Static Files and Uploads

Static Files, Templates and File Uploads

An API that only speaks JSON is rare in practice. Sooner or later the same Express 24,430 process has to hand a browser a stylesheet, render an HTML page, or accept a cover image a user picked from disk. Express covers the first two out of the box: express.static maps a URL prefix onto a directory, and the view layer — app.set('view engine') plus res.render — turns a template and an object into HTML. Uploads need one package, multer 12,087 .

Security runs through all three. A static directory is a promise that only those files are public. A template that interpolates user text without escaping is a stored cross-site-scripting bug. An upload endpoint without a size limit invites disk exhaustion; one that trusts the client's filename invites path traversal.

HTML forms, the multipart/form-data encoding and the caching headers are Front-End Web Development material; Node's streams are Buffers and Streams and res.sendFile is Redirects and Downloads. What follows stays on the server side of the wire.

Subsections