Threat-model the upload before writing the handler
Apply STRIDE categories to identify controls for a user-upload flow.
Design a profile-photo upload that accepts user files, stores them, and renders them in account pages. STRIDE: check spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege across trust boundaries. The common shortcut is to validate only the file extension and then store a public URL, which misses identity, access, audit, and resource-exhaustion risks. Draw the data flow Browser selects file -> API validates -> object storage saves -> database stores reference -> image renders through CDN. Threats appear at boundaries, so the flow must show where data crosses trust zones. Run STRIDE prompts Ask one question…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in