> nestjs-file-uploads
Secure file handling, Validation, and S3 streaming. Use when implementing secure file uploads, validation, or S3 streaming in NestJS. (triggers: **/*.controller.ts, FileInterceptor, Multer, S3, UploadedFile)
curl "https://skillshub.wtf/HoangNguyen0403/agent-skills-standard/nestjs-file-uploads?format=md"File Upload Patterns
Priority: P0 (FOUNDATIONAL)
Secure file upload handling with validation and storage patterns.
- Magic Bytes: NEVER trust
content-typeheader or file extension.- Tool: Use
file-typeormmmagicto verify the actual buffer signature.
- Tool: Use
- Limits: Set strict
limits: { fileSize: 5000000 }(5MB) in Multer config to prevent DoS.
Streaming (Scalability)
- Memory Warning: Default Multer
MemoryStoragecrashes servers with large files. - Pattern: Use Streaming for any file > 10MB.
- Library:
multer-s3(direct upload to bucket) orbusboy(raw stream processing). - Architecture:
- Client requests Signed URL from API.
- Client uploads directly to S3/GCS (Bypassing API server completely).
- Pro Tip: This is the only way to scale file uploads infinitely.
- Library:
Processing
- Async: Don't process images/videos in the HTTP Request.
- Flow:
- Upload file.
- Push
FileUploadedEventto Queue (BullMQ). - Worker downloads, resizes/converts, and re-uploads.
🚫 Anti-Patterns
- Do NOT use standard patterns if specific project rules exist.
- Do NOT ignore error handling or edge cases.
> related_skills --same-repo
> typescript-tooling
Development tools, linting, and build config for TypeScript. Use when configuring ESLint, Prettier, Jest, Vitest, tsconfig, or any TS build tooling. (triggers: tsconfig.json, .eslintrc.*, jest.config.*, package.json, eslint, prettier, jest, vitest, build, compile, lint)
> typescript-security
Secure coding practices for TypeScript. Use when validating input, handling auth tokens, sanitizing data, or managing secrets and sensitive configuration. (triggers: **/*.ts, **/*.tsx, validate, sanitize, xss, injection, auth, password, secret, token)
> typescript-language
Modern TypeScript standards for type safety and maintainability. Use when working with types, interfaces, generics, enums, unions, or tsconfig settings. (triggers: **/*.ts, **/*.tsx, tsconfig.json, type, interface, generic, enum, union, intersection, readonly, const, namespace)
> typescript-best-practices
Idiomatic TypeScript patterns for clean, maintainable code. Use when writing or refactoring TypeScript classes, functions, modules, or async logic. (triggers: **/*.ts, **/*.tsx, class, function, module, import, export, async, promise)