
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@devino.solutions/upup
Advanced tools
Upup is an open-source, free-to-use Full-stack library that easily handles your file upload needs with seamless DigitalOcean Spaces, Amazon S3, Backblaze, Microsoft Azure Blob Storage, Google Drive, and OneDrive integrations.
🎮 Join our Discord, where we can provide quick support: Discord Invite Link
Install upup with your favourite package manager
npm install @devino.solutions/upup
yarn add @devino.solutions/upup
pnpm add @devino.solutions/upup
bun install @devino.solutions/upup
This logic diagram explains how the client and server parts of the upup package works

The example below shows a minimal configuration for AWS S3 upload, using the UpupUploader client component and the s3GeneratePresignedUrl utility. For full code examples check these docs
import { UpupUploader, UpupProvider } from '@bassem97/upup'
export default function Uploader() {
return (
<UpupUploader
provider={UpupProvider.AWS} // assuming we are uploading to AWS
tokenEndpoint="http://<path_to_your_server>/api/upload-token" // Path to your server route that calls our exported upload utilities
/>
)
}
The
UpupUploadermust be placed in a client component.
Then use it in your application:
import Uploader from '<path_to_your_uploader_component>'
export default function App() {
return <Uploader />
}
providerandtokenEndpointare the only required props for the UpupUploader component. For a full list of component props, check out these docs.
import { s3GeneratePresignedUrl } from '@devino.solutions/upup/server'
app.post('/api/upload-token', async (req, res) => {
try {
const { provider, ...fileParams } = req.body // The request body sent from the `UpupUploader` client component
const origin = req.headers['origin'] // The origin of your client application
// Generate presigned URL
const presignedData = await s3GeneratePresignedUrl({
origin: origin as string,
provider,
fileParams,
bucketName: process.env.AWS_BUCKET_NAME as string,
s3ClientConfig: {
region: process.env.AWS_REGION as string,
credentials: {
accessKeyId: process.env.AWS_ACCESS_KEY_ID as string,
secretAccessKey: process.env
.AWS_SECRET_ACCESS_KEY as string,
},
},
})
return res.status(200).json({
data: presignedData,
message: 'Upload successful!',
error: false,
})
} catch (error) {
return res.status(500).json({
message: (error as Error).message,
error: true,
})
}
})
Once again, the example shown above is the minimal required configuration for AWS S3 upload. For uploading to other services see these docs
It is important to note that while it is possible to:
UpupUploader React component on the client and implement your own custom server logic to handle uploads,For best performance and minimal overhead, we advise that you use both the UpupUploader React component together with the server utilities, like s3GeneratePresignedUrl
The full list of exported server utility functions include:
s3GeneratePresignedUrl: for S3-compatible Uploads: like AWS, Digital Ocean, BackblazeazureGenerateSasUrl: for Azure Blob Uploads onlyFor a full list of values sent by the React component to the server, check out these docs.
Find the full API reference and guides in the official documentation.
Please read our Contributing Guidelines before submitting pull requests. All contributions fall under our Code of Conduct.
For security concerns, please review our Security Policy.
This project is licensed under the MIT License - see the LICENSE file for details.
Made with ❤️ by Devino
FAQs
README.md
The npm package @devino.solutions/upup receives a total of 72 weekly downloads. As such, @devino.solutions/upup popularity was classified as not popular.
We found that @devino.solutions/upup demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.