# form file upload loses file when validation fails

**URL:** https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067
**Category:** Forms & APIs
**Created:** [March 14, 2024, 2:33pm UTC](https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067 "2024-03-14T14:33:03Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![nerdoc](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/nerdoc/32/8916_2.png) [@nerdoc](https://forum.djangoproject.com/u/nerdoc)
#### Post date: [March 14, 2024, 2:33pm UTC](https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067/1 "2024-03-14T14:33:03Z")

</div>

It is a bit scary that Django looses file uploads when validation fails. There are already Stackoverflow issues like [this](https://stackoverflow.com/questions/3097982/how-to-make-a-django-form-retain-a-file-after-failing-validation), and the [django-file-resubmit](https://github.com/un1t/django-file-resubmit) app that tries to address that problem (4 years without commit - maintained?)

Is there a “Django” way to solve this issue once and for all? I accept that it is a security issue that a browser can’t pre-fill a filefield in a GET request. But then, Django, knowing this, must automatically store the file elsewhere temporarily until the form is submitted.

It shouldn’t be necessary to use an external module for that. It should be in Django core.

Thoughts?

---

<div class="post-metadata">

### Author: ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)
#### Post date: [March 14, 2024, 3:04pm UTC](https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067/2 "2024-03-14T15:04:32Z")

</div>

> [@nerdoc](#):
>
> It is a bit scary that Django looses file uploads when validation fails.

Why would it be “scary”? This is precisely what I would hope it would do.

> [@nerdoc](#):
>
> It shouldn’t be necessary to use an external module for that. It should be in Django core.

I disagree. You don’t normally keep data from submitted forms that are invalid. If you want to do this, then I do believe that constitutes a “special-case” that needs to be handled differently.

If you want to handle this yourself, you do have multiple options.

Yes, you can implement the logic used by `django-file-resubmit to maintain a cache of “uploaded-but-not-commited” files. (You then need to manage that cache to ensure you don’t have a boundless number of useless files hanging around.

Or, you could make the file upload a separate step. Have the user fill out the form with the necessary data, then present a follow-up form for the upload.

Or, you could implement an “AJAX-style” validation of the form data. Submit the non-input fields via AJAX, and then permit the file upload to proceed once the form data has been validated.

---

<div class="post-metadata">

### Author: ![nerdoc](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/nerdoc/32/8916_2.png) [@nerdoc](https://forum.djangoproject.com/u/nerdoc)
#### Post date: [March 14, 2024, 5:13pm UTC](https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067/3 "2024-03-14T17:13:52Z")

</div>

Yes, that may be a few options. The file resubmit module did not convince me.  
I think I will go the separate step way, this fits better into the workflow.  
Thanks for the separation of thoughts here.

> Or, you could implement an “AJAX-style” validation of the form data. Submit the non-input fields via AJAX, and then permit the file upload to proceed once the form data has been validated.

What do you mean with “non-input fields”?

---

<div class="post-metadata">

### Author: ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)
#### Post date: [March 14, 2024, 5:46pm UTC](https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067/4 "2024-03-14T17:46:53Z")

</div>

Sorry, very bad edit on my part. That should be “non-file” input fields. In other words, all fields _other_ than the file uploads.

---

<div class="post-metadata">

### Author: ![nerdoc](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/nerdoc/32/8916_2.png) [@nerdoc](https://forum.djangoproject.com/u/nerdoc)
#### Post date: [March 15, 2024, 6:18pm UTC](https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067/5 "2024-03-15T18:18:22Z")

</div>

Thanks! Clear then! If you want we can delete the last 2 posts - to reduce spam, and you correct the word in your answer?

---

<div class="post-metadata">

### Author: ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)
#### Post date: [February 27, 2025, 12:38pm UTC](https://forum.djangoproject.com/t/form-file-upload-loses-file-when-validation-fails/29067/6 "2025-02-27T12:38:20Z")

</div>

3 posts were split to a new topic: [Keeping file uploads when form validation fails](https://forum.djangoproject.com/t/keeping-file-uploads-when-form-validation-fails/39185)
