File Uploads with Actions
Learn to handle file uploads directly through Server Actions, including secure storage and processing.
File Uploads with Actions is a free Next.js 15 Fullstack (App Router + Server Actions) lesson on CoddyKit — lesson 2 of 3. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Next.js 15 Fullstack (App Router + Server Actions) learning path, one of 3 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Uploading Files with Actions
File uploads are a common feature, allowing users to share images, documents, and more. Traditionally, handling these required complex API routes and separate handlers.
With Next.js Server Actions, handling file uploads becomes much simpler and more integrated directly within your forms, keeping your logic co-located.
Setting Up the File Input
To allow file uploads, you need an HTML form with a specific setup. The <input type="file"> element is essential for selecting files from a user's device.
- Use the
nameattribute to identify the file in your Server Action. - Add
enctype="multipart/form-data"to your<form>tag. This tells the browser to encode the form data, including files, correctly.
<form action="/api/upload" method="POST" enctype="multipart/form-data">
<input type="file" name="myFile" />
<button type="submit">Upload</button>
</form>Capturing Files via FormData
When a form with enctype="multipart/form-data" is submitted to a Server Action, Next.js automatically parses the data into a FormData object.
You can access the uploaded file(s) from this FormData object using its get() method, which returns a standard JavaScript File object.
// app/actions.js
'use server';
export async function uploadFile(formData) {
const file = formData.get('myFile');
if (!file) {
return { error: 'No file uploaded.' };
}
// 'file' is a File object
console.log('File name:', file.name);
console.log('File size:', file.size, 'bytes');
console.log('File type:', file.type);
return { success: true };
}Exploring the File Object
The File object received in your Server Action is a powerful Web API object. It provides key information about the uploaded file:
name: The original filename provided by the user.size: The file size in bytes.type: The MIME type of the file (e.g., "image/jpeg", "application/pdf").arrayBuffer(): An asynchronous method to get the file's content as anArrayBuffer, which is crucial for saving it.
Storing Uploaded Files to Disk
To save the uploaded file permanently, you'll need to extract its content from the File object and write it to a storage location. The arrayBuffer() method helps convert the file into raw binary data.
You can then use Node.js's built-in fs/promises module to write this data to your server's file system.
// app/actions.js (continued)
'use server';
import { writeFile } from 'fs/promises';
import path from 'path';
export async function saveUploadedFile(formData) {
const file = formData.get('myFile');
if (!file || file.size === 0) return { error: 'No file.' };
const buffer = Buffer.from(await file.arrayBuffer());
const filename = Date.now() + '-' + file.name; // Unique filename
const filePath = path.join(process.cwd(), 'public/uploads', filename);
try {
await writeFile(filePath, buffer);
console.log('File saved to:', filePath);
return { success: true, filename };
} catch (error) {
console.error('Error saving file:', error);
return { error: 'Failed to save file.' };
}
}Validating File Uploads
It's crucial to validate uploaded files on the server-side to prevent security vulnerabilities and ensure data integrity. Always check:
- File Type: Ensure the file's MIME type is among your allowed types (e.g., only images, not executable files).
- File Size: Limit the maximum size to prevent denial-of-service attacks or excessive storage usage.
Client-side validation is helpful for user experience but can be bypassed, so server-side checks are mandatory.
Implementing Server-Side Validation
Here's how you can add basic type and size validation to your Server Action before saving the file. This makes your upload process much more robust and secure.
// app/actions.js (validation added)
'use server';
import { writeFile } from 'fs/promises';
import path from 'path';
const MAX_FILE_SIZE = 1024 * 1024 * 5; // 5MB
const ALLOWED_TYPES = ['image/jpeg', 'image/png', 'application/pdf'];
export async function validateAndSaveFile(formData) {
const file = formData.get('myFile');
if (!file || file.size === 0) return { error: 'No file.' };
if (file.size > MAX_FILE_SIZE) {
return { error: 'File too large (max 5MB).' };
}
if (!ALLOWED_TYPES.includes(file.type)) {
return { error: 'Invalid file type.' };
}
const buffer = Buffer.from(await file.arrayBuffer());
const filename = Date.now() + '-' + file.name;
const filePath = path.join(process.cwd(), 'public/uploads', filename);
await writeFile(filePath, buffer);
return { success: true, filename };
}Handling Multiple File Uploads
To allow users to upload multiple files at once, simply add the multiple attribute to your <input type="file"> tag.
On the server, formData.getAll('myFiles') will return an array of File objects, allowing you to iterate and process each one individually.
// HTML for multiple files:
<form action="/api/upload" method="POST" enctype="multipart/form-data">
<input type="file" name="myFiles" multiple />
<button type="submit">Upload</button>
</form>
// Server Action for multiple files:
'use server';
export async function uploadMultipleFiles(formData) {
const files = formData.getAll('myFiles');
if (!files || files.length === 0) return { error: 'No files.' };
const uploadedNames = [];
for (const file of files) {
// Perform validation and saving for each file
console.log('Processing file:', file.name);
uploadedNames.push(file.name);
}
return { success: true, uploadedNames };
}Beyond Local Storage
While saving files locally is suitable for development and small projects, production applications often use cloud storage solutions for scalability, reliability, and security.
Popular options include AWS S3, Google Cloud Storage, and Cloudinary. Server Actions can integrate directly with these services by sending the file's ArrayBuffer to their respective SDKs, providing robust storage capabilities.
File Upload Quiz
Which of the following HTML attributes is absolutely essential for a basic form to correctly send file data to a Next.js Server Action?
Recap & Next Steps
You've learned how to handle file uploads using Next.js Server Actions!
- Set up HTML forms with
enctype="multipart/form-data"and<input type="file">. - Access uploaded files as
Fileobjects from theFormDataobject in your Server Actions. - Save files to disk using Node.js
fs/promisesby converting theFileobject's content viaBuffer.from(await file.arrayBuffer()). - Implement crucial server-side validation for file types and sizes to enhance security.
- Handle multiple file uploads by adding the
multipleattribute to the input and usingformData.getAll().
Next, explore how to provide optimistic UI updates for a smoother user experience after an action!
Frequently asked questions
Is the “File Uploads with Actions” lesson free?
Yes — the full text of “File Uploads with Actions” is free to read here on the web, and the Next.js 15 Fullstack (App Router + Server Actions) course includes 3 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Next.js 15 Fullstack (App Router + Server Actions) course, upgrade to CoddyKit PRO.
What will I learn in “File Uploads with Actions”?
Learn to handle file uploads directly through Server Actions, including secure storage and processing. You practise Next.js 15 Fullstack (App Router + Server Actions) with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Next.js 15 Fullstack (App Router + Server Actions)?
No prior experience is required. Next.js 15 Fullstack (App Router + Server Actions) on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 3, so you can start here or from the beginning and move at your own pace.
How long does the “File Uploads with Actions” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Next.js 15 Fullstack (App Router + Server Actions) lesson?
Yes. Every Next.js 15 Fullstack (App Router + Server Actions) lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Optimistic UI Updates
- File Uploads with Actions
- Validation & Error Handling in Server Actions