ZCore LogoZCore
Api reference

LocalStorageProvider

API reference for LocalStorageProvider with path traversal defense, stream uploading, and validation guards.

LocalStorageProvider implements storage operations targeting the host filesystem. It defends against path traversal attacks by enforcing strict path bounds checks, generates high-entropy collision-free identifiers, resolves web-accessible URL paths dynamically, and evaluates uploaded files through configurable security validators.

Class Definition

from typing import Optional, List
from zcore.storage import LocalStorageProvider, StorageProvider, BaseStorageValidator

class LocalStorageProvider(StorageProvider):
    def __init__(
        self, 
        base_path: str = "./storage", 
        url_prefix: str = "/storage", 
        validators: Optional[List[BaseStorageValidator]] = None
    ) -> None:
        ...

Initialization Parameters

Prop

Type


Methods

upload

Uploads an incoming file to the local directory. Runs configured validators, generates a collision-resistant UUID filename, and asynchronously streams chunks to disk.

async def upload(self, file: UploadFile, folder: str = "") -> str: ...

Prop

Type

upload_stream

Directly streams binary raw chunks from an asynchronous generator to a local file destination.

async def upload_stream(
    self, 
    file_stream: AsyncGenerator[bytes, None], 
    filename: str, 
    folder: str = ""
) -> str: ...

Prop

Type

delete

Securely removes a file from local storage using its physical path or web URL. Asserts that the target path resides within base_path before unlinking to prevent arbitrary file deletion exploits.

async def delete(self, file_path_or_url: str) -> bool: ...

Prop

Type

exists

Verifies the physical presence of an asset within the local storage sandbox using its web URL or relative path.

async def exists(self, file_path_or_url: str) -> bool: ...

Prop

Type

get_url

Resolves the normalized web-accessible URL for a stored asset.

async def get_url(self, file_path_or_url: str) -> str: ...

Prop

Type

Path Traversal Prevention: LocalStorageProvider normalizes paths and validates sandbox boundaries against base_path. Operations attempting directory breakouts (e.g., ../../etc/passwd) are blocked immediately.

On this page