File Upload

Generic file upload capability: images/videos/regular files, whitelist-validated and stored to local /media, returning an accessible URL.

/api/upload/

Service Description

The file upload service provides three upload entry points: images, videos and generic files. Files are stored in the site's /media directory and returned with a directly usable URL, making it a convenient shared attachment channel for business systems.

All endpoints use multipart/form-data with the file field fixed as file. The server validates the extension against a whitelist and checks magic bytes; file types that can be rendered inline or executed (such as svg, html and scripts) are rejected outright, so uploads cannot be abused as stored XSS.

Size limits: images up to 20 MB, videos and generic files up to 100 MB. This service requires project signature authentication.

Local File Upload

Local storage (/media/uploads/...) Signature Required

All use multipart/form-data with the file field fixed to file; only whitelisted types are supported and file headers are validated (to prevent masquerading/script uploads).

POST /api/upload/image Total calls: 2

Upload Image

Upload an image and return a directly referenceable image URL.

multipart/form-data file field file: just use the "Select File" button below to upload.

  • Supported types: jpg/jpeg/png/gif/bmp/webp/ico/tiff; Size limit 20MB.
  • svg is disabled because it can embed scripts.
  • On success, returns the data field: filename / original_name / size / size_mb / ext / type / relative_path / url.
  • The returned url is the site media access address (/media/...), which can be referenced directly.
POST /api/upload/video Total calls: 0

Upload Video

Upload a video file.

multipart/form-data file field file: just use the "Select File" button below to upload.

  • Size limit 100MB; returns type=video.
  • On success, returns the data field: filename / original_name / size / size_mb / ext / type / relative_path / url.
  • The returned url is the site media access address (/media/...), which can be referenced directly.
POST /api/upload/file Total calls: 3

Upload Generic File

Upload a generic file (whitelist: zip/pdf/docx/xlsx/txt, etc.).

multipart/form-data file field file: just use the "Select File" button below to upload.

  • Size limit 100MB; whitelist-based with file header validation; returns type=file.
  • On success, returns the data field: filename / original_name / size / size_mb / ext / type / relative_path / url.
  • The returned url is the site media access address (/media/...), which can be referenced directly.
XiaoYingAPI · Unified API Aggregation Service