Skip to content

basalt / http/src / sanitizeFilename

Function: sanitizeFilename() ​

> sanitizeFilename(raw): string

Defined in: http/src/multipart.ts:343

Reduces a client-supplied filename to a safe display basename: never a path. Directories are stripped on both / and \ (so ../../x and C:\x become x), a drive prefix is dropped, control/NUL and invisible bidi characters are removed, trailing dots/spaces are trimmed, and the result is capped at 255 UTF-8 bytes with the extension kept. Returns 'file' when nothing usable is left. Still only a label — never use it as a storage key.

Parameters ​

raw ​

string

Returns ​

string

Released under the MIT License.