Articles in this topic
Guard the signing endpoint with an atomic Redis token bucket in Lua, return 429 with Retry-After and RateLimit headers, and refund tokens for abandoned uploads.
Read article →Reject decompression bombs by screening the ZIP central directory for implausible expansion, then extracting through a shared byte budget that aborts mid-inflate.
Read article →A content-length-range condition is the one byte ceiling a browser cannot lie about. Sign it, order the form correctly, and read the EntityTooLarge XML.
Read article →Enforce storage quotas on direct uploads — reserve bytes atomically before signing, bind the size into the URL, and settle or release on completion.
Read article →Stop scripted upload abuse with Cloudflare Turnstile — verify a token server-side before issuing upload URLs, bind it to the action, and step up by risk.
Read article →