All tools / Security & hardening
uploadwarden
Accept browser file uploads without the usual holes.
Buy uploadwarden for $49One payment of $49, plus sales tax where it applies, and every future update. Delivered as a private GitHub repository you're invited to.
See it work
uploadwarden --allow-svg check uploadwarden/samples/*
REFUSE uploadwarden/samples/forged.pdf That file is named .pdf but its contents are not a real PDF. Re-export it and try again.
ACCEPT uploadwarden/samples/guide.pdf -> guide-5a838678.pdf (45 B)
ACCEPT uploadwarden/samples/logo.svg -> logo-e23386f9.svg (113 B)
REFUSE uploadwarden/samples/setup.exe “setup.exe” is not a supported type. You can upload: jpg, pdf, png, svg, webp.
REFUSE uploadwarden/samples/trap.svg That SVG has parts that could run code or load other files, so it cannot be used. Export it again as a plain SVG, or as a PNG.
What it does
An extension allowlist, a magic-number check, an SVG refusal list, generated stored names, size caps, safe download headers, a path-resolve guard and an index that survives redeploys, as a small standard-library Python library and command.
- Allowlist plus magic number
- A page of HTML named forged.pdf is refused.
- SVG refusal list
- Refuses script, event handlers, embedded HTML, entities, external references and CSS escapes, including namespace-prefixed elements. It is a refusal list, not a sanitiser, and is one layer beside the sandboxing header and the image context.
- Generated stored names
- Content-addressed, ASCII-only, never the client's name; a hash collision never overwrites.
- Path-resolve guard
- Rejects traversal, symlinks that leave the folder, colons and Windows device names.
- Safe download headers
- Attachment by default, nosniff, an explicit type and a sandboxing CSP for SVG.
- An index that survives
- Atomic writes and a cross-process lock beside the bytes, in the root you give.
What you get
uploadwarden 1.0.2: the Python library and the uploadwarden command (check, add, list, delete, headers), sample files, a WSGI example and the full test suite, with 224 automated tests.
A commercial license. Use it and change it in your own projects and your clients' projects. Don't share or resell the source. Read the license.
Every update. New versions land in the same repository; git pull to get them.
Requirements
Python 3.10 or newer. Python 3.10 or newer, no third-party packages. There is no virus scan, sign-in or rate limiting.
How buying works
- Enter your GitHub username. You'll see the account before you pay, so you can check it's yours.
- Pay $49, plus any sales tax shown at checkout, on Stripe's checkout page.
- Accept the invitation GitHub emails you. Signed in as that account, you'll also find it at
github.com/dominares-tools/uploadwarden/invitations. Invitations expire after 7 days; you can get a new one any time. - Clone and install:
git clone https://github.com/dominares-tools/uploadwarden.gitPrivate repo: sign in to GitHub on this computer first. Run
gh auth loginand choose HTTPS, or give git a personal access token when it asks for a password. To use an SSH key instead, clonegit@github.com:dominares-tools/uploadwarden.git.python3 -m venv .venv && . .venv/bin/activate pip install ./uploadwarden
Questions
Do I need GitHub?
Yes. Access is a read-only invitation to a private repository, sent to the GitHub account you choose.
Can I get a refund?
Yes, within 14 days, no questions asked. Access ends when the refund goes through. Refund policy.
Who takes the payment?
Payments are handled by Stripe, which works out sales tax. Your receipt and card statement show Link (LINK.COM*), Stripe's checkout service.
Something wrong?
Email support@dominares.org. Every buyer of a tool shares its repository, so support happens by email rather than in GitHub issues.