文件上传
简介
文件上传字段基于 Filepond。
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachment')

TIP
Filament 也支持 spatie/laravel-medialibrary。请查看插件文档以获取更多信息。
配置存储磁盘及目录
默认情况下,文件会上传到配置文件中定义的存储磁盘中。你也可以设置 FILESYSTEM_DISK 环境变量来修改他。
TIP
为了正确预览图像和其他文件,Filepond 要求文件与应用来自同一域名,或者需要存在相应的 CORS 标头。确保 APP_URL 环境变量正确,或修改文件系统驱动以设置正确的URL。如果你在单独的域名(如 S3)上托管文件,请确保设置了 CORS 标头。
要修改特定字段的磁盘和目录,以及文件的可见度,请使用 disk()、directory() 和 visibility() 方法。默认情况下,文件以 private 可见度上传到你的存储磁盘,除非你将该磁盘设置为 public:
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachment')
->disk('s3')
->directory('form-attachments')
->visibility('public')
除了允许静态值之外,disk()、directory() 和 visibility() 方法也接受函数来动态计算它们的值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
NOTE
如果这些文件被移除,开发者有责任从磁盘中删除它们,因为 Filament 无法感知它们是否被其他地方依赖。自动执行此操作的一种方法是观察 模型事件。
上传多个文件
你也可以上传多个文件。这将会把 URL 保存到 JSON 中:
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachments')
->multiple()
或者,你也可以传递布尔值来控制是否可以一次上传多个文件:
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachments')
->multiple(FeatureFlag::active())
除了允许静态值之外,multiple() 方法也接受函数来动态计算其值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
如果你使用 Eloquent 保存文件 URL,则应确保向模型属性添加一个 array cast:
use Illuminate\Database\Eloquent\Model;
class Message extends Model
{
protected $casts = [
'attachments' => 'array',
];
// ...
}
控制最大并行上传数
你可以使用 maxParallelUploads() 方法控制并行上传的最大数量:
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachments')
->multiple()
->maxParallelUploads(1)
这会将并行上传数量限制为 1。如果未设置,我们将使用 FilePond 的默认值,即 2。
除了允许静态值之外,maxParallelUploads() 方法也接受函数来动态计算其值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
控制文件名
默认情况下,系统会为新上传的文件生成一个随机文件名。这是为了确保不会与现有文件发生任何冲突。
控制文件名的安全隐患
在使用 preserveFilenames() 或 getUploadedFileNameForStorageUsing() 方法之前,请注意其安全隐患。如果你允许用户使用自定义文件名上传文件,则他们可能会利用这一点上传恶意文件。即使你使用 acceptedFileTypes() 方法 限制可上传的文件类型,这种情况仍然适用,因为它使用了 Laravel 的 mimetypes 规则,该规则不验证文件的扩展名, 只验证其 MIME 类型,而 MIME 类型可能会被篡改。
这主要是 TemporaryUploadedFile 对象上的 getClientOriginalName() 方法存在的问题,而 preserveFilenames() 方法正是使用了该方法。默认情况下,Livewire 会为每个上传的文件生成一个随机文件名,并使用文件的 mime 类型来确定文件扩展名。
如果攻击者上传了具有欺骗性 mime 类型的 PHP 文件,则 在 local 或 public 文件系统磁盘上 使用这些方法会使你的应用容易受到远程代码执行攻击。使用 S3 磁盘可以保护你免受这种特定攻击媒介的影响,因为 S3 执行 PHP 文件的方式与服务器从本地存储提供文件的方式不同。
如果你使用的是 local 或 public 磁盘,则应考虑使用 storeFileNamesIn() 方法将原始文件名存储在数据库的单独列中,并将随机生成的文件名保留在文件系统中。这样,你仍然可以向用户显示原始文件名,同时确保文件系统的安全。
除了这个安全问题之外,你还应该注意,允许用户使用自己的文件名上传文件可能会导致与现有文件冲突,并使你的存储管理变得困难。如果你没有将用户限制在特定目录中,用户可能会上传同名文件并覆盖其他用户的内容,因此这些功能在任何情况下都应仅允许受信任的用户访问。
保留原始文件名
NOTE
在使用此功能之前,请确保你已阅读安全隐患。
要保留上传文件的原始文件名,请使用 preserveFilenames() 方法:
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachment')
->preserveFilenames()
或者,你可以传递一个布尔值来控制是否应保留原始文件名:
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachment')
->preserveFilenames(FeatureFlag::active())
除了允许静态值之外,preserveFilenames() 方法也接受函数来动态计算其值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
生成自定义文件名
NOTE
在使用此功能之前,请确保你已阅读安全隐患。
你可以完全自定义使用 getUploadedFileNameForStorageUsing() 方法生成文件名的方式,并根据上传的 $file 从闭包中返回一个字符串:
use Livewire\Features\SupportFileUploads\TemporaryUploadedFile;
FileUpload::make('attachment')
->getUploadedFileNameForStorageUsing(
fn (TemporaryUploadedFile $file): string => (string) str($file->getClientOriginalName())
->prepend('custom-prefix-'),
)
You can inject various utilities into the function passed to getUploadedFileNameForStorageUsing() as parameters.
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| File | Livewire\Features\SupportFileUploads\TemporaryUploadedFile | $file | The temporary file object being uploaded. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
独立保存原始文件名
你可以使用 storeFileNamesIn() 方法保留随机生成的文件名,同时仍存储原始文件名:
use Filament\Forms\Components\FileUpload;
FileUpload::make('attachments')
->multiple()
->storeFileNamesIn('attachment_file_names')
attachment_file_names 现在将存储你上传文件的原始文件名,以便你在提交表单时将其保存到数据库。如果你使用 multiple() 上传多个文件,请确保也向此 Eloquent 模型属性添加 array cast。
除了允许静态值之外,storeFileNamesIn() 方法也接受函数来动态计算其值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
头像模式
你可以使用 avatar() 方法为文件上传字段启用头像模式:
use Filament\Forms\Components\FileUpload;
FileUpload::make('avatar')
->avatar()
这将仅允许上传图片,上传后,图片将以紧凑的圆形布局显示,非常适合头像。
此功能与圆形裁剪器完美搭配。
图片编辑器
你可以使用 imageEditor() 方法为文件上传字段启用图像编辑器:
use Filament\Forms\Components\FileUpload;
FileUpload::make('image')
->image()
->imageEditor()
上传图片后,点击铅笔图标即可打开编辑器。你也可以点击现有图片上的铅笔图标来打开编辑器,保存后会移除该图片并重新上传。
你也可以选择传递布尔值来控制是否启用图片编辑器:
use Filament\Forms\Components\FileUpload;
FileUpload::make('image')
->image()
->imageEditor(FeatureFlag::active())
除了允许静态值之外,imageEditor() 方法也接受函数来动态计算其值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
允许用户按宽高比裁剪图片
你可以使用 imageEditorAspectRatios() 方法允许用户按一组特定的宽高比裁剪图片:
use Filament\Forms\Components\FileUpload;
FileUpload::make('image')
->image()
->imageEditor()
->imageEditorAspectRatios([
'16:9',
'4:3',
'1:1',
])
你还可以通过传递 null 作为选项来允许用户选择无纵横比、“自由裁剪”:
use Filament\Forms\Components\FileUpload;
FileUpload::make('image')
->image()
->imageEditor()
->imageEditorAspectRatios([
null,
'16:9',
'4:3',
'1:1',
])
除了允许静态值之外,imageEditorAspectRatios() 方法也接受函数来动态计算其值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
设置图片编辑器模式
你可以使用 imageEditorMode() 方法更改图片编辑器的模式,该方法接受 1、2 或 3。这些选项的详细说明请参阅 Cropper.js 文档:
use Filament\Forms\Components\FileUpload;
FileUpload::make('image')
->image()
->imageEditor()
->imageEditorMode(2)
除了允许静态值之外,imageEditorMode() 方法也接受函数来动态计算其值。你可以将各种 utility 作为参数注入到函数中。
Learn more about utility injection.| Utility | Type | Parameter | Description |
|---|---|---|---|
| Field | Filament\Forms\Components\Field | $component | The current field component instance. |
| Get function | Filament\Schemas\Components\Utilities\Get | $get | A function for retrieving values from the current form data. Validation is not run. |
| Livewire | Livewire\Component | $livewire | The Livewire component instance. |
| Eloquent model FQN | ?string<Illuminate\Database\Eloquent\Model> | $model | The Eloquent model FQN for the current schema. |
| Operation | string | $operation | The current operation being performed by the schema. Usually <code>create</code>, <code>edit</code>, or <code>view</code>. |
| Raw state | mixed | $rawState | The current value of the field, before state casts were applied. Validation is not run. |
| Eloquent record | ?Illuminate\Database\Eloquent\Model | $record | The Eloquent record for the current schema. |
| State | mixed | $state | The current value of the field. Validation is not run. |
