DEV Community

ArunEz
ArunEz

Posted on Originally published at blog.arunshaw.in

AWS S3 File Upload With NodeJs and React

AWS S3 File Upload With NodeJs and React

An extensive guide to upload files and retrieve the public url after upload, update and delete a file from AWS S3 Bucket.

Read Article : AWS S3 File Upload With NodeJs and React

Top comments (2)

Collapse
 
scsoi profile image
疏影 •

Node + React + S3 is the right stack for app-side uploads. The piece I'd add: from a Windows admin side, the question is 'how do I actually look at what the app has uploaded'. Three patterns that close that gap:

  • Mount the bucket as a drive letter. ScsDriver handles S3 alongside SMB / Blob / SFTP / WebDAV — useful when the same Node app is writing to S3 and the admin needs to inspect from a Windows laptop.
  • For CORS: keep the allowed origins scoped to your own frontend host. 'Allowed origins: *' is the most common misconfiguration that lets a third-party site start pushing files into your bucket.
  • For audit: enable CloudTrail data events on the bucket. They're cheap and the 'who uploaded what' answer becomes a 30-second CloudTrail query instead of an archaeology project. Operational note: validate the MIME type on the server before generating a presigned URL. The browser's Content-Type header is attacker-controlled; the server's check is the one that matters.
Collapse
 
scsoi profile image
疏影 •

Single-file upload via SDK is fine for prototypes but the moment you need to migrate 50M objects, re-encrypt a million, or fix metadata on billions of rows, single-PUT is the wrong tool. S3 Batch Operations is the answer and most teams underuse it:

  1. S3 Inventory is the prerequisite — Batch Ops reads from a CSV manifest that S3 Inventory generates daily or weekly. Plan for the inventory delay; if you need to act on today's data, use 'list-and-execute' mode and accept the higher per-object cost.

  2. Per-job failure tracking — every Batch Ops job writes a completion report to a prefix you specify. Parse it programmatically; do not eyeball it. We set up a Lambda on s3:TestEvent + ObjectCreated for the report bucket.

  3. IAM role, not user — Batch Ops assumes an IAM role to perform each object operation. The role's policy must allow s3:GetObject on the manifest bucket AND the target bucket. Easy to miss when the manifest bucket is in a different account.

  4. Cost reality — Batch Ops charges per object operated, plus the underlying operation cost. For 'S3 Copy' jobs that touch terabytes, the bill can exceed $10K. Always run the inventory report first to size the job before kicking it off.

For ops on Windows who want to see Batch Operations reports in Explorer: ScsDriver