Some tricks in Django Upload Files

Some interesting examples on how to handle file uploads using Django:

  • Code snippet posted on Djangosnippets. The file is saved by declaring asave() method in the form class. This method is invoked when callingform.save(), which is standard Django newforms practice. (Note that this snipped uses clean_data. As of Django version 0.96,clean_data has been renamed to cleaned_data, so you will have to change the code or it won’t work)
  • Django image upload and validation. The author uses a model for the file and its related data. The uploaded file is saved by calling thesave_FOO_file method. (This method is automatically provided by Django for fields declared as models.ImageField ormodels.FileField in the model. See the db-api documentation.)
  • Django image upload, form_for_instance and monkey-patching. The example code creates a form class from request.user by callingform_for_instance. The resulting class in then monkey-patched to insert the avatar image validation code. (Although the code is interesting the monkey patch seems unnecessary. I wouldn’t mind inserting the avatar validation method in a UserProfileForm class derived fromform.Forms. The code would be certainly clearer: I think KISS takes precedence over DRY in this case.)

Interesting, there seems to be no easy way of limiting the uploaded file size. The file can be rejected at validation time, but the data would have already been transfered.

A file upload recipe

After reading those posts, I think that a good recipe for handling file uploads in Django would be:

  • Write a django model for the uploaded file and its related data. Using a Django model makes sense, because it is usually necessary for the application to keep track of the uploaded files.
  • Write a subclass of form.Forms and declare a clean_FOO method for each models.FileInput or models.ImageInput fields declared in the model class. These clean_FOO methods are used to validate the uploaded files.
  • use a django view to receive the POST data, or display the form if no data is posted or errors are found.
  • validate the uploaded file or files by triggering the standard django newforms validation mechanism: is_valid().
  • save the file or files getting the data directly from the request.FILESobject, by writing a save() method for the subclassed form or by callingsave_FOO_file for the model instance.

A simpler way to upload a file

The following short Django example uses no data models, does no data validation, and saves the file directly to disk using python standard file functions. It is just a simple test I wrote to get familiar with therequest.FILES object. This is not production code: it could be used to execute an arbitrary script on the server. The directory where the file is to be saved must be writable by the user that is running the Django server script. (The example uses MEDIA_ROOT as defined in settings.py.)

file: views.py

01from django import http
02from django import newforms as forms
03from django.shortcuts import render_to_response
04from djangotest.settings import MEDIA_ROOT</p>
05
06

class SimpleFileForm(forms.Form):

07 file = forms.Field(widget=forms.FileInput, required=False)</p>
08
09

def directupload(request):

10 """
11 Saves the file directly from the request object.
12 Disclaimer: This is code is just an example, and should
13 not be used on a real website. It does not validate
14 file uploaded: it could be used to execute an
15 arbitrary script on the server.
16 """</p>
17
18
template = 'fileupload.html'
19
20if request['method'] == 'POST':
21 if 'file' in request.FILES:
22 file = request.FILES['file']
23
24 # Other data on the request.FILES dictionary:
25 # filesize = len(file['content'])
26 # filetype = file['content-type']
27
28 filename = file['filename']
29
30 fd = open('%s/%s' % (MEDIA_ROOT, filename), 'wb')
31 fd.write(file['content'])
32 fd.close()
33
34 return http.HttpResponseRedirect(' upload_success.html')
35else:
36 # display the form
37 form = SimpleFileForm()
38 return render_to_response(template, {'form': form })
39</code></pre>
40
41

file: fileupload.html

01{% extends "base.html" %}p>
02
03<p>{% block body %}p>
04
05<h1>Upload a fileh1>
06
07<pre><code> <form action="." method="post" enctype="multipart/form-data">
08 {{ form }}
09 <input type="submit" value="Upload" />
10 </form>
11code>pre>
12
13<p>{% endblock %}

No comments:

Post a Comment