Skip to content

Simple large file uploads via presigned S3 URLs - #210

Merged
mnapoli merged 8 commits into
masterfrom
large-file-uploads
Sep 24, 2026
Merged

mnapoli merged 8 commits into
masterfrom
large-file-uploads

Conversation

@mnapoli

@mnapoli mnapoli commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Lambda limits request bodies to about 6 MB (roughly 4 MB of file once base64-encoded), so large files cannot go through the application.

This PR adds a helper to simplify S3 uploads: the browser asks the app for a presigned S3 URL, uploads the file straight to S3 under a temporary prefix, then sends the S3 key to the app, which validates it and moves the file to its final location.

Usage

Gate::define('uploadFiles', fn (User $user) => true);
import { upload } from 'bref-upload';
const { key } = await upload(file, { progress: (ratio) => console.log(ratio) });
// send `key` to the backend with the rest of the form
$validated = $request->validate([
    'file' => ['required', new UploadedToS3(extensions: ['pdf'], maxSize: 10 * 1024 * 1024)],
]);
Storage::copy($validated['file'], "documents/{$document->id}.pdf");

The bucket needs a lifecycle rule expiring tmp/ and a CORS rule allowing PUT from the app's origin. The Bref docs are updated in a separate PR.

Documentation: brefphp/bref#2181

@mnapoli mnapoli changed the title Simple large file uploads via presigned S3 uploads Simple large file uploads via presigned S3 URLs Sep 22, 2026
…TTP client

The `XSRF-TOKEN` cookie is read first (like axios and Inertia do), the
`<meta name="csrf-token">` tag is the fallback, and the token is only sent
automatically for same-origin requests.

The new `httpClient` option accepts an axios-compatible client, like
`Vapor.store()`, so that Vapor users can keep their configured axios instance.

Claude-Session: https://claude.ai/code/session_013xfi415r8t7YxVptPkiJU4
@mnapoli
mnapoli merged commit 9d219bf into master Sep 24, 2026
6 checks passed
@mnapoli
mnapoli deleted the large-file-uploads branch September 24, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant