All guides

How to Upload a PDF File Using C#

Uploading files is a common requirement in modern applications. This guide will walk you through two primary methods for uploading PDF files using C#: a simple file copy (for local scenarios) and a web-based upload using ASP.NET Core MVC.


Method 1: Simple File Copy (For Console/WinForms/WPF)

This method is ideal for applications where you simply need to copy a PDF from one location to another on the same machine or a network drive.

Steps:

  1. Specify Source and Destination Paths: Define the path to the PDF you want to upload and the target directory.
  2. Check if the Source File Exists: Always validate that the file exists before attempting to copy.
  3. Ensure the Target Directory Exists: Create the target directory if it doesn't.
  4. Copy the File: Use the File.Copy method.

Code Example:

using System;
using System.IO;

class Program
{
    static void Main()
    {
        // 1. Define paths
        string sourceFilePath = @"C:\Users\YourName\Documents\my-document.pdf";
        string targetDirectory = @"D:\ServerUploads\PDFs\";
        string targetFilePath = Path.Combine(targetDirectory, "uploaded-file.pdf");

        try
        {
            // 2. Check if source file exists
            if (!File.Exists(sourceFilePath))
            {
                Console.WriteLine("Source file does not exist.");
                return;
            }

            // 3. Create the target directory if it doesn't exist
            Directory.CreateDirectory(targetDirectory);

            // 4. Copy the file (overwrite if it already exists)
            File.Copy(sourceFilePath, targetFilePath, overwrite: true);
            Console.WriteLine("PDF file uploaded successfully!");
        }
        catch (Exception ex)
        {
            Console.WriteLine($"An error occurred: {ex.Message}");
        }
    }
}

Method 2: Web Upload with ASP.NET Core MVC

This is the most common scenario for web applications. It involves creating a form for the user to select a file and a controller action to process the upload.

Step 1: Create the View (HTML Form)

Create a Razor view (e.g., Index.cshtml) with a form that has enctype="multipart/form-data", which is essential for file uploads.

@* Views/Home/Index.cshtml *@

<form
  asp-action="UploadPdf"
  asp-controller="Home"
  method="post"
  enctype="multipart/form-data"
>
  <div class="form-group">
    <label for="file">Select a PDF File:</label>
    <input
      type="file"
      name="file"
      id="file"
      accept=".pdf"
      class="form-control"
    />
  </div>
  <button type="submit" class="btn btn-primary">Upload PDF</button>
</form>

@* Display a success message *@ @if (ViewBag.Message != null) {
<div class="alert alert-success">@ViewBag.Message</div>
}

Key Points:

  • enctype="multipart/form-data": Crucial for sending file data.
  • accept=".pdf": Hints the browser to filter for PDF files (client-side only).

Step 2: Create the Controller Action

In your controller (e.g., HomeController.cs), create an action method to handle the POST request.

using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Mvc;
using System.IO;
using System.Threading.Tasks;

public class HomeController : Controller
{
    // ... other actions ...

    [HttpPost]
    public async Task<IActionResult> UploadPdf(IFormFile file)
    {
        // 1. Basic validation
        if (file == null || file.Length == 0)
        {
            ViewBag.Message = "Please select a valid PDF file.";
            return View("Index");
        }

        // 2. Validate file type (check the MIME type and extension)
        if (file.ContentType != "application/pdf" ||
            Path.GetExtension(file.FileName).ToLower() != ".pdf")
        {
            ViewBag.Message = "Error: Only PDF files are allowed.";
            return View("Index");
        }

        // 3. Set a size limit (e.g., 5 MB)
        const long maxFileSize = 5 * 1024 * 1024; // 5MB in bytes
        if (file.Length > maxFileSize)
        {
            ViewBag.Message = "Error: File size cannot exceed 5 MB.";
            return View("Index");
        }

        // 4. Define the path where the file will be saved
        var uploadsFolder = Path.Combine(Directory.GetCurrentDirectory(), "wwwroot", "uploads");

        // Create the directory if it doesn't exist
        Directory.CreateDirectory(uploadsFolder);

        // Generate a unique file name to prevent overwrites
        var uniqueFileName = Guid.NewGuid().ToString() + "_" + file.FileName;
        var filePath = Path.Combine(uploadsFolder, uniqueFileName);

        // 5. Save the file to the server
        using (var fileStream = new FileStream(filePath, FileMode.Create))
        {
            await file.CopyToAsync(fileStream);
        }

        // 6. Success!
        ViewBag.Message = "File uploaded successfully!";
        return View("Index");
    }
}

Explanation of the Controller Code:

  1. Validation: Checks if a file was provided and is not empty.
  2. File Type Check: Validates both the MIME type (application/pdf) and the file extension. This is a defense-in-depth measure, but note that MIME types can be spoofed.
  3. Size Limit: Prevents users from uploading excessively large files, protecting your server's storage and bandwidth.
  4. Target Path: Defines a folder inside the wwwroot directory so that uploaded files can be served over the web if necessary. Using Guid creates a unique filename to avoid conflicts.
  5. Saving the File: Uses a FileStream to asynchronously write the file to disk. CopyToAsync is non-blocking and efficient.

Security Best Practices

  1. Validate File Type: Never trust the file extension alone. For highly sensitive systems, consider scanning the file's header bytes or using a dedicated library to verify it's a valid PDF.
  2. Limit File Size: Always enforce a reasonable size limit.
  3. Sanitize Filenames: Remove or replace any dangerous characters from the original filename before saving it to prevent path traversal attacks (e.g., ../../../malicious.exe). The example uses a Guid which avoids this issue entirely.
  4. Store Files Securely: Do not save uploaded files in a web-accessible directory unless you intend for them to be publicly downloadable. If they are private, store them outside of wwwroot and implement an authentication/authorization controller to serve them.
  5. Use HTTPS: Always use HTTPS in production to encrypt the file during transmission.

Conclusion

Uploading PDF files in C# is straightforward. For desktop applications, the File.Copy method is simple and effective. For web applications, ASP.NET Core's IFormFile interface provides a powerful and secure way to handle file uploads asynchronously, complete with built-in validation and security features.

By following the code examples and best practices outlined above, you can implement a robust and secure PDF upload feature in your C# application.