{"id":907,"date":"2026-05-20T09:56:03","date_gmt":"2026-05-20T01:56:03","guid":{"rendered":"https:\/\/junai.ai\/blog\/nodejs-file-upload-20\/"},"modified":"2026-05-20T09:56:03","modified_gmt":"2026-05-20T01:56:03","slug":"nodejs-file-upload-20","status":"publish","type":"post","link":"https:\/\/junai.ai\/blog\/nodejs-file-upload-20\/","title":{"rendered":"\ud30c\uc77c \uc5c5\ub85c\ub4dc \u2014 multer\ub85c \uc774\ubbf8\uc9c0\u00b7\ud30c\uc77c \ubc1b\uae30"},"content":{"rendered":"\n<!-- WordPress REST API \ubc1c\ud589\uc6a9 HTML (\uc790\ub3d9 \uc0dd\uc131) -->\n<!-- WP-FEATURED-MEDIA-ID: 854 -->\n<div style=\"max-width:800px;margin:0 auto;\">\n<style>\n:root {--color-primary:#059669;--color-accent:#10b981;--color-bg:#fafbfc;--color-bg-card:#fff;--color-text:#1a202c;--color-text-muted:#64748b;--hero-start:#064e3b;--hero-end:#059669;}\n*{box-sizing:border-box;}\n.container{max-width:760px;margin:0 auto;padding:0 24px 80px;}\n.hero{background:linear-gradient(135deg,var(--hero-start) 0%,var(--hero-end) 100%);color:#fff;padding:80px 24px 60px;text-align:center;}\n.hero .eyebrow{display:inline-block;font-size:14px;color:#6ee7b7;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;margin-bottom:14px;}\n.hero h1{font-size:36px;margin:0 0 16px;line-height:1.3;font-weight:800;}\n.hero p{color:#d1fae5;font-size:18px;max-width:640px;margin:0 auto;line-height:1.6;}\n.hero img{width:100%;max-width:640px;height:auto;margin:32px auto 0;border-radius:10px;display:block;}\narticle{padding-top:48px;}\narticle h2{font-size:26px;margin:56px 0 20px;padding-left:14px;border-left:5px solid var(--color-accent);line-height:1.4;}\narticle h3{font-size:19px;margin:32px 0 12px;color:var(--color-primary);}\narticle p{margin:16px 0;}\narticle strong{color:var(--color-primary);font-weight:700;}\narticle code{background:#d1fae5;padding:2px 8px;border-radius:4px;font-family:'SF Mono',Menlo,Consolas,monospace;font-size:14px;color:#065f46;}\n.databox{background:#d1fae5;border-left:4px solid var(--color-accent);padding:16px 20px;margin:24px 0;border-radius:0 8px 8px 0;font-size:15.5px;}\n.databox strong{color:var(--color-primary);}\n.warnbox{background:linear-gradient(135deg,#fef3c7 0%,#fde68a 100%);padding:16px 20px;margin:24px 0;border-radius:8px;font-size:15.5px;}\n.tablewrap{overflow-x:auto;-webkit-overflow-scrolling:touch;margin:22px 0;}\ntable{width:100%;border-collapse:collapse;font-size:15px;background:var(--color-bg-card);}\nth,td{padding:11px 12px;text-align:left;border-bottom:1px solid #e2e8f0;vertical-align:top;}\nth{background:#f1f5f9;font-weight:700;color:#0f172a;}\ntd:first-child,th:first-child{font-weight:700;}\n@media (max-width:560px){.tablewrap table,.tablewrap thead,.tablewrap tbody,.tablewrap tr,.tablewrap th,.tablewrap td{display:block;width:auto;}.tablewrap thead{display:none;}.tablewrap tr{margin:0 0 14px;border:1px solid #e2e8f0;border-radius:10px;overflow:hidden;}.tablewrap td{border:none;border-bottom:1px solid #f1f5f9;padding:9px 14px;}.tablewrap td:first-child{background:#f1f5f9;font-weight:800;font-size:15.5px;}.tablewrap td:last-child{border-bottom:none;}.tablewrap td[data-label]::before{content:attr(data-label) \" \u2014 \";font-weight:700;color:var(--color-primary);}}\n.code-block{background:#0f172a;color:#e2e8f0;padding:16px 20px;border-radius:8px;font-family:'SF Mono',Menlo,Consolas,monospace;font-size:14px;line-height:1.6;margin:20px 0;overflow-x:auto;white-space:pre;}\n.cta{background:linear-gradient(135deg,#059669 0%,#10b981 100%);color:#fff;padding:28px 24px;border-radius:12px;margin:48px 0 0;text-align:center;}\n.cta h3{color:#fff;margin:0 0 8px;font-size:20px;}\n.cta p{color:#d1fae5;margin:0;font-size:15.5px;}\n.footer-nav{margin-top:32px;padding-top:20px;border-top:1px solid #e2e8f0;font-size:14px;color:var(--color-text-muted);}\n.footer-nav a{color:var(--color-primary);text-decoration:none;}\n@media (max-width:480px){.hero h1{font-size:26px;}.hero p{font-size:16px;}article h2{font-size:21px;}article h3{font-size:17px;}body{font-size:16px;}}\n<\/style>\n<section class=\"hero\">\n  <span class=\"eyebrow\">Node.js \uad50\uc7ac \u00b7 20\ud3b8 \u00b7 \ud30c\uc77c \uc5c5\ub85c\ub4dc<\/span>\n  <h1>\ud30c\uc77c \uc5c5\ub85c\ub4dc \u2014 multer\ub85c \uc774\ubbf8\uc9c0\u00b7\ud30c\uc77c \ubc1b\uae30<\/h1>\n  <p>multipart\/form-data \uac00 \ubb34\uc5c7\uc774\uace0, multer \uac00 \uadf8 \uc704\uc5d0\uc11c \ubb34\uc5c7\uc744 \uc790\ub3d9\ud654\ud558\ub098.<\/p>\n  <img decoding=\"async\" src=\"https:\/\/junai.ai\/blog\/wp-content\/uploads\/2026\/05\/hero-5-85.jpg\" alt=\"multipart \ud30c\uc77c\uc774 \uc11c\ubc84\ub85c \uc5c5\ub85c\ub4dc\ub418\ub294 \ucee8\uc149 \uc77c\ub7ec\uc2a4\ud2b8\">\n<\/section>\n\n<div class=\"container\">\n<article>\n\n<p>13\ud3b8\uc758 <code>express.json()<\/code> \uc73c\ub85c\ub294 \ubabb \ubc1b\ub294 \uac8c \ud558\ub098 \uc788\ub2e4 \u2014 <strong>\ud30c\uc77c<\/strong>. \uc774\ubbf8\uc9c0\u00b7PDF\u00b7\ub3d9\uc601\uc0c1\uc740 <code>multipart\/form-data<\/code> \ub77c\ub294 \ubcc4\ub3c4 \uc778\ucf54\ub529\uc73c\ub85c \uc804\uc1a1. JSON \ud30c\uc11c\ub85c\ub294 \ubabb \ud480\uace0 \uc804\uc6a9 \ubbf8\ub4e4\uc6e8\uc5b4\uac00 \ud544\uc694. \uadf8 \ud45c\uc900\uc774 <strong>multer<\/strong>.<\/p>\n\n<p>\uc774\ubc88 \ud3b8\uc740 multer \uc758 \ud575\uc2ec \ud328\ud134 \u2014 \uba54\ubaa8\ub9ac\u00b7\ub514\uc2a4\ud06c \uc800\uc7a5 \uc120\ud0dd, MIME \uac80\uc99d, \ud06c\uae30 \uc81c\ud55c, S3 \uc9c1\uc5c5\ub85c\ub4dc\uae4c\uc9c0. \ubcf4\uc548 \uc0ac\uace0\uac00 \uc790\uc8fc \ub098\ub294 \uc601\uc5ed\uc774\ub77c \ub05d\uae4c\uc9c0.<\/p>\n\n<h2>1. \uc124\uce58\uc640 \uac00\uc7a5 \ub2e8\uc21c\ud55c \uc0ac\uc6a9<\/h2>\n\n<div class=\"code-block\">$ npm install multer\n$ npm install -D @types\/multer<\/div>\n\n<div class=\"code-block\">\/\/ server.js\nimport express from &#8216;express&#8217;;\nimport multer from &#8216;multer&#8217;;\n\nconst app = express();\nconst upload = multer({ dest: &#8216;uploads\/&#8217; });\n\napp.post(&#8216;\/upload&#8217;, upload.single(&#8216;photo&#8217;), (req, res) =&gt; {\n  console.log(req.file);\n  \/\/ {\n  \/\/   fieldname: &#8216;photo&#8217;,\n  \/\/   originalname: &#8216;cat.jpg&#8217;,\n  \/\/   mimetype: &#8216;image\/jpeg&#8217;,\n  \/\/   destination: &#8216;uploads\/&#8217;,\n  \/\/   filename: &#8216;8f3a1c2e9b4d5&#8230;&#8217;,\n  \/\/   path: &#8216;uploads\/8f3a1c2e9b4d5&#8230;&#8217;,\n  \/\/   size: 154823\n  \/\/ }\n  res.json({ url: `\/uploads\/${req.file.filename}` });\n});<\/div>\n\n<p>HTML \ud3fc\uc740 <code>enctype=\"multipart\/form-data\"<\/code> \ud544\uc218. <code>upload.single('photo')<\/code> \uac00 \ubbf8\ub4e4\uc6e8\uc5b4\ub85c \ub07c\uc5b4\ub4e4\uc5b4 multipart \ub97c \ud30c\uc2f1\ud558\uace0 <code>req.file<\/code> \uc5d0 \uacb0\uacfc\ub97c \ubc15\ub294\ub2e4.<\/p>\n\n<h2>2. \uc800\uc7a5 \ubc29\uc2dd \u2014 memoryStorage vs diskStorage<\/h2>\n\n<div class=\"tablewrap\">\n<table>\n<thead><tr><th>\ubc29\uc2dd<\/th><th>\uc7a5\uc810<\/th><th>\ub2e8\uc810<\/th><th>\uc6a9\ub3c4<\/th><\/tr><\/thead>\n<tbody>\n<tr><td>diskStorage (\uae30\ubcf8)<\/td><td data-label=\"\uc7a5\uc810\">\ud070 \ud30c\uc77c\ub3c4 \uba54\ubaa8\ub9ac \uc548\uc804<\/td><td data-label=\"\ub2e8\uc810\">\ub514\uc2a4\ud06c IO, \uc784\uc2dc \uc815\ub9ac \ud544\uc694<\/td><td data-label=\"\uc6a9\ub3c4\">\uc11c\ubc84 \ub85c\uceec \uc800\uc7a5<\/td><\/tr>\n<tr><td>memoryStorage<\/td><td data-label=\"\uc7a5\uc810\">\ube60\ub984, \uc989\uc2dc \ucc98\ub9ac \uac00\ub2a5<\/td><td data-label=\"\ub2e8\uc810\">\ud070 \ud30c\uc77c\uc740 \uba54\ubaa8\ub9ac \ud3ed\ubc1c<\/td><td data-label=\"\uc6a9\ub3c4\">S3\u00b7CDN \uc989\uc2dc \uc5c5\ub85c\ub4dc<\/td><\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n\n<p>S3 \uac19\uc740 \uc678\ubd80 \uc2a4\ud1a0\ub9ac\uc9c0\ub85c \ubc14\ub85c \ubcf4\ub0bc \uac70\uba74 \ub514\uc2a4\ud06c\uc5d0 \uc548 \uc4f0\ub294 \uac8c \uae54\ub054. <code>memoryStorage<\/code> \uba74 <code>req.file.buffer<\/code> \uc5d0 11\ud3b8\uc758 Buffer \uac1d\uccb4\uac00 \ud1b5\uc9f8\ub85c \ub2f4\uae34\ub2e4.<\/p>\n\n<div class=\"code-block\">\/\/ memoryStorage \u2014 \uc989\uc2dc S3 \uc5c5\ub85c\ub4dc\nconst upload = multer({ storage: multer.memoryStorage() });\n\napp.post(&#8216;\/upload-s3&#8217;, upload.single(&#8216;photo&#8217;), async (req, res) =&gt; {\n  const result = await s3.putObject({\n    Bucket: &#8216;my-bucket&#8217;,\n    Key: `${Date.now()}-${req.file.originalname}`,\n    Body: req.file.buffer,           \/\/ \u2190 Buffer \uc9c1\uc811\n    ContentType: req.file.mimetype,\n  });\n  res.json({ url: `https:\/\/my-bucket.s3&#8230;\/${result.Key}` });\n});<\/div>\n\n<h2>3. \uac80\uc99d \u2014 MIME \uacfc \ud06c\uae30 \uc81c\ud55c (\ubcf4\uc548 \ud544\uc218)<\/h2>\n\n<p>\uc5c5\ub85c\ub4dc\ub294 \ubcf4\uc548 \uc0ac\uace0 1\uc21c\uc704. \uac80\uc99d \uc5c6\uc774 \ubc1b\uc73c\uba74 \uace7 \uc0ac\uace0.<\/p>\n\n<div class=\"code-block\">const upload = multer({\n  storage: multer.diskStorage({\n    destination: &#8216;uploads\/&#8217;,\n    filename: (req, file, cb) =&gt; {\n      \/\/ \uc6d0\ubcf8 \uc774\ub984 \uadf8\ub300\ub85c \uc4f0\uba74 \uc704\ud5d8. \ub79c\ub364 + \ud655\uc7a5\uc790\ub9cc \uc2e0\ub8b0\n      const ext = path.extname(file.originalname).toLowerCase();\n      cb(null, `${Date.now()}-${crypto.randomUUID()}${ext}`);\n    },\n  }),\n\n  limits: {\n    fileSize: 5 * 1024 * 1024,    \/\/ 5MB \uc0c1\ud55c\n    files: 5,                     \/\/ \ub3d9\uc2dc 5\uac1c \uc0c1\ud55c\n  },\n\n  fileFilter: (req, file, cb) =&gt; {\n    const ok = [&#8216;image\/jpeg&#8217;, &#8216;image\/png&#8217;, &#8216;image\/webp&#8217;].includes(file.mimetype);\n    if (!ok) return cb(new Error(&#8216;\uc774\ubbf8\uc9c0 \ud30c\uc77c\ub9cc \uac00\ub2a5&#8217;));\n    cb(null, true);\n  },\n});<\/div>\n\n<div class=\"warnbox\">\n<strong>\ucd5c\uc545\uc758 \uc2e4\uc218 4\uac00\uc9c0<\/strong> \u2014 \u2460 \uc6d0\ubcf8 \ud30c\uc77c\uba85 \uadf8\ub300\ub85c \uc800\uc7a5(<code>..\/..\/etc\/passwd<\/code> path traversal), \u2461 \ud06c\uae30 \uc81c\ud55c \uc548 \ub460(\ub514\uc2a4\ud06c \uac00\ub4dd), \u2462 MIME \uc548 \uac80\uc99d(.php \uc5c5\ub85c\ub4dc \ud6c4 \uc2e4\ud589), \u2463 \uc815\uc801 \ud3f4\ub354 \uacf5\uac1c(\uc5c5\ub85c\ub4dc \ud3f4\ub354\uac00 \uc11c\ube59\ub418\uc5b4 \uc545\uc131 \ud30c\uc77c \ub2e4\uc6b4\ub85c\ub4dc). 4\uac1c \ub2e4 \ud55c \uc904 \ud55c \uc904 \ub2e4 \ub9c9\uc544\uc57c.\n<\/div>\n\n<h2>4. \uc5ec\ub7ec \ud30c\uc77c \u2014 array\u00b7fields<\/h2>\n\n<div class=\"code-block\">\/\/ \uac19\uc740 \uc774\ub984\uc73c\ub85c \uc5ec\ub7ec \uac1c\napp.post(&#8216;\/photos&#8217;, upload.array(&#8216;photos&#8217;, 10), (req, res) =&gt; {\n  console.log(req.files); \/\/ \ubc30\uc5f4\n  res.json({ count: req.files.length });\n});\n\n\/\/ \uc11c\ub85c \ub2e4\ub978 \uc774\ub984\uc758 \ud30c\uc77c\ub4e4\napp.post(&#8216;\/profile&#8217;, upload.fields([\n  { name: &#8216;avatar&#8217;,  maxCount: 1 },\n  { name: &#8216;banner&#8217;,  maxCount: 1 },\n  { name: &#8216;gallery&#8217;, maxCount: 5 },\n]), (req, res) =&gt; {\n  console.log(req.files);\n  \/\/ { avatar: [{&#8230;}], banner: [{&#8230;}], gallery: [{&#8230;}, &#8230;] }\n});<\/code><\/div>\n\n<p>\uc2e4\uc804\uc5d0\uc120 <code>fields<\/code> \uac00 \uc790\uc8fc \u2014 \ud504\ub85c\ud544 \ud398\uc774\uc9c0\ucc98\ub7fc \ub2e4\ub978 \uc885\ub958 \ud30c\uc77c \ubb36\uc74c.<\/p>\n\n<h2>5. \uc5d0\ub7ec \ucc98\ub9ac \u2014 Multer \uc804\uc6a9 \uc5d0\ub7ec<\/h2>\n\n<p>\ud06c\uae30 \ucd08\uacfc\u00b7\ud544\ud130 \uac70\ubd80 \uc2dc <code>MulterError<\/code> \uac00 throw. 14\ud3b8 \uc5d0\ub7ec \ubbf8\ub4e4\uc6e8\uc5b4\uc5d0\uc11c \ubd84\uae30.<\/p>\n\n<div class=\"code-block\">\/\/ \uc5d0\ub7ec \ud578\ub4e4\ub7ec (\ub77c\uc6b0\ud2b8 \ub4a4\uc5d0)\napp.use((err, req, res, next) =&gt; {\n  if (err instanceof multer.MulterError) {\n    if (err.code === &#8216;LIMIT_FILE_SIZE&#8217;) {\n      return res.status(413).json({ error: &#8216;\ud30c\uc77c\uc774 \ub108\ubb34 \ud07d\ub2c8\ub2e4 (5MB \uc774\ud558)&#8217; });\n    }\n    return res.status(400).json({ error: err.message });\n  }\n  \/\/ \uadf8 \uc678 \uc5d0\ub7ec\n  next(err);\n});<\/code><\/div>\n\n<p>\ud2b9\ud788 <strong>LIMIT_FILE_SIZE<\/strong> \uac00 \ud754\ud558\ub2e4. \uc0ac\uc6a9\uc790\uc5d0\uac8c \uce5c\uc808\ud55c \uba54\uc2dc\uc9c0\ub85c \ubcc0\ud658.<\/p>\n\n<div class=\"databox\">\n<strong>\uc2e4\uc804 \u2014 \uac70\uc758 \ud56d\uc0c1 S3\u00b7R2 \uc9c1\uc5c5\ub85c\ub4dc<\/strong> \u2014 \uc11c\ubc84\ub97c \uac70\uce58\uba74 \uba54\ubaa8\ub9ac\u00b7\ub300\uc5ed\ud3ed \ub0ad\ube44. \ud074\ub77c\uc774\uc5b8\ud2b8\uac00 <strong>S3 presigned URL<\/strong> \ubc1b\uc544 \ube0c\ub77c\uc6b0\uc800\uc5d0\uc11c \uc9c1\uc811 \uc5c5\ub85c\ub4dc \u2192 \ub05d\ub09c \ub4a4 \uc11c\ubc84\uc5d0 \uc54c\ub9bc. \uc11c\ubc84\ub294 URL \ubc1c\uae09\uacfc \uba54\ud0c0\ub370\uc774\ud130\ub9cc. \ud68c\uc0ac \ucf54\ub4dc 90% \uac00 \uc774 \ubc29\uc2dd. multer \ub294 \uc774\uac78 \ubabb \ud558\ub294 \uc791\uc740 \ud504\ub85c\uc81d\ud2b8\u00b7\ub0b4\ubd80 \ub3c4\uad6c\uc6a9.\n<\/div>\n\n<h3>\uc694\uc57d \u2014 20\ud3b8 \uc88c\ud45c<\/h3>\n\n<p>\uc5ec\uae30\uae4c\uc9c0 \uc815\ub9ac. <code>npm i multer<\/code> + <code>upload.single\/array\/fields<\/code>. \uc800\uc7a5\uc740 <code>diskStorage<\/code>(\ub85c\uceec) \ub610\ub294 <code>memoryStorage<\/code>(S3 \uc9c1\ud589). <strong>4\uac00\uc9c0 \ubcf4\uc548 \ud544\uc218<\/strong> \u2014 \ub79c\ub364 \ud30c\uc77c\uba85\u00b7\ud06c\uae30 \uc81c\ud55c\u00b7MIME \uac80\uc99d\u00b7\uc5c5\ub85c\ub4dc \ud3f4\ub354 \ube44\uacf5\uac1c. \uc5ec\ub7ec \ud30c\uc77c\uc740 <code>array<\/code>\u00b7<code>fields<\/code>. <code>MulterError<\/code> \ubd84\uae30\ub85c \uc0ac\uc6a9\uc790 \uce5c\ud654 \uba54\uc2dc\uc9c0. \uc2e4\uc804 \uad8c\uc7a5\uc740 <strong>S3 presigned URL \uc9c1\uc5c5\ub85c\ub4dc<\/strong>. \ub2e4\uc74c \ud3b8\uc5d0\uc11c \ub85c\uadf8 \u2014 <strong>winston\u00b7morgan<\/strong>.<\/p>\n\n<div class=\"cta\">\n<h3>\ub2e4\uc74c \ud3b8 \uc608\uace0 \u2014 \ub85c\uae45<\/h3>\n<p>winston\u00b7morgan \uc73c\ub85c \uc11c\ubc84 \ub85c\uadf8 \uad00\ub9ac. 21\ud3b8.<\/p>\n<\/div>\n\n<div class=\"footer-nav\">\n\uc2dc\ub9ac\uc988 \u00b7 <a href=\"https:\/\/junai.ai\/blog\/category\/nodejs\/\">\uc27d\uac8c \ubc30\uc6b0\ub294 Node.js<\/a> \u00b7 \uc774\uc804: <a href=\"https:\/\/junai.ai\/blog\/nodejs-auth-jwt-19\/\">Ch.19 JWT \uc778\uc99d<\/a>\n<\/div>\n\n<\/article>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Express multer \ub85c multipart \ud30c\uc77c \uc5c5\ub85c\ub4dc \u2014 \uba54\ubaa8\ub9ac\u00b7\ub514\uc2a4\ud06c \uc800\uc7a5, MIME \uac80\uc99d, \ud06c\uae30 \uc81c\ud55c, \uc5ec\ub7ec \ud30c\uc77c, S3 \uc9c1\uc5c5\ub85c\ub4dc. \uad50\uc7ac 20\ud3b8.<\/p>\n","protected":false},"author":1,"featured_media":854,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24],"tags":[],"class_list":["post-907","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nodejs"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/posts\/907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/comments?post=907"}],"version-history":[{"count":0,"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/posts\/907\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/media\/854"}],"wp:attachment":[{"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/media?parent=907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/categories?post=907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/junai.ai\/blog\/wp-json\/wp\/v2\/tags?post=907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}