Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Uploads, Storage and Controlled Access
Python & Django

Uploads, Storage and Controlled Access

Handling files and documents in Django securely: storage outside the code directory, private files served through permission checks, uploads and backups.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Store outside the code directory or in object storage, serve private files through a view that checks permissions, and never build a path from user input.

Never serve private files directly

A file at a guessable URL is not access controlled. Private documents must be served through a view that authenticates, authorises and then streams the file.

The most common document security failure in business applications is a PDF at a predictable URL that nobody checks permissions for.

Upload handling

  1. Store outside the code directory, or in object storage
  2. Validate content, not the extension or the reported type
  3. Generate your own filename, never using the uploaded one
  4. Limit size and type, enforced server-side
  5. Never build a path from anything a user supplied

Object storage once you scale

OptionSuits
Local disk outside the code directorySingle server, modest volume
Object storageMultiple servers, redundancy, any real volume
DatabaseRarely — small files only, complicates backups

Object storage with signed URLs handles both the access control and the serving efficiently, and it removes files from your backup burden.

Generated documents

  • Generate in the background, not during a request
  • Store what was produced rather than regenerating
  • Record which template version produced it
  • Never overwrite a document that has been sent
  • Retain according to your records policy

An invoice regenerated next year may differ, because the template or a product name changed. The document you sent is the record.

Include files in backups

Uploaded files are frequently outside the database backup and therefore outside the backup entirely. A restore that recovers records and not documents is a partial restore.

Check specifically, and test restoring both together.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

How do we serve private files?

A view that checks permissions then streams the file, or object storage with short-lived signed URLs.

Should uploads be scanned?

Where files will be shared with other users, yes. For files only the uploader retrieves, the risk is lower.

What about large uploads?

Direct to object storage with signed URLs, bypassing the application. That avoids memory and timeout problems.

Are uploaded files in our backups?

Check specifically. They are commonly missed and it is discovered during a restore.

Keep reading

More on Python & Django

Python & Django

An API Other Systems Can Depend On

Designing a Python API service others can depend on: validation at the boundary, consistent errors and status codes, early versioning and documentation.

Python & Django

Moving and Transforming Data Reliably

Building data pipelines in Python that cope with malformed input: restartable stages, quarantining failures, reconciling counts and alerting on absence.

Start here

Documents at guessable URLs?

That is not access control. Serving through a permission-checking view is a contained fix.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →