Skip to content
AITroveRead. Build. Understand.
Make this comfortable

HTML file capture: suggest a camera without treating it as permission

Last updated: 1 Oct 20266 min read
tutorial
IntermediateBy AITrove Editorial

The capture attribute can express a preferred camera-facing mode on a file upload control. It cannot guarantee that a camera exists, that a particular picker opens, or that the returned bytes are safe.

Decide from the browser contract

A depot worker photographs a damaged seal at intake. The form asks for an image and suggests the rear camera, while its visible instruction still works if the device offers an ordinary file picker. The selected file remains user-controlled input. The upload handler must authenticate the worker, limit bytes, inspect the decoded image, remove metadata if policy requires it, and associate the result with the correct case. Explain retention before submission; a photograph may contain location or personal details unrelated to the damage. Capture is a preference, not a hidden permission grant or a replacement for a normal upload path.

html
<form action="/intake/I-47/seal-photo" method="post" enctype="multipart/form-data">
  <label for="seal-photo">Damaged seal photo</label>
  <p id="seal-photo-help">Take a photo or choose an existing image. Maximum 6 MB.</p>
  <input id="seal-photo" name="sealPhoto" type="file"
         accept="image/*" capture="environment"
         aria-describedby="seal-photo-help" required>
  <button type="submit">Attach photo</button>
</form>

Cost and verification

The attribute adds no script or network request. Image decoding, malware screening, storage, and retention create the operational cost; the form route shown here requires a real authenticated handler before use. Test rear- and front-camera devices, desktop browsers, denied camera access, picker fallback, and files with misleading extensions. Do not infer image dimensions, MIME validity, or safety from the picker hint. If a photo is optional for a particular case, remove required and explain the alternate evidence path in visible text.

Common Mistakes

  • Do not describe capture as a promise to open the rear camera on every browser.
  • Do not trust accept or the filename as server validation.
  • Do not collect a photo without a clear retention and access rule.

Connected lessons

html
browser-contract
Storage details