GIPL.FileSecurity 1.1.4

dotnet add package GIPL.FileSecurity --version 1.1.4
                    
NuGet\Install-Package GIPL.FileSecurity -Version 1.1.4
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="GIPL.FileSecurity" Version="1.1.4" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="GIPL.FileSecurity" Version="1.1.4" />
                    
Directory.Packages.props
<PackageReference Include="GIPL.FileSecurity" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add GIPL.FileSecurity --version 1.1.4
                    
#r "nuget: GIPL.FileSecurity, 1.1.4"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package GIPL.FileSecurity@1.1.4
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=GIPL.FileSecurity&version=1.1.4
                    
Install as a Cake Addin
#tool nuget:?package=GIPL.FileSecurity&version=1.1.4
                    
Install as a Cake Tool

GIPL.FileSecurity

GIPL.FileSecurity is a .NET library for secure file-upload validation. It validates uploaded files using extension, filename, MIME type, file signatures (magic bytes), file structure, size limits, and stream-based inspection.

The library is designed to help prevent common file-upload security issues such as extension spoofing, MIME-type mismatches, invalid file structures, and unsafe filenames.

Features

  • File extension validation

  • File name validation

  • MIME type validation

  • File signature / magic-byte validation

  • PDF validation

  • DOC / DOCX validation

  • XLS / XLSX validation

  • PPT / PPTX validation

  • Image validation

  • ZIP-based document validation

  • File size validation

  • Stream-based validation

  • Safe file name generation

  • Validation result with error code and message

  • No requirement to save the uploaded file to disk before validation

  • Password-protected files are not supported.

  • JavaScript-based files are not supported.

  • Macro-enabled Office files are not supported.


Supported Frameworks

The package supports:

.NET Framework

  • .NET Framework 4.6.1 and above

.NET

  • .NET 5.0 and above

Installation

Install the NuGet package using Package Manager Console:


Install-Package GIPL.FileSecurity

Or using the .NET CLI:


dotnet add package GIPL.FileSecurity


Required Parameters

The main validation method requires the following parameters:


fileStream

fileName

fileSize

MaxFileSize

AllowedExtensions

FileNamePattern

Parameter Description

| Parameter | Description |

|---|---|

| `fileStream` | Stream containing the uploaded file |

| `fileName` | Original uploaded file name |

| `fileSize` | Uploaded file size in bytes |

| `MaxFileSize` | Maximum allowed file size in MB/KB |

| `AllowedExtensions` | Array of permitted file extensions |

| `FileNamePattern` | Regular expression used to validate the filename |

The validation method is:


FileSecurityValidator.Validate(

    fileStream,

    fileName,

    fileSize,

    MaxFileSize,

    AllowedExtensions,

    FileNamePattern);


Allowed Extensions

Example allowed extensions:


string[] allowedExtensions =

{

    ".pdf",

    ".doc",

    ".docx",

    ".odt",

    ".rtf",

    ".txt",

    ".xls",

    ".xlsx",

    ".ods",

    ".csv",

    ".ppt",

    ".pptx",

    ".odp",

    ".jpg",

    ".jpeg",

    ".png",

    ".gif",

    ".bmp",

    ".tiff",

    ".zip"

};

Extensions should be provided with the leading `.` character.


File Name Pattern

Recommended filename validation pattern:


string fileNamePattern =

    @"^[A-Za-z0-9][A-Za-z0-9 _-]\*\\.[A-Za-z0-9]+$";

This pattern allows filenames such as:


document.pdf

My Document.pdf

invoice_2026.pdf

report-01.xlsx

photo_01.jpg

It rejects filenames containing unsupported characters such as:


../../file.pdf

<script>.pdf

file|name.pdf

file:name.pdf


.NET Framework Example

The following example can be used with .NET Framework 4.6.1 and above, including ASP.NET applications using `HttpPostedFile`.


using System;

using GIPL.FileSecurity;

string[] allowedExtensions =

{

    ".pdf",

    ".doc",

    ".docx",

    ".odt",

    ".rtf",

    ".txt",

    ".xls",

    ".xlsx",

    ".ods",

    ".csv",

    ".ppt",

    ".pptx",

    ".odp",

    ".jpg",

    ".jpeg",

    ".png",

    ".gif",

    ".bmp",

    ".tiff",

    ".zip"

};

string fileNamePattern =

    @"^[A-Za-z0-9][A-Za-z0-9 _-]\*\\.[A-Za-z0-9]+$";

FileValidationResult result = FileSecurityValidator.Validate(

    FileUpload.PostedFile.InputStream,

    FileUpload.FileName,

    FileUpload.PostedFile.ContentLength,

    5,

    allowedExtensions,

    fileNamePattern);

if (!result.IsValid)

{

    string msg = result.Message;

    string errorCode = result.ErrorCode;

    string name = result.FileName;

    return;

}

In this example:


Maximum file size = 5 MB / 0.5m mb

The uploaded file is validated directly from:


FileUpload.PostedFile.InputStream

The file does not need to be saved to disk before validation.


Create a Safe File Name

After successful validation, generate a safe filename using:


string newFileName =

    FileSecurityValidator.GenerateSafeFileName(result.FileName);

Example:


if (result.IsValid)

{

    string newFileName =

        FileSecurityValidator.GenerateSafeFileName(result.FileName);

    // Use newFileName when storing the uploaded file.

}

It is recommended to use the generated safe filename instead of trusting the original client-provided filename for storage.


ASP.NET Core / .NET Example

The following example can be used with .NET 5.0 and above and `IFormFile`.


using System.IO;

using GIPL.FileSecurity;

string[] allowedExtensions =

{

    ".pdf",

    ".doc",

    ".docx",

    ".odt",

    ".rtf",

    ".txt",

    ".xls",

    ".xlsx",

    ".ods",

    ".csv",

    ".ppt",

    ".pptx",

    ".odp",

    ".jpg",

    ".jpeg",

    ".png",

    ".gif",

    ".bmp",

    ".tiff",

    ".zip"

};

string fileNamePattern =

    @"^[A-Za-z0-9][A-Za-z0-9 _-]\*\\.[A-Za-z0-9]+$";

FileValidationResult result;

using (Stream stream = model.File.OpenReadStream())

{

    result = FileSecurityValidator.Validate(

        stream,

        model.File.FileName,

        model.File.Length,

        5,

        allowedExtensions,

        fileNamePattern);

}

if (!result.IsValid)

{

    string msg = result.Message;

    string errorCode = result.ErrorCode;

    string name = result.FileName;

    return;

}

The maximum allowed file size in this example is:


5 MB / 0.5m MB


ASP.NET Core Safe File Name

After successful validation:


string newFileName =

    FileSecurityValidator.GenerateSafeFileName(result.FileName);

Example:


if (result.IsValid)

{

    string newFileName =

        FileSecurityValidator.GenerateSafeFileName(result.FileName);

    // Save the file using newFileName.

}


Complete ASP.NET Core Example


using System.IO;

using GIPL.FileSecurity;

public IActionResult Upload(IFormFile file)

{

    string[] allowedExtensions =

    {

        ".pdf",

        ".doc",

        ".docx",

        ".odt",

        ".rtf",

        ".txt",

        ".xls",

        ".xlsx",

        ".ods",

        ".csv",

        ".ppt",

        ".pptx",

        ".odp",

        ".jpg",

        ".jpeg",

        ".png",

        ".gif",

        ".bmp",

        ".tiff",

        ".zip",

        ".rar"

    };

    string fileNamePattern =

        @"^[A-Za-z0-9][A-Za-z0-9 _-]\*\\.[A-Za-z0-9]+$";

    FileValidationResult result;

    using (Stream stream = file.OpenReadStream())

    {

        result = FileSecurityValidator.Validate(

            stream,

            file.FileName,

            file.Length,

            5,

            allowedExtensions,

            fileNamePattern);

    }

    if (!result.IsValid)

    {

        string message = result.Message;

        string errorCode = result.ErrorCode;

        string fileName = result.FileName;

        return BadRequest(new

        {

            IsValid = false,

            Message = message,

            ErrorCode = errorCode,

            FileName = fileName

        });

    }

    string newFileName =

        FileSecurityValidator.GenerateSafeFileName(result.FileName);

    return Ok(new

    {

        IsValid = true,

        OriginalFileName = result.FileName,

        SafeFileName = newFileName

    });

}


Validation Flow

The recommended upload flow is:


User selects file

       ↓

Open uploaded file stream

       ↓

File size validation

       ↓

File name validation

       ↓

Extension validation

       ↓

MIME type validation

       ↓

File signature / magic-byte validation

       ↓

File-content validation

       ↓

PDF / Office / Image validation

       ↓

Validation successful

       ↓

Generate safe file name

       ↓

Store the file

If any validation step fails, the upload should be rejected.


FileValidationResult

The validation method returns:


FileValidationResult

Example:


FileValidationResult result =

    FileSecurityValidator.Validate(

        fileStream,

        fileName,

        fileSize,

        maxFileSize,

        allowedExtensions,

        fileNamePattern);

You can check the validation status:


if (!result.IsValid)

{

    // File validation failed.

}

Available result information can be used as:


string message = result.Message;

string errorCode = result.ErrorCode;

string fileName = result.FileName;

Example:


if (!result.IsValid)

{

    string msg = result.Message;

    string errorCode = result.ErrorCode;

    string name = result.FileName;

    // Reject upload.

    return;

}


Maximum File Size

The `MaxFileSize` parameter is specified in MB. You can use whole-number or fractional values.

Case 1: Maximum File Size in MB

For example:

| `MaxFileSize` | Maximum File Size |

|---:|---:|

| `1` | 1 MB |

| `2` | 2 MB |

| `3` | 3 MB |

| `5` | 5 MB |

| `10` | 10 MB |

Example — 5 MB limit:

Example:


FileSecurityValidator.Validate(

    fileStream,

    fileName,

    fileSize,

    5, // Maximum file size in 5 MB

    allowedExtensions,

    fileNamePattern);

Case 2: Maximum File Size Using Fractional KB Values

Fractional values let you set limits smaller than 500 KB.

| `MaxFileSize` | Maximum File Size |

|---:|---:|

| `0.5m` | 512 KB |

| `0.1m` | 102.4 KB |

| `0.25m` | 256 KB |

| `0.75m` | 768 KB |

Example — 0.5m MB (512 KB) limit:


FileSecurityValidator.Validate(

    fileStream,

    fileName,

    fileSize,

    0.5m, // Maximum file size: 0.5m MB (512 KB)

    allowedExtensions,

    fileNamePattern);


Stream-Based Validation

The library is designed to validate uploaded files directly from a stream.

.NET Framework


FileUpload.PostedFile.InputStream

ASP.NET Core


model.File.OpenReadStream()

This allows validation before the uploaded content is stored permanently.


Security Recommendation

Do not rely only on the file extension or MIME type supplied by the client.

For secure file uploads, validate multiple properties:

1. File size

2. Filename

3. Extension

4. MIME type

5. File signature / magic bytes

6. Actual file structure

7. Format-specific content

8. Malware scanning where required

9. Generate a safe server-side filename

10. Store uploaded files using controlled server-side paths

Client-provided values such as:


FileName

Content-Type

Extension

should not be treated as proof of the actual file type.


Basic Usage Summary

.NET Framework


FileValidationResult result = FileSecurityValidator.Validate(

    FileUpload.PostedFile.InputStream,

    FileUpload.FileName,

    FileUpload.PostedFile.ContentLength,

    5,

    allowedExtensions,

    fileNamePattern);

if (!result.IsValid)

{

    string msg = result.Message;

    string errorCode = result.ErrorCode;

    string name = result.FileName;

    return;

}

string newFileName =

    FileSecurityValidator.GenerateSafeFileName(result.FileName);

.NET Core / .NET 5+


FileValidationResult result;

using (Stream stream = model.File.OpenReadStream())

{

    result = FileSecurityValidator.Validate(

        stream,

        model.File.FileName,

        model.File.Length,

        5,

        allowedExtensions,

        fileNamePattern);

}

if (!result.IsValid)

{

    string msg = result.Message;

    string errorCode = result.ErrorCode;

    string name = result.FileName;

    return;

}

string newFileName =

    FileSecurityValidator.GenerateSafeFileName(result.FileName);


License

Copyright © GIPL.

Use of this package is subject to the license terms distributed with the package.

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 was computed.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net461 was computed.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 is compatible.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.4 42 9/30/2026
1.1.3 48 9/30/2026
1.1.1 88 9/25/2026
1.0.9 81 9/25/2026
1.0.8 82 9/25/2026
1.0.7 100 9/19/2026
1.0.6 116 9/7/2026
1.0.5 103 9/2/2026
1.0.4 97 9/2/2026
1.0.3 92 9/2/2026
1.0.2 131 9/1/2026
1.0.1 122 9/1/2026