Skip to content
AITroveRead. Build. Understand.
Make this comfortable

File Quarantine, Inspection, and Derived Previews

Last updated: 4 Oct 20266 min read
tutorial
IntermediateBy AITrove Editorial

File inspection is the transition from transferred bytes to an asset that the application is willing to handle. A filename extension, browser MIME type, or first-byte signature alone cannot prove that a file is benign or that a parser can process it safely. The server should validate an allowlisted format with a maintained parser, apply resource limits, scan according to product risk, and create derived previews in an isolated worker. The raw upload remains quarantined while that work is pending or failed. A derived thumbnail is a separate object with its own access and retention rules; it must not be published merely because the original upload was accepted.

Working case

Asset 62 claims to be a PDF for case 47. Its first bytes resemble a PDF, but the inspection worker discovers an embedded payload that violates the product’s accepted profile. The worker records rejected with a reason code that can be shown without exposing scanner internals. The file is never linked from case details. A valid image in asset 63 passes format checks and scanning, then a processor writes a small preview with dimensions and checksum. Both original and preview remain tenant-scoped. If preview generation fails, the original can stay pending or available without preview according to an explicit product rule.

Implementation boundary

javascript
function mayExposeAsset(asset) {
  return asset.inspection === "accepted" && asset.requiredOutputsReady;
}
console.log(mayExposeAsset({ inspection: "pending", requiredOutputsReady: true }));
// Output: false

Keep a state machine such as pending, inspecting, accepted, rejected, and processing-failed. Allow only named transitions guarded by asset version so duplicate jobs cannot reverse a final decision. Validate the entire file, not only an extension or a few header bytes. Run parsers and thumbnail builders with CPU, memory, time, output-size, and file-count limits; archives can expand far beyond their compressed size. Keep untrusted files out of application execution paths and avoid sending private evidence to an external scanning service without an approved data contract. Store derived assets under generated keys, record their source version, and require authorization at retrieval.

Cost and boundaries

Inspection is at least O(n) byte work for n-byte input and may include expensive decoding; thumbnails add CPU and output storage. Deep archive scanning can expand work beyond compressed input, so set a decompressed-byte and entry-count budget. Queueing inspection protects request latency but adds a delay before use. Retaining rejected raw bytes creates risk and cost; set a reviewed retention rule for audit and cleanup. Measure pending age, parser timeouts, rejection reasons, worker crashes, preview mismatch, and accepted-to-visible delay. A faster path must not silently bypass checks under load.

Failure trace

A parser worker crashes after marking the asset accepted but before writing the preview, and a retry uses stale state to publish an old thumbnail. Make output idempotent by source version and commit the availability transition only after required artifacts exist. Another processor decompresses an archive without a cap and exhausts memory. Enforce byte and entry budgets in the worker. Test mislabeled types, polyglot files, malformed images, archive expansion, duplicate queue delivery, scanner outage, worker timeout, and a tenant permission change while inspection runs.

Verification

  • Uninspected and rejected bytes have no public retrieval path.
  • Workers are bounded against malformed and expanded content.
  • Derived previews match the inspected source version and access scope.

Practice drill

Upload three files for case 47: a valid image, a mislabeled script, and a compressed file that exceeds the expansion budget. Verify each moves through the expected states and only the valid one receives a derived preview. Retry the worker after a deliberate crash and confirm no duplicate public record or stale output appears. Remove reviewer 29’s case permission during processing, then attempt to read both raw and preview objects. Confirm authorization is checked at retrieval, independent of the earlier upload right.

Decision note

Release files only after a bounded inspection transition, and bind every derivative to the inspected source version.

Common Mistakes

  • Using an extension or MIME header as complete validation.
  • Running parsers without resource limits.
  • Serving a thumbnail through a weaker authorization path.

Connected lessons

File Ingestion and Private Asset Lifecycle; Upload Intake Budgets and Storage Ownership; Resumable Transfer Parts and Integrity; Private Asset Downloads, Revocation, and Expiry; Safe File Upload Pipeline; Background Jobs and the Outbox Boundary; Object-Level Authorization for Reads and Writes.

Apply and check

Build Project: private evidence file lifecycle and review Web Development: file and email delivery decisions quiz.

web-tech
web-development
Storage details