Next.js 15 Fullstack (App Router + Server Actions) · 课时

使用操作上传文件

学习如何直接通过服务器操作处理文件上传,包括安全存储和处理

第 2 / 3 课11 个步骤

使用操作上传文件 是 CoddyKit 上的免费 Next.js 15 Fullstack (App Router + Server Actions) 课时。 这是第 2 节课,共 3 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Next.js 15 Fullstack (App Router + Server Actions) 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Next.js 15 Fullstack (App Router + Server Actions) 课程共包含 3 节课。

本课时的部分内容尚未翻译,以英文显示。

Uploading Files with Actions

File uploads are a common feature, allowing users to share images, documents, and more. Traditionally, handling these required complex API routes and separate handlers.

With Next.js Server Actions, handling file uploads becomes much simpler and more integrated directly within your forms, keeping your logic co-located.

Setting Up the File Input

To allow file uploads, you need an HTML form with a specific setup. The <input type="file"> element is essential for selecting files from a user's device.

  • Use the name attribute to identify the file in your Server Action.
  • Add enctype="multipart/form-data" to your <form> tag. This tells the browser to encode the form data, including files, correctly.
<form action="/api/upload" method="POST" enctype="multipart/form-data">
  <input type="file" name="myFile" />
  <button type="submit">Upload</button>
</form>

Capturing Files via FormData

When a form with enctype="multipart/form-data" is submitted to a Server Action, Next.js automatically parses the data into a FormData object.

You can access the uploaded file(s) from this FormData object using its get() method, which returns a standard JavaScript File object.

// app/actions.js
'use server';

export async function uploadFile(formData) {
  const file = formData.get('myFile');
  if (!file) {
    return { error: 'No file uploaded.' };
  }
  // 'file' is a File object
  console.log('File name:', file.name);
  console.log('File size:', file.size, 'bytes');
  console.log('File type:', file.type);
  return { success: true };
}

Exploring the File Object

The File object received in your Server Action is a powerful Web API object. It provides key information about the uploaded file:

  • name: The original filename provided by the user.
  • size: The file size in bytes.
  • type: The MIME type of the file (e.g., "image/jpeg", "application/pdf").
  • arrayBuffer(): An asynchronous method to get the file's content as an ArrayBuffer, which is crucial for saving it.

Storing Uploaded Files to Disk

To save the uploaded file permanently, you'll need to extract its content from the File object and write it to a storage location. The arrayBuffer() method helps convert the file into raw binary data.

You can then use Node.js's built-in fs/promises module to write this data to your server's file system.

// app/actions.js (continued)
'use server';
import { writeFile } from 'fs/promises';
import path from 'path';

export async function saveUploadedFile(formData) {
  const file = formData.get('myFile');
  if (!file || file.size === 0) return { error: 'No file.' };

  const buffer = Buffer.from(await file.arrayBuffer());
  const filename = Date.now() + '-' + file.name; // Unique filename
  const filePath = path.join(process.cwd(), 'public/uploads', filename);

  try {
    await writeFile(filePath, buffer);
    console.log('File saved to:', filePath);
    return { success: true, filename };
  } catch (error) {
    console.error('Error saving file:', error);
    return { error: 'Failed to save file.' };
  }
}

Validating File Uploads

It's crucial to validate uploaded files on the server-side to prevent security vulnerabilities and ensure data integrity. Always check:

  • File Type: Ensure the file's MIME type is among your allowed types (e.g., only images, not executable files).
  • File Size: Limit the maximum size to prevent denial-of-service attacks or excessive storage usage.

Client-side validation is helpful for user experience but can be bypassed, so server-side checks are mandatory.

Implementing Server-Side Validation

Here's how you can add basic type and size validation to your Server Action before saving the file. This makes your upload process much more robust and secure.

// app/actions.js (validation added)
'use server';
import { writeFile } from 'fs/promises';
import path from 'path';

const MAX_FILE_SIZE = 1024 * 1024 * 5; // 5MB
const ALLOWED_TYPES = ['image/jpeg', 'image/png', 'application/pdf'];

export async function validateAndSaveFile(formData) {
  const file = formData.get('myFile');
  if (!file || file.size === 0) return { error: 'No file.' };

  if (file.size > MAX_FILE_SIZE) {
    return { error: 'File too large (max 5MB).' };
  }
  if (!ALLOWED_TYPES.includes(file.type)) {
    return { error: 'Invalid file type.' };
  }

  const buffer = Buffer.from(await file.arrayBuffer());
  const filename = Date.now() + '-' + file.name;
  const filePath = path.join(process.cwd(), 'public/uploads', filename);

  await writeFile(filePath, buffer);
  return { success: true, filename };
}

Handling Multiple File Uploads

To allow users to upload multiple files at once, simply add the multiple attribute to your <input type="file"> tag.

On the server, formData.getAll('myFiles') will return an array of File objects, allowing you to iterate and process each one individually.

// HTML for multiple files:
<form action="/api/upload" method="POST" enctype="multipart/form-data">
  <input type="file" name="myFiles" multiple />
  <button type="submit">Upload</button>
</form>

// Server Action for multiple files:
'use server';

export async function uploadMultipleFiles(formData) {
  const files = formData.getAll('myFiles');
  if (!files || files.length === 0) return { error: 'No files.' };

  const uploadedNames = [];
  for (const file of files) {
    // Perform validation and saving for each file
    console.log('Processing file:', file.name);
    uploadedNames.push(file.name);
  }
  return { success: true, uploadedNames };
}

Beyond Local Storage

While saving files locally is suitable for development and small projects, production applications often use cloud storage solutions for scalability, reliability, and security.

Popular options include AWS S3, Google Cloud Storage, and Cloudinary. Server Actions can integrate directly with these services by sending the file's ArrayBuffer to their respective SDKs, providing robust storage capabilities.

File Upload Quiz

Which of the following HTML attributes is absolutely essential for a basic form to correctly send file data to a Next.js Server Action?

Recap & Next Steps

You've learned how to handle file uploads using Next.js Server Actions!

  • Set up HTML forms with enctype="multipart/form-data" and <input type="file">.
  • Access uploaded files as File objects from the FormData object in your Server Actions.
  • Save files to disk using Node.js fs/promises by converting the File object's content via Buffer.from(await file.arrayBuffer()).
  • Implement crucial server-side validation for file types and sizes to enhance security.
  • Handle multiple file uploads by adding the multiple attribute to the input and using formData.getAll().

Next, explore how to provide optimistic UI updates for a smoother user experience after an action!

免费开始

用 AI 导师学习 TypeScript — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
22
课程
88

常见问题解答

「使用操作上传文件」课时是免费的吗?

是的 — 「使用操作上传文件」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Next.js 15 Fullstack (App Router + Server Actions) 课程的其余内容,请升级到 CoddyKit PRO。 Next.js 15 Fullstack (App Router + Server Actions) 课程共包含 3 节课。

「使用操作上传文件」这节课中我会学到什么?

学习如何直接通过服务器操作处理文件上传,包括安全存储和处理 你通过在浏览器中直接运行的动手代码来练习 Next.js 15 Fullstack (App Router + Server Actions),全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Next.js 15 Fullstack (App Router + Server Actions) 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Next.js 15 Fullstack (App Router + Server Actions) 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 3 节。

「使用操作上传文件」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Next.js 15 Fullstack (App Router + Server Actions) 课中编写并运行代码吗?

能。每节 Next.js 15 Fullstack (App Router + Server Actions) 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 乐观用户界面更新
  2. 使用操作上传文件
  3. 服务器操作中的验证与错误处理
← 返回 Next.js 15 Fullstack (App Router + Server Actions)