Django file upload
filed in Django, Python on Jul.29, 2007
Some interesting examples on how to handle file uploads using Django:
- Code snippet posted on Djangosnippets. The file is saved by declaring a
save()method in the form class. This method is invoked when callingform.save(), which is standard Django newforms practice. (Note that this snipped usesclean_data. As of Django version 0.96,clean_datahas been renamed tocleaned_data, so you will have to change the code or it won’t work) - Django image upload and validation. The author uses a model for the file and its related data. The uploaded file is saved by calling the
save_FOO_filemethod. (This method is automatically provided by Django for fields declared asmodels.ImageFieldormodels.FileFieldin the model. See the db-api documentation.) - Django image upload, form_for_instance and monkey-patching. The example code creates a form class from
request.userby callingform_for_instance. The resulting class in then monkey-patched to insert the avatar image validation code. (Although the code is interesting the monkey patch seems unnecessary. I wouldn’t mind inserting the avatar validation method in aUserProfileFormclass derived fromform.Forms. The code would be certainly clearer: I think KISS takes precedence over DRY in this case.)
Interesting, there seems to be no easy way of limiting the uploaded file size. The file can be rejected at validation time, but the data would have already been transfered.
A file upload recipe
After reading those posts, I think that a good recipe for handling file uploads in Django would be:
- Write a django model for the uploaded file and its related data. Using a Django model makes sense, because it is usually necessary for the application to keep track of the uploaded files.
- Write a subclass of
form.Formsand declare aclean_FOOmethod for eachmodels.FileInputormodels.ImageInputfields declared in the model class. These clean_FOO methods are used to validate the uploaded files. - use a django view to receive the POST data, or display the form if no data is posted or errors are found.
- validate the uploaded file or files by triggering the standard django newforms validation mechanism:
is_valid(). - save the file or files getting the data directly from the
request.FILESobject, by writing asave()method for the subclassed form or by callingsave_FOO_filefor the model instance.
A simpler way to upload a file
The following short Django example uses no data models, does no data validation, and saves the file directly to disk using python standard file functions. It is just a simple test I wrote to get familiar with the request.FILES object. This is not production code: it could be used to execute an arbitrary script on the server.
The directory where the file is to be saved must be writable by the user that is running the Django server script. (The example uses MEDIA_ROOT as defined in settings.py.)
file: views.py
from django import http
from django import newforms as forms
from django.shortcuts import render_to_response
from djangotest.settings import MEDIA_ROOT</p>
<p>class SimpleFileForm(forms.Form):
file = forms.Field(widget=forms.FileInput, required=False)</p>
<p>def directupload(request):
"""
Saves the file directly from the request object.
Disclaimer: This is code is just an example, and should
not be used on a real website. It does not validate
file uploaded: it could be used to execute an
arbitrary script on the server.
"""</p>
<pre><code>template = 'fileupload.html'
if request['method'] == 'POST':
if 'file' in request.FILES:
file = request.FILES['file']
# Other data on the request.FILES dictionary:
# filesize = len(file['content'])
# filetype = file['content-type']
filename = file['filename']
fd = open('%s/%s' % (MEDIA_ROOT, filename), 'wb')
fd.write(file['content'])
fd.close()
return http.HttpResponseRedirect(' upload_success.html')
else:
# display the form
form = SimpleFileForm()
return render_to_response(template, { 'form': form })
</code></pre>
<p>
file: fileupload.html
{% extends "base.html" %}</p>
<p>{% block body %}</p>
<h1>Upload a file</h1>
<pre><code> <form action="." method="post" enctype="multipart/form-data">
{{ form }}
<input type="submit" value="Upload" />
</form>
</code></pre>
<p>{% endblock %}


