test plan.
Frequently asked questions
Is checking the file extension enough?
No. Review the actual permitted format, content checks, processing path, storage location, and serving behavior as a set of controls.
Can a successful upload still have access control problems?
Yes. Preview, download, generated artifacts, and shared links can expose the file through separate routes. Assess each relevant resource boundary.
Does deleting an attachment remove every copy?
That depends on the application's storage, cache, and retention design. Verify access to the original object and derived artifacts against the stated deletion policy.
Primary sources and further reading
These guides combine published security guidance with practical assessment planning. Adapt checks to the owner's policy, environment, and authorized scope.