# Nestjs File Uploads

> Validate and stream file uploads securely with Validation and S3 streaming in NestJS. Use when implementing secure file uploads, validation, or S3 streaming in NestJS.

- Skill: `filippodesilva/nestjs-file-uploads` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add filippodesilva/nestjs-file-uploads`
- Raw SKILL.md: https://api.skillmd.com/api/skills/filippodesilva/nestjs-file-uploads/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- License: MIT
- Author: FilippoDeSilva (https://skillmd.com/u/filippodesilva)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/filippodesilva/nestjs-file-uploads

---

# File Upload Patterns

## **Priority: P0 (FOUNDATIONAL)**

- **Magic Bytes**: NEVER trust `content-type` header or file extension.
 - **Tool**: Use `file-type` or `mmmagic` to verify actual buffer signature.
- **Limits**: Set strict `limits: { fileSize: 5000000 }` (5MB) in Multer config to prevent DoS.

## Streaming (Scalability)

- **Memory Warning**: Default Multer `MemoryStorage` crashes servers with large files.
- **Pattern**: Use **Streaming** for any file > 10MB.
 - **Library**: `multer-s3` (direct upload to bucket) or `busboy` (raw stream processing).
 - **Architecture**:
 1. Client requests Signed URL from API.
 2. Client uploads directly to S3/GCS (Bypassing API server completely).
 3. **Pro Tip**: Only approach to scale file uploads infinitely.

## Processing

- **Async**: Don't process images/videos in HTTP Request.
- **Flow**:
 1. Upload file.
 2. Push `FileUploadedEvent` to Queue (BullMQ).
 3. Worker downloads, resizes/converts, and re-uploads.

## Anti-Patterns

- **No content-type trust**: Always verify file magic bytes; MIME header can spoofed.
- **No MemoryStorage for large files**: Use streaming or signed URL pattern for files > 10MB.
- **No synchronous file processing**: Offload image/video work to BullMQ workers via FileUploadedEvent.

## References
