GIPL.FileSecurity 1.0.8

There is a newer version of this package available.
See the version list below for details.
dotnet add package GIPL.FileSecurity --version 1.0.8
                    
NuGet\Install-Package GIPL.FileSecurity -Version 1.0.8
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="GIPL.FileSecurity" Version="1.0.8" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="GIPL.FileSecurity" Version="1.0.8" />
                    
Directory.Packages.props
<PackageReference Include="GIPL.FileSecurity" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add GIPL.FileSecurity --version 1.0.8
                    
#r "nuget: GIPL.FileSecurity, 1.0.8"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package GIPL.FileSecurity@1.0.8
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=GIPL.FileSecurity&version=1.0.8
                    
Install as a Cake Addin
#tool nuget:?package=GIPL.FileSecurity&version=1.0.8
                    
Install as a Cake Tool

GIPL.FileSecurity

GIPL.FileSecurity is a .NET library for secure file-upload validation. It validates uploaded files using extension, filename, MIME type, file signatures (magic bytes), file structure, size limits, and stream-based inspection.

The library is designed to help prevent common file-upload security issues such as extension spoofing, MIME-type mismatches, invalid file structures, and unsafe filenames.

Features

  • File extension validation
  • File name validation
  • MIME type validation
  • File signature / magic-byte validation
  • PDF validation
  • DOC / DOCX validation
  • XLS / XLSX validation
  • PPT / PPTX validation
  • Image validation
  • ZIP-based document validation
  • File size validation
  • Stream-based validation
  • Safe file name generation
  • Validation result with error code and message
  • No requirement to save the uploaded file to disk before validation

Supported Frameworks

The package supports:

.NET Framework

  • .NET Framework 4.6.1 and above

.NET

  • .NET 5.0 and above

Installation

Install the NuGet package using Package Manager Console:

Install-Package GIPL.FileSecurity

Or using the .NET CLI:

dotnet add package GIPL.FileSecurity

Required Parameters

The main validation method requires the following parameters:

fileStream
fileName
fileSize
MaxFileSize
AllowedExtensions
FileNamePattern

Parameter Description

Parameter Description
fileStream Stream containing the uploaded file
fileName Original uploaded file name
fileSize Uploaded file size in bytes
MaxFileSize Maximum allowed file size in MB
AllowedExtensions Array of permitted file extensions
FileNamePattern Regular expression used to validate the filename

The validation method is:

FileSecurityValidator.Validate(
    fileStream,
    fileName,
    fileSize,
    MaxFileSize,
    AllowedExtensions,
    FileNamePattern);

Allowed Extensions

Example allowed extensions:

string[] allowedExtensions =
{
    ".pdf",
    ".doc",
    ".docx",
    ".odt",
    ".rtf",
    ".txt",

    ".xls",
    ".xlsx",
    ".ods",
    ".csv",

    ".ppt",
    ".pptx",
    ".odp",

    ".jpg",
    ".jpeg",
    ".png",
    ".gif",
    ".bmp",
    ".tiff",

    ".zip",
    ".rar"
};

Extensions should be provided with the leading . character.


File Name Pattern

Recommended filename validation pattern:

string fileNamePattern =
    @"^[A-Za-z0-9][A-Za-z0-9 _-]*\.[A-Za-z0-9]+$";

This pattern allows filenames such as:

document.pdf
My Document.pdf
invoice_2026.pdf
report-01.xlsx
photo_01.jpg

It rejects filenames containing unsupported characters such as:

../../file.pdf
<script>.pdf
file|name.pdf
file:name.pdf

.NET Framework Example

The following example can be used with .NET Framework 4.6.1 and above, including ASP.NET applications using HttpPostedFile.

using System;
using GIPL.FileSecurity;

string[] allowedExtensions =
{
    ".pdf",
    ".doc",
    ".docx",
    ".odt",
    ".rtf",
    ".txt",

    ".xls",
    ".xlsx",
    ".ods",
    ".csv",

    ".ppt",
    ".pptx",
    ".odp",

    ".jpg",
    ".jpeg",
    ".png",
    ".gif",
    ".bmp",
    ".tiff",

    ".zip",
    ".rar"
};

string fileNamePattern =
    @"^[A-Za-z0-9][A-Za-z0-9 _-]*\.[A-Za-z0-9]+$";

FileValidationResult result = FileSecurityValidator.Validate(
    FileUpload.PostedFile.InputStream,
    FileUpload.FileName,
    FileUpload.PostedFile.ContentLength,
    5,
    allowedExtensions,
    fileNamePattern);

if (!result.IsValid)
{
    string msg = result.Message;
    string errorCode = result.ErrorCode;
    string name = result.FileName;

    return;
}

In this example:

Maximum file size = 5 MB

The uploaded file is validated directly from:

FileUpload.PostedFile.InputStream

The file does not need to be saved to disk before validation.


Create a Safe File Name

After successful validation, generate a safe filename using:

string newFileName =
    FileSecurityValidator.GenerateSafeFileName(result.FileName);

Example:

if (result.IsValid)
{
    string newFileName =
        FileSecurityValidator.GenerateSafeFileName(result.FileName);

    // Use newFileName when storing the uploaded file.
}

It is recommended to use the generated safe filename instead of trusting the original client-provided filename for storage.


ASP.NET Core / .NET Example

The following example can be used with .NET 5.0 and above and IFormFile.

using System.IO;
using GIPL.FileSecurity;

string[] allowedExtensions =
{
    ".pdf",
    ".doc",
    ".docx",
    ".odt",
    ".rtf",
    ".txt",

    ".xls",
    ".xlsx",
    ".ods",
    ".csv",

    ".ppt",
    ".pptx",
    ".odp",

    ".jpg",
    ".jpeg",
    ".png",
    ".gif",
    ".bmp",
    ".tiff",

    ".zip",
    ".rar"
};

string fileNamePattern =
    @"^[A-Za-z0-9][A-Za-z0-9 _-]*\.[A-Za-z0-9]+$";

FileValidationResult result;

using (Stream stream = model.File.OpenReadStream())
{
    result = FileSecurityValidator.Validate(
        stream,
        model.File.FileName,
        model.File.Length,
        5,
        allowedExtensions,
        fileNamePattern);
}

if (!result.IsValid)
{
    string msg = result.Message;
    string errorCode = result.ErrorCode;
    string name = result.FileName;

    return;
}

The maximum allowed file size in this example is:

5 MB

ASP.NET Core Safe File Name

After successful validation:

string newFileName =
    FileSecurityValidator.GenerateSafeFileName(result.FileName);

Example:

if (result.IsValid)
{
    string newFileName =
        FileSecurityValidator.GenerateSafeFileName(result.FileName);

    // Save the file using newFileName.
}

Complete ASP.NET Core Example

using System.IO;
using GIPL.FileSecurity;

public IActionResult Upload(IFormFile file)
{
    string[] allowedExtensions =
    {
        ".pdf",
        ".doc",
        ".docx",
        ".odt",
        ".rtf",
        ".txt",

        ".xls",
        ".xlsx",
        ".ods",
        ".csv",

        ".ppt",
        ".pptx",
        ".odp",

        ".jpg",
        ".jpeg",
        ".png",
        ".gif",
        ".bmp",
        ".tiff",

        ".zip",
        ".rar"
    };

    string fileNamePattern =
        @"^[A-Za-z0-9][A-Za-z0-9 _-]*\.[A-Za-z0-9]+$";

    FileValidationResult result;

    using (Stream stream = file.OpenReadStream())
    {
        result = FileSecurityValidator.Validate(
            stream,
            file.FileName,
            file.Length,
            5,
            allowedExtensions,
            fileNamePattern);
    }

    if (!result.IsValid)
    {
        string message = result.Message;
        string errorCode = result.ErrorCode;
        string fileName = result.FileName;

        return BadRequest(new
        {
            IsValid = false,
            Message = message,
            ErrorCode = errorCode,
            FileName = fileName
        });
    }

    string newFileName =
        FileSecurityValidator.GenerateSafeFileName(result.FileName);

    return Ok(new
    {
        IsValid = true,
        OriginalFileName = result.FileName,
        SafeFileName = newFileName
    });
}

Validation Flow

The recommended upload flow is:

User selects file
       ↓
Open uploaded file stream
       ↓
File size validation
       ↓
File name validation
       ↓
Extension validation
       ↓
MIME type validation
       ↓
File signature / magic-byte validation
       ↓
File-content validation
       ↓
PDF / Office / Image validation
       ↓
Validation successful
       ↓
Generate safe file name
       ↓
Store the file

If any validation step fails, the upload should be rejected.


FileValidationResult

The validation method returns:

FileValidationResult

Example:

FileValidationResult result =
    FileSecurityValidator.Validate(
        fileStream,
        fileName,
        fileSize,
        maxFileSize,
        allowedExtensions,
        fileNamePattern);

You can check the validation status:

if (!result.IsValid)
{
    // File validation failed.
}

Available result information can be used as:

string message = result.Message;
string errorCode = result.ErrorCode;
string fileName = result.FileName;

Example:

if (!result.IsValid)
{
    string msg = result.Message;
    string errorCode = result.ErrorCode;
    string name = result.FileName;

    // Reject upload.
    return;
}

Maximum File Size

The MaxFileSize parameter is specified in MB.

For example:

5

means:

Maximum file size = 5 MB

Example:

FileSecurityValidator.Validate(
    fileStream,
    fileName,
    fileSize,
    5,
    allowedExtensions,
    fileNamePattern);

For a 10 MB limit:

FileSecurityValidator.Validate(
    fileStream,
    fileName,
    fileSize,
    10,
    allowedExtensions,
    fileNamePattern);

Stream-Based Validation

The library is designed to validate uploaded files directly from a stream.

.NET Framework

FileUpload.PostedFile.InputStream

ASP.NET Core

model.File.OpenReadStream()

This allows validation before the uploaded content is stored permanently.


Security Recommendation

Do not rely only on the file extension or MIME type supplied by the client.

For secure file uploads, validate multiple properties:

  1. File size
  2. Filename
  3. Extension
  4. MIME type
  5. File signature / magic bytes
  6. Actual file structure
  7. Format-specific content
  8. Malware scanning where required
  9. Generate a safe server-side filename
  10. Store uploaded files using controlled server-side paths

Client-provided values such as:

FileName
Content-Type
Extension

should not be treated as proof of the actual file type.


Basic Usage Summary

.NET Framework

FileValidationResult result = FileSecurityValidator.Validate(
    FileUpload.PostedFile.InputStream,
    FileUpload.FileName,
    FileUpload.PostedFile.ContentLength,
    5,
    allowedExtensions,
    fileNamePattern);

if (!result.IsValid)
{
    string msg = result.Message;
    string errorCode = result.ErrorCode;
    string name = result.FileName;

    return;
}

string newFileName =
    FileSecurityValidator.GenerateSafeFileName(result.FileName);

.NET Core / .NET 5+

FileValidationResult result;

using (Stream stream = model.File.OpenReadStream())
{
    result = FileSecurityValidator.Validate(
        stream,
        model.File.FileName,
        model.File.Length,
        5,
        allowedExtensions,
        fileNamePattern);
}

if (!result.IsValid)
{
    string msg = result.Message;
    string errorCode = result.ErrorCode;
    string name = result.FileName;

    return;
}

string newFileName =
    FileSecurityValidator.GenerateSafeFileName(result.FileName);

License

Copyright © GIPL.

Use of this package is subject to the license terms distributed with the package.

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 was computed.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net461 was computed.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 is compatible.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.4 42 9/30/2026
1.1.3 48 9/30/2026
1.1.1 88 9/25/2026
1.0.9 81 9/25/2026
1.0.8 82 9/25/2026
1.0.7 100 9/19/2026
1.0.6 116 9/7/2026
1.0.5 103 9/2/2026
1.0.4 97 9/2/2026
1.0.3 92 9/2/2026
1.0.2 131 9/1/2026
1.0.1 122 9/1/2026