So youâve configured a Workflow that meets all of your business requirements: youâre scanning all uploads to your website for viruses and malware, making sure the uploads do not contain any NSFW or copyrighted content, andâif the upload is an imageâoptimizing it for delivery. Now what? How do we invoke this workflow?
There are two places Developers need to wire up this workflow:
- When uploading files, we pass the Workflow ID to the Filestack API so it knows to run it
- Optionally, we configure a callback URL that we build to catch the response/result asynchronously
Letâs take a look at the first step: telling Filestackâs API to run the Workflow.
Running a Workflow on File Uploads
What causes a Workflow to run? Specifying the ID of that workflow during upload. For example, when Iâm configuring the File Picker with things like the types of files I want to allow the user to upload, one of the parameters I can pass in includes the Workflow ID:
const client = filestack.init('AeFer9A6sSqGncM97K0qBr');
const options = {
storeTo: {
workflows: ['5057edbf-383d-4d8a-83d8-a93cc973101c']
}
};
picker = client.picker(options);
picker.open();
This Workflow ID is passed as a string inside of an array with a key of âworkflowsâ inside of an object under the storeTo: parameter inside of the options object that is passed to the picker as it is initialized. Thatâs it! I mean, your JavaScript is going to look slightly different than the example I gaveâthatâs my APIKEY and WorkflowID in the example, slightly modified because I donât intend for you to use mine. You will, of course, enter the values that match your account. Thereâs even a handy code generator for you in the Workflows editor on the Filestack Developer Portal website, so you can just click the âPicker configurationâ button in the editor when youâre ready and it will generate that code for you with your own values included automatically.
All of the conditional logic inside of the workflow is configured visually, when Iâm logged in to Filestack.comâs Developer Portal. My code refers to this Workflow by the unique ID, and I donât have to update my code every time I make a change to that Workflow. I can edit the Workflowâs steps, save, and without touching my siteâs code the newly-edited Workflow is run on each upload.
Catch the response/result from a callback
Now, normally a request will patiently await a response, but what about longer-running processes that may need to live a little longer than the user might stay connected? You could really stack up quite a lot of tasks for a file to go through in your Workflow, but your users donât have to sit around waiting for all of that to finish running.
You can configure Webhooks under the âConfigurationâ menu found on the left-hand side of the Developer Portal.
Securing Your Workflows
Before you unleash your virus-detecting, NSFW-filtering, copyright-content-detecting file upload Workflow on the world, you need to secure it. Filestack offers robust security that you can configure in the Developer Portal, and each SDK offers an easy integration with the policy and signature requirements.
A policy says what should happen; a signature says itâs you (and only you) making the request. That seems odd at first, given that you want other people to upload their files. What youâre verifying is the integrity between your code and the Filestack API. Other people will be the ones uploading their files, but theyâll be doing so on your terms.
To create a security policy that allows Workflows to run on your appâs file uploads, navigate over to the Security section in the Developer Portal:
See that âApp Secretâ on the page? No! You donât. Itâs partially masked to really drive home the fact that this is the key to the kingdom here. Your APIKEY and Workflow ID are simply tools that tell the machines what to do. Itâs that App Secret that serves as your secure identifier, and it should only ever be used on the back end where clients canât see it.
Read more about our Policies and Signatures here: https://www.filestack.com/docs/security/policies/#policies-and-signatures
David Liedle is Filestackâs Chief Evangelist. He works remotely in New York City with his wife and son, and their kitty. See more at https://DavidCanHelp.me/
Read More â


