<input type=file> restricting types of files, default directory

Posted on 2001-07-09
Last Modified: 2012-08-13
Hi all,
Two questions:

To restrict the types of files a user can select using <input type=file>, I set the following property: (e.g.) accept="image/*". This should, supposedly, only list images in the file browser box when you click Browse. Except it doesn't, it always lists all files. I'm using IE 5.5 on Win2K. Is this a Netscape property? What am I doing wrong?

Is it possible to open the file browser box in a certain specified directory, it always seems to start in "my pictures" or something like this.

Question by:Musravus1
  • 3
  • 2
LVL 19

Expert Comment

ID: 6264447
You don't have ANY control over this on the client side. You can change what you're going to accept on the SERVER, but you can't change what they get or where they start on the CLIENT.

HUMONGOUS security hole if you could.

Author Comment

ID: 6264517
That makes sense of course if you think about it, although I can't really see why specifying that the file browser box should only list files of type "image" is a huge security risk.

In the meantime I have found out that most browsers don't support the "accept" property although it has been out there for a long time.

Does anyone know if IE6 has found a nice way to deal with this problem?
LVL 53

Expert Comment

ID: 6264701
I have not done much with IE 6 beta yet, but the direction is toward higher levels of privacy protection which means more restrictive security, not less.

As developers we find the security elements to be a limitation, but from the users side the security concerns get raised with every new hack attack, and the browsers are designed for users not developers.

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

LVL 53

Accepted Solution

COBOLdinosaur earned 100 total points
ID: 6265946
This is a filter I did a while ago.  It might help. It doesn't prevent the
user from selecting the wrong file type, but it does prevent them from
submitting anythin with the wrong extension.

   <title> file type filter </title>
   body {background-color:blue;color:lightyellow;border:5px outset red}
   #prompt {padding:10;background-color:blueviolet;color:floralwhite;
   .container {width:250;background-color:brown;color:peru;
               border:3px outset burlywood}
   .file {background-color:deepskyblue;colorcadet:blue;
   .sbutton {background-color:dimgray;color:pink;border-color:dodgerblue}
<script language="JavaScript">
   var fileType = new Array(".gif", ".jpg", ".png");
   var arrayList="File Types: ";
   for (i=0;i<fileType.length;i++)
      { arrayList+=fileType[i]+" "; }
   var uploadOK=false;
   function filterFiles(thesource,thefile)
      uploadOK = false;
      if (thefile)
         while (thefile.indexOf("\\") != -1)
            thefile = thefile.slice(thefile.indexOf("\\") + 1);
         ftype = thefile.slice(thefile.indexOf(".")).toLowerCase();
         for (i=0;i<fileType.length;i++)
            if (fileType[i]==ftype)
      if (uploadOK)
         alert(arrayList+' only please');
//  End -->
<h1 align="center"> File Upload Filter</h1>
<p> With this script you can set the file extensions that are acceptable
    for uploading and the user will be prompted with the list.  When
    they select a file and submit, the extention will be validated and
    either the submit will be executed for the user will get an alert.
<div align="center">
<script language="JavaScript">
document.write('<div align="center" id="prompt"> Upload '+arrayList+ '</div>');
// -->
<div align="center" class="container">
<form method="post" name="myform">
   <input type="file" name="myfile" class="file">
   <input type="button" name="Submit" value="Submit" class="sbutton"
      onClick="filterFiles(document.myform,document.myform.myfile.value);return false">

Author Comment

ID: 6268248
Thanks, that will do the trick for now. I'm planning into turning this into a signed applet (don't worry, it's an intranet application) which will do most of the stuff I want, I just needed to know the alternatives.

I'll abandon the "default directory" idea, it makes sense you can't prescribe this on a client machine you know nothing about.
LVL 53

Expert Comment

ID: 6268896
At least with an intranet you have some consistency with the client environment, unlike the Internet where the user variations ar almost infinite.


Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How can I upload multiple images from a HTML form? 2 28
Html test in IIS 4 20
div to fit another div 8 22
Select case on click 3 16
Have you tried to learn about Unicode, UTF-8, and multibyte text encoding and all the articles are just too "academic" or too technical? This article aims to make the whole topic easy for just about anyone to understand.
Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
HTML5 has deprecated a few of the older ways of showing media as well as offering up a new way to create games and animations. Audio, video, and canvas are just a few of the adjustments made between XHTML and HTML5. As we learned in our last micr…
The viewer will learn the basics of jQuery including how to code hide show and toggles. Reference your jQuery libraries: (CODE) Include your new external js/jQuery file: (CODE) Write your first lines of code to setup your site for jQuery…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question