You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在MURA CMS 6中配置指定文件上传MIME类型(ColdFusion 11)

Solution for Restricting File Uploads to PDF/DOC with Strict Validation in MURA CMS 6/ColdFusion 11

Great call prioritizing server-side validation over just client-side JS checks—you’re absolutely right to guard against bypassed client restrictions. Here’s how to implement this properly in your MURA setup:

Step 1: Client-Side File Input Guidance (Optional but User-Friendly)

While server-side validation is non-negotiable, setting the accept attribute on your file input helps guide users upfront. In your MURA user extension form template, update the file field like this:

<input type="file" name="userDocumentUpload" accept=".pdf,.doc">

Remember: This is just a convenience—server-side checks are mandatory to block malicious files.

Step 2: Server-Side Upload with Strict Content Validation

In your ColdFusion handler (where you process the user form submission), use <cffile action="upload"> with the strict attribute enabled to validate file signatures, not just extensions. Here’s the core code:

<cffile 
    action="upload"
    destination="#expandPath('/your/mura/uploads/directory')#"
    name="userDocumentUpload"
    accept="application/pdf,application/msword"
    strict="true"
    result="uploadStatus"
    overwrite="false"
>

Critical Details:

  • strict="true": This forces ColdFusion to check the file’s actual content signature (magic numbers in the file header) instead of relying solely on the file extension. This blocks fake files with renamed extensions entirely.
  • accept: The MIME types listed are the official standards for PDF (application/pdf) and legacy Microsoft Word DOC (application/msword). Avoid using extension-only values here.
  • result: Captures upload metadata and status to handle success/errors gracefully.

Step 3: Tie Upload to MURA User Extension Property

Once the upload succeeds, link the file to the user’s extended attribute. Here’s how to update the MURA user record:

<cfif uploadStatus.fileWasSaved>
    <!--- Fetch the current MURA user object --->
    <cfset targetUser = application.mura.getUser(session.userid)>
    <!--- Store the file path in your custom user extension property --->
    <cfset targetUser.setExtendedAttribute('userDocument', uploadStatus.serverDirectory & '/' & uploadStatus.serverFile)>
    <cfset targetUser.save()>
</cfif>

Step 4: Error Handling for Invalid Uploads

Wrap the upload logic in a try/catch block to handle invalid files or upload failures:

<cftry>
    <!--- Insert the CFFILE upload code here --->
    
    <cfcatch type="any">
        <!--- Show user-friendly error message --->
        <cfset application.mura.addErrorMessage("Invalid file type. Only PDF and DOC files are allowed.")>
        <!--- Redirect back to the user form --->
        <cflocation url="#application.mura.getSelfURL()#" addtoken="false">
    </cfcatch>
</cftry>

Quick Reminders

  • Ensure your upload directory has proper write permissions for the ColdFusion service user.
  • If you ever need to support DOCX files later, use the MIME type application/vnd.openxmlformats-officedocument.wordprocessingml.document.

内容的提问来源于stack exchange,提问作者Charles Robertson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:14:54