Class DiskFileItemFactory
- java.lang.Object
-
- org.apache.commons.fileupload2.core.DiskFileItemFactory
-
- All Implemented Interfaces:
FileItemFactory<DiskFileItem>
public final class DiskFileItemFactory extends Object implements FileItemFactory<DiskFileItem>
The defaultFileItemFactoryimplementation.This implementation creates
FileIteminstances which keep their content either in memory, for smaller items, or in a temporary file on disk, for larger items. The size threshold, above which content will be stored on disk, is configurable, as is the directory in which temporary files will be created.If not otherwise configured, the default configuration values are as follows:
- Size threshold is 10 KB.
- Repository is the system default temporary directory, as returned by
System.getProperty("java.io.tmpdir").
NOTE: Files are created in the system default temporary directory with predictable names. This means that a local attacker with write access to that directory can perform a TOUTOC attack to replace any uploaded file with a file of the attackers choice. The implications of this will depend on how the uploaded file is used but could be significant. When using this implementation in an environment with local, untrusted users,
AbstractOriginSupplier.setPath(Path)MUST be used to configure a repository location that is not publicly writable. In a Servlet container the location identified by the ServletContext attributejavax.servlet.context.tempdirmay be used.Temporary files, which are created for file items, should be deleted later on. The best way to do this is using a
FileCleaningTracker, which you can set on theDiskFileItemFactory. However, if you do use such a tracker, then you must consider the following: Temporary files are automatically deleted as soon as they are no longer needed. (More precisely, when the corresponding instance ofFileis garbage collected.) This is done by the so-called reaper thread, which is started and stopped automatically by theFileCleaningTrackerwhen there are files to be tracked. It might make sense to terminate that thread, for example, if your web application ends. See the section on "Resource cleanup" in the users guide of Commons FileUpload.
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static classDiskFileItemFactory.BuilderBuilds a newDiskFileItemFactoryinstance.-
Nested classes/interfaces inherited from interface org.apache.commons.fileupload2.core.FileItemFactory
FileItemFactory.AbstractFileItemBuilder<I extends FileItem<I>,B extends FileItemFactory.AbstractFileItemBuilder<I,B>>
-
-
Field Summary
Fields Modifier and Type Field Description static intDEFAULT_THRESHOLDThe default threshold in bytes above which uploads will be stored on disk.
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description static DiskFileItemFactory.Builderbuilder()Constructs a newDiskFileItemFactory.Builder.DiskFileItem.BuilderfileItemBuilder()Creates a new AbstractFileItemBuilder.CharsetgetCharsetDefault()Gets the default charset for use when no explicit charset parameter is provided by the sender.org.apache.commons.io.FileCleaningTrackergetFileCleaningTracker()Gets the tracker, which is responsible for deleting temporary files.PathgetRepository()Gets the directory used to temporarily store files that are larger than the configured size threshold.intgetThreshold()Gets the size threshold beyond which files are written directly to disk.
-
-
-
Field Detail
-
DEFAULT_THRESHOLD
public static final int DEFAULT_THRESHOLD
The default threshold in bytes above which uploads will be stored on disk.- See Also:
- Constant Field Values
-
-
Method Detail
-
builder
public static DiskFileItemFactory.Builder builder()
Constructs a newDiskFileItemFactory.Builder.- Returns:
- a new
DiskFileItemFactory.Builder.
-
fileItemBuilder
public DiskFileItem.Builder fileItemBuilder()
Description copied from interface:FileItemFactoryCreates a new AbstractFileItemBuilder.- Specified by:
fileItemBuilderin interfaceFileItemFactory<DiskFileItem>- Returns:
- a new AbstractFileItemBuilder.
-
getCharsetDefault
public Charset getCharsetDefault()
Gets the default charset for use when no explicit charset parameter is provided by the sender.- Returns:
- the default charset
-
getFileCleaningTracker
public org.apache.commons.io.FileCleaningTracker getFileCleaningTracker()
Gets the tracker, which is responsible for deleting temporary files.- Returns:
- An instance of
FileCleaningTracker, or null (default), if temporary files aren't tracked.
-
getRepository
public Path getRepository()
Gets the directory used to temporarily store files that are larger than the configured size threshold.- Returns:
- The directory in which temporary files will be located.
-
getThreshold
public int getThreshold()
Gets the size threshold beyond which files are written directly to disk. The default value is 10240 bytes.- Returns:
- The size threshold in bytes.
-
-