# File uploads — allowed types
MetaSoul ERP validates uploads with `App\Support\UploadRules` (Phase 2.2 / H3).
Executable and script types such as **`.php`**, **`.exe`**, **`.phar`**, **`.phtml`** are **not** in the allow-lists.
Files are stored under `storage/app/public/…` (linked via `php artisan storage:link`), not as executable web scripts.
---
## Presets
| Preset | Typical use | Allowed extensions (summary) |
|--------|-------------|------------------------------|
| **Documents** (`UploadRules::DOCUMENTS`) | Chatter, property docs, approvals, discuss | pdf, images, office (doc/xls/ppt), csv, txt, zip, odt/ods/rtf |
| **Images** | Product / media images | jpg, jpeg, png, gif, webp, bmp, svg |
| **Icons** | Website icons | png, jpg, jpeg, gif, webp, svg, ico |
| **Videos** | Website video | mp4, webm, ogg, mov |
| **CSV** | Import tools | csv, txt |
| **Bank** | Bank statement import | csv, txt, ofx, qfx |
| **XML** | UBL import | xml, txt |
| **Workspace** | Documents app | Documents + mp3/mp4/webm/m4a |
| **Layout** | Quote headers/footers | pdf + images |
Max sizes vary by endpoint (commonly 5–10 MB; Documents up to ~64 MB).
---
## Controllers hardened in Phase 2.2
Among others: `ProjectTaskController`, `Offline\SyncController`, `PropertyController`, Sales chatter/layouts, Website media, Subscriptions, PLM, Helpdesk, Documents, Discuss, Approvals, Accounting UBL/bank import.
---
## Buyer tip
If a legitimate file type is rejected, convert to PDF or a listed office/image format, or ask your developer to extend `UploadRules` carefully (never allow PHP/EXE).
---
*Related: [INSTALL.md](INSTALL.md) · [SECURITY notes in TROUBLESHOOTING.md](TROUBLESHOOTING.md)*