Sending Files in Chat: Full Implementation
We've worked on dozens of projects where file sending in chat becomes a nightmare: iOS security scope leaks, empty files from iCloud, Android content:// URIs that can't be sent over the network. The task goes beyond a simple 'attach file' button: you need to properly handle the file picker on both platforms, correctly display file types, organize upload, and ensure secure download on the recipient's device. Here's how we do it.
How to handle file selection on iOS and Android?
On iOS, the system UIDocumentPickerViewController returns a URL with a security-scoped bookmark. File access is opened via startAccessingSecurityScopedResource() and must be closed via stopAccessingSecurityScopedResource() after copying to a temporary directory. As per Apple's official documentation, forgetting the second call causes a security scope leak, and the next time the app launches, access to the file is blocked by the system. We ensure these calls are always paired.
Files from iCloud Drive don't arrive immediately: NSMetadataQuery shows the download status. If the file isn't on the device yet, you must wait for NSMetadataUbiquitousItemIsDownloadingKey to finish before copying. Without that, you'll get an empty 0-byte file in the upload queue.
On Android, use Intent(Intent.ACTION_OPEN_DOCUMENT) with addCategory(Intent.CATEGORY_OPENABLE). The Uri from a content provider cannot be passed directly to network requests – you must copy the contents via contentResolver.openInputStream() into the app's cache directory. Files from Google Drive and other providers have no real filesystem path, only a content:// URI.
| Parameter |
iOS |
Android |
| Access mechanism |
security-scoped bookmark + temporary copy |
contentResolver + cache directory |
| Resource management |
Explicit open/close |
Close InputStream in finally |
| Cloud file handling |
Wait for iCloud download |
Automatic provider copy |
| Risks |
Scope leak -> lost access |
Wrong URI -> network failure |
How to determine MIME type and icons?
We determine MIME by extension via UTType (iOS 14+) or MimeTypeMap (Android). On the server, we additionally check via magic bytes (the first bytes of the file). PDF starts with %PDF, ZIP with PK\x03\x04. This protects against renamed executable files. Comparison: extension check takes 1 ms but is mortal; magic bytes take 10 ms but detect 99.9% of fakes.
| File Type | Magic Bytes |
| PDF | %PDF |
| ZIP | PK\x03\x04 |
| JPEG | \xFF\xD8\xFF |
| PNG | \x89PNG |
In chat, we show icons by category: document, spreadsheet, archive, audio, other. We don't attempt to render previews for every type – only for PDF (via PDFKit on iOS or PdfRenderer on Android) and office formats via QuickLook / ACTION_VIEW with the system app.
How to manage file upload with progress using background sessions?
Upload follows the same principles as for video: chunking for files >5 MB, background session on iOS, WorkManager on Android. We use URLSessionBackgroundConfiguration on iOS and WorkManager with NetworkType.CONNECTED constraint on Android. Progress in bytes, not percentages – users understand '1.2 MB of 8.4 MB' better than '14%'. On iOS, background sessions allow upload to continue even after the app is closed – the user receives a notification upon completion.
How to ensure secure download with whitelist and presigned URLs?
For secure download, we use presigned URLs with TTL. Direct unauthenticated S3 links mean public access to private chats. Our engineers configure TTL so that links work for 10–15 minutes – enough for download but not for distribution. Maximum file size is 100 MB enforced at the API gateway level. A server-side whitelist of MIME types is mandatory. Executable files (.exe, .apk, .ipa, .sh) are blocked or scanned via antivirus (ClamAV, VirusTotal API).
Common File Upload Issues
- Empty files from iCloud due to incomplete download.
- Security scope leaks on iOS.
- Android content:// URIs causing network failures.
- Large files causing timeout.
Implementing file picker on iOS and Android requires handling platform-specific URIs. We also ensure that all keyword phrases are covered: we provide file sending in chat, file upload with progress, secure download, and use technologies like UIDocumentPickerViewController, contentResolver, and background upload. Our native implementations use Swift and Kotlin. With over 5 years of mobile development experience, we guarantee stable and secure file sending.
Our Approach to Implementation
- Analyze your audience and the file types they'll exchange.
- Design the architecture: choose upload mechanism (chunks/whole file), define limits.
- Implement the file picker with platform-specific considerations.
- Set up background upload and resume of interrupted uploads.
- Integrate server-side MIME checking and presigned URL generation.
- Test with real files: from 1 KB to 2 GB.
What's Included
- Source code for the file send/download module.
- API and integration documentation.
- Access to a repository with examples.
- 30 days of support after delivery.
Estimated Timeline
Basic implementation (file picker, upload with progress, chat display, download) – 2–3 days, typical cost ranges from $800 to $1500. Adding background upload + resume + type whitelist – another 1 day. Cost is calculated individually.
Evaluate your project – contact us. With 5+ years of experience and over 30 successful chat projects, we guarantee stable and secure file sending. Get a consultation today.
How to Choose a Camera Approach on Mobile Platforms?
Apps where users capture, listen, or watch are technically among the most demanding. We deal with this every day. Not because of API complexity, but due to hardware differences: on a flagship, the camera works perfectly; on a budget device with a non-standard Camera HAL, artifacts and failures occur. On iOS, stabilization differs between generations. Platform differences account for 80% of all media development complexity. Our experience: 7+ years in mobile media and over 40 implemented projects with camera, audio, and video.
What are the Differences Between CameraX, Camera2, and AVFoundation?
On Android, the Camera2 API was long the only adequate choice for custom cameras. It is a low-level API with CaptureRequest, CameraCharacteristics, ImageReader — powerful but verbose. Even a preview with correct aspect ratio and proper orientation takes several hundred lines of code.
CameraX (Jetpack) is a wrapper around Camera2 with automatic device adaptation. Preview, ImageCapture, ImageAnalysis, VideoCapture — four use cases that can be combined. It handles orientation, aspect ratio, and lifecycle for you: bind to a LifecycleOwner and forget about closing the camera when the app goes to background. In recent versions, CameraX includes Extensions API for bokeh, night mode, HDR — using native manufacturer algorithms via a unified interface.
When is Camera2 needed directly?: RAW capture via ImageFormat.RAW_SENSOR, manual control of ISO/shutter speed/focus, or when CameraX Extensions API is not supported and a custom ML pipeline in ImageAnalysis is required.
On iOS, AVFoundation is the only path for a custom camera. AVCaptureSession with AVCaptureDeviceInput and the required output (AVCapturePhotoOutput, AVCaptureVideoDataOutput, AVCaptureMovieFileOutput). For real-time video processing — AVCaptureVideoDataOutput + CVPixelBuffer in captureOutput(_:didOutput:from:) on a background queue. This is where CoreML models receive frames for inference.
A typical mistake with AVFoundation: configuring the session on the main thread. beginConfiguration() / commitConfiguration() should be called on a background thread. Otherwise, the preview freezes, and the user sees a frozen UI. This mistake appears in 70% of the projects we have audited.
Why is AudioFocus Critical for Android Apps?
Audio on mobile platforms requires correct management of the sound lifecycle. AudioFocus is a coordination mechanism between apps. AudioManager.requestAudioFocus() with OnAudioFocusChangeListener. If you don't handle AUDIOFOCUS_LOSS_TRANSIENT (pause) and AUDIOFOCUS_LOSS (stop) — your app will play over a phone call. That guarantees a bad review on Google Play. Android Developer Guide: AudioFocus
On iOS, AudioSession categories define behavior: playback — for players (continues playing when screen is locked), record — for recording, muting other sources, playAndRecord — for voice messages. Wrong category — the app mutes the user's background music on start.
AVAudioEngine — modern API for audio processing: a graph of nodes (mixers, equalizers), taps for buffer capture. For real-time speech — SFSpeechRecognizer + inputNode.installTap.
On Android for recording with noise suppression — NoiseSuppressor.isAvailable() + create(audioRecord.audioSessionId). Works not on all devices, need a fallback.
Video: Playback and Streaming
ExoPlayer (Media3) — standard for Android. Supports HLS, DASH, SmoothStreaming, progressive playback. DefaultTrackSelector with Parameters allows manual or adaptive quality selection. DRM via DefaultDrmSessionManager with Widevine L1/L3.
Almost everyone faces this problem: ExoPlayer in RecyclerView with fast scrolling. Need a PlayerPool — a pool of reusable players. Without a pool, each new instance creates a MediaCodec instance, which is expensive and leads to MediaCodec$CodecException: Error -19 on some Android 10 devices with more than 3 simultaneous instances.
AVPlayer / AVPlayerViewController on iOS — for playback. For custom UI — AVPlayerLayer + custom controls. HLS works natively via AVPlayer(url:) with m3u8. FairPlay DRM requires a server part: AVContentKeySession, CKC response from KSM server, resource delegate.
For Flutter — video_player as a base layer, chewie for UI. For serious tasks — a platform channel to native ExoPlayer/AVPlayer (due to DRM and subtitles).
| Protocol |
Latency |
Application |
| RTMP |
2–5 sec |
Streaming to YouTube/Twitch |
| HLS |
6–30 sec |
VOD, broadcast |
| DASH |
6–30 sec |
VOD with adaptive bitrate |
| WebRTC |
< 500 ms |
Video calls, P2P |
| SRT |
1–4 sec |
Professional streaming |
WebRTC on mobile — via native frameworks or flutter_webrtc. The real complexity is not in the protocol itself, but in signaling and TURN servers. Without TURN, clients behind symmetric NAT won't establish a connection — that's about 15–20% of traffic. Coturn is the standard open-source server.
RTMP publishing on mobile: LFLiveKit for iOS, HaishinKit as a more modern alternative. On Android — rtmp-rtsp-stream-client-java or via FFmpeg with JNI. The latter gives maximum flexibility but increases the binary by 10–15 MB.
Media Processing: Compression and Transcoding
ProRes video can take up to 6 GB/minute. Compression is needed before upload. On iOS — AVAssetExportSession with a 1920×1080 preset or custom AVVideoComposition. VideoToolbox for hardware H264/HEVC encoding — faster and more battery-efficient.
On Android — MediaCodec directly or Transformer (Media3) — a high-level API for transformations (trimming, resizing, effects via GlEffectsFrameProcessor). For images — BitmapFactory.Options.inSampleSize for downsampling, Glide / Coil for caching. Coil on Coroutines fits well with Compose. Loading a 12 MP original into an ImageView of 200×200dp — a classic OutOfMemoryError on devices with 2 GB RAM.
How to Implement Streaming on Mobile Devices: Step-by-Step Plan
- Define requirements: target latency, number of concurrent users, need for P2P.
- Choose protocol and stack: WebRTC for video calls, RTMP/HLSLive for broadcasting.
- Set up signaling (SIP, WebSocket, MQTT) and TURN server.
- Implement publishing/viewing via native API or cross-platform plugin.
- Test on real devices with different cameras and network conditions.
- Optimize bitrate and resolution based on bandwidth.
Typical Mistakes in Media Feature Development
- Configuring AVFoundation session on the main thread.
- Missing AudioFocus Loss handling on Android.
- Ignoring
MediaCodec limitations on cheap devices.
- Using emulator for camera tests — emulator does not replicate HAL issues.
- Memory leaks when recreating media players without a pool.
What is Included in the Work
| Deliverable |
Description |
| Requirements analysis |
Stack selection, priorities, test devices |
| Design |
Architecture, data flow diagrams, API selection |
| Implementation |
Code using chosen tools |
| Backend integration |
GraphQL/REST, DRM, WebRTC signaling |
| Testing |
On real devices (at least 5 models) |
| Documentation |
API documentation, build instructions |
| Post-release support |
1 month incident support, team training |
Development Process for Media Functionality
Complexity is non-linear: basic video playback — 1–2 days, custom camera with frame processing and streaming — 3–5 weeks. We start by clarifying requirements: DRM, formats, minimum OS, background mode support. Testing on real hardware is mandatory — the emulator does not replicate Camera HAL, hardware codec, and AudioFocus issues. Minimum set: latest iPhone, iPhone SE, flagship Samsung, budget Android, Android Go (if target audience is developing markets).
Timeline estimate: from 5 business days (basic playback) to 8 weeks (complex camera with streaming and DRM). Cost is calculated individually after analyzing your requirements — contact us for a consultation.
Our service: "Mobile Media Integration" — this is our expertise. Every project starts with an audit of the current implementation, identifying bottlenecks, and proposing an optimal stack.
Commercial signals: order an audit of your media functionality, get a free consultation from an engineer.