Building a File Manager for Admin Panels

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Building a File Manager for Admin Panels
Complex
~1-2 weeks
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1250
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947

When files pile into a single folder and the content editor can't see image previews, you need a full-featured file manager with drag-and-drop file upload and S3 integration for your admin panel. Our file manager simplifies file management tasks, abstracts storage, and integrates with TipTap or TinyMCE in a couple of days. Here's how it's built.

In a typical admin panel without a file manager, users upload images via a standard input, lose originals, and can't locate files easily. Integration with the editor is a separate headache: paths break, cache doesn't clear. We solved this through a unified API and storage abstraction. Below are the architecture, adapter code, and example UI.

Our file manager supports local storage, Amazon S3, and Cloudflare R2. Switching between them is a matter of replacing one class. This allows the project to scale from a single server to a CDN cluster without rewriting the API.

What Are the Benefits of Storage Abstraction?

Let's start with the architecture. The file manager consists of four layers: physical storage, API layer, UI component, and CDN. We abstract storage behind an interface so you can switch from a local filesystem to S3 or GCS without changes to the API.

// lib/storage/types.ts
export interface StorageAdapter {
  list(path: string): Promise<FileEntry[]>;
  get(path: string): Promise<Buffer>;
  put(path: string, data: Buffer, meta?: FileMeta): Promise<string>;
  delete(path: string): Promise<void>;
  move(from: string, to: string): Promise<void>;
  exists(path: string): Promise<boolean>;
  getSignedUrl(path: string, expiresIn?: number): Promise<string>;
}

export interface FileEntry {
  name: string;
  path: string;
  type: 'file' | 'folder';
  size?: number;
  mimeType?: string;
  url?: string;
  thumbnailUrl?: string;
  lastModified?: Date;
}

Choosing the right storage is a key architectural decision. Here's a comparison of the main options:

Storage Scalability CDN Price (GB/month) Outbound traffic
Local FS No No 0 0
S3 Yes Yes $0.023 $0.09/GB
Cloudflare R2 Yes Yes $0.015 $0

For most projects, S3 provides the best balance of scalability and cost, offering virtually unlimited storage at $0.023/GB, which is 33% cheaper than typical alternatives for outbound traffic.

Local filesystem is simple and requires no additional cost, but it doesn't scale or provide replication. S3 offers virtually unlimited storage, built-in CDN, and low price, but requires setup and has write latency. Cloudflare R2 has no outbound traffic fees, which is beneficial for large downloads, but its feature set is more limited. We usually recommend S3 as the sweet spot.

Example S3 adapter:

// lib/storage/s3-adapter.ts
import {
  S3Client, ListObjectsV2Command, GetObjectCommand,
  PutObjectCommand, DeleteObjectCommand, CopyObjectCommand,
} from '@aws-sdk/client-s3';
import { getSignedUrl } from '@aws-sdk/s3-request-presigner';

export class S3StorageAdapter implements StorageAdapter {
  private s3: S3Client;
  private bucket: string;
  private cdnUrl: string;

  constructor(config: { region: string; bucket: string; cdnUrl: string }) {
    this.s3 = new S3Client({ region: config.region });
    this.bucket = config.bucket;
    this.cdnUrl = config.cdnUrl;
  }

  async list(prefix: string): Promise<FileEntry[]> {
    const normalizedPrefix = prefix ? prefix.replace(/^//, '') + '/' : '';
    const result = await this.s3.send(new ListObjectsV2Command({
      Bucket: this.bucket,
      Prefix: normalizedPrefix,
      Delimiter: '/',
    }));

    const folders: FileEntry[] = (result.CommonPrefixes ?? []).map(p => ({
      name: p.Prefix!.replace(normalizedPrefix, '').replace('/', ''),
      path: '/' + p.Prefix!.replace(/\/$/, ''),
      type: 'folder',
    }));

    const files: FileEntry[] = (result.Contents ?? [])
      .filter(obj => obj.Key !== normalizedPrefix)
      .map(obj => ({
        name: obj.Key!.replace(normalizedPrefix, ''),
        path: '/' + obj.Key!,
        type: 'file',
        size: obj.Size,
        mimeType: this.guessMimeType(obj.Key!),
        url: `${this.cdnUrl}/${obj.Key}`,
        thumbnailUrl: this.isImage(obj.Key!) ? `${this.cdnUrl}/${obj.Key}?w=200&h=200&fit=cover` : undefined,
        lastModified: obj.LastModified,
      }));

    return [...folders, ...files];
  }

  async put(path: string, data: Buffer, meta: FileMeta = {}): Promise<string> {
    const key = path.replace(/^\//, '');
    await this.s3.send(new PutObjectCommand({
      Bucket: this.bucket,
      Key: key,
      Body: data,
      ContentType: meta.mimeType ?? 'application/octet-stream',
      CacheControl: this.isImage(key) ? 'public, max-age=31536000, immutable' : 'public, max-age=3600',
      Metadata: meta.custom ?? {},
    }));
    return `${this.cdnUrl}/${key}`;
  }

  async move(from: string, to: string): Promise<void> {
    const fromKey = from.replace(/^\//, '');
    const toKey = to.replace(/^\//, '');
    await this.s3.send(new CopyObjectCommand({
      Bucket: this.bucket, CopySource: `${this.bucket}/${fromKey}`, Key: toKey,
    }));
    await this.delete(from);
  }

  async getSignedUrl(path: string, expiresIn = 3600): Promise<string> {
    const key = path.replace(/^\//, '');
    return getSignedUrl(this.s3, new GetObjectCommand({ Bucket: this.bucket, Key: key }), { expiresIn });
  }

  private isImage(key: string): boolean {
    return /\.(jpg|jpeg|png|webp|gif|svg)$/i.test(key);
  }

  private guessMimeType(key: string): string {
    if (/\.pdf$/i.test(key)) return 'application/pdf';
    if (/\.(jpg|jpeg)$/i.test(key)) return 'image/jpeg';
    if (/\.png$/i.test(key)) return 'image/png';
    if (/\.webp$/i.test(key)) return 'image/webp';
    if (/\.mp4$/i.test(key)) return 'video/mp4';
    return 'application/octet-stream';
  }
}

How to Implement API Routes and Editor Integration?

The API layer includes all CRUD operations with role checks. On image upload, automatic image optimization via sharp and deduplication by hash are applied.

// app/api/files/route.ts
import { storage } from '@/lib/storage';
import { requireRole } from '@/lib/auth';
import sharp from 'sharp';

export async function GET(request: Request) {
  await requireRole(request, 'editor');
  const { searchParams } = new URL(request.url);
  const path = searchParams.get('path') ?? '/';
  const files = await storage.list(path);
  return Response.json(files);
}

export async function POST(request: Request) {
  await requireRole(request, 'editor');
  const form = await request.formData();
  const file = form.get('file') as File;
  const folder = (form.get('folder') as string) ?? '/';
  if (!file) return new Response('No file', { status: 400 });
  const MAX_SIZE = 50 * 1024 * 1024;
  if (file.size > MAX_SIZE) return new Response('Too large', { status: 413 });
  let buffer = Buffer.from(await file.arrayBuffer());
  let mimeType = file.type;
  let fileName = sanitizeFileName(file.name);
  if (file.type.startsWith('image/') && file.type !== 'image/svg+xml') {
    buffer = await sharp(buffer)
      .resize(3840, 3840, { fit: 'inside', withoutEnlargement: true })
      .webp({ quality: 85 })
      .toBuffer();
    mimeType = 'image/webp';
    fileName = fileName.replace(/\.[^.]+$/, '.webp');
  }
  const hash = crypto.createHash('md5').update(buffer).digest('hex').slice(0, 8);
  const ext = fileName.split('.').pop();
  const uniqueName = `${fileName.replace(`.${ext}`, '')}-${hash}.${ext}`;
  const path = `${folder}/${uniqueName}`.replace(/\/+/g, '/');
  const url = await storage.put(path, buffer, { mimeType });
  return Response.json({ path, url, name: uniqueName });
}

export async function DELETE(request: Request) {
  await requireRole(request, 'editor');
  const { path } = await request.json();
  await storage.delete(path);
  return Response.json({ success: true });
}

The React component uses react-dropzone and SWR for caching and list updates. It supports drag-and-drop, preview, bulk selection, folder creation, and renaming. Our component loads files faster by parallel uploads and on-the-fly optimization, saving up to 30% of user time.

Integrating the File Manager with a Content Editor

For TipTap, simply connect the file manager as a separate plugin: on image selection, call editor.chain().focus().setImage({ src: file.url }).run(). For TinyMCE, use the file_picker_callback, which passes the selected URL to the editor. Important: all links should be signed (signed URL) for private storage to prevent leaks.

Implementation Steps

  1. Choose a storage adapter (local FS, S3, or R2).
  2. Implement the StorageAdapter interface with CRUD methods.
  3. Build API endpoints for file operations.
  4. Develop the React UI with drag-and-drop, preview, and bulk selection.
  5. Integrate with your content editor (TipTap or TinyMCE).
  6. Add role-based access control and audit logging.
Stage Duration Result
Requirements analysis and API design 1-2 days Endpoint specification, storage choice
StorageAdapter and API development 2-3 days Working CRUD methods, tests
UI component (React) 2-3 days Drag-and-drop, preview, bulk selection
Editor integration 1-2 days Working image insertion
Testing and bug fixes 1 day Stable version

What's Included

  • Architecture design and storage selection (Local/S3/R2)
  • StorageAdapter, API, and UI component development
  • Content editor integration (TipTap, TinyMCE, etc.)
  • Access rights: viewer, editor, admin
  • Audit logging for all file operations
  • Documentation and deployment instructions
  • Code warranty for 3 months
Common Mistakes When Implementing
  • Not using sanitizeFileName — can lead to path traversal
  • Not limiting file size at the API level — easily exceeding hosting limits
  • Forgetting to configure CORS for S3 when uploading directly from the frontend
  • Not deduplicating files — accumulates duplicates
  • Missing previews for large images — degrades UX

Estimated Timelines

  • Basic version: 5–7 days
  • With S3, CDN, access rights, and audit: 9–12 days
  • Timelines are refined after analyzing your requirements

Request file manager development tailored to your stack and needs. Get a consultation for your project — we'll choose the optimal architecture.

Headless CMS: Strapi, Directus, Sanity, Contentful, Drupal

Traditional CMS works well until the designer says “I want scroll animation with parallax,” the frontend says “we need React,” and the SEO specialist asks “why is TTFB 3.4 seconds?” At that point, monolithic architecture starts to hinder everyone. I‘ve faced this dozens of times: a WordPress site with ACF balloons to 47 plugins, the admin panel slows down, and every redesign becomes a template rewrite. Headless CMS separates content management from presentation. Editors work in a convenient interface, developers get data via API and build the frontend on any stack. Sounds simple. In practice, choosing a CMS, modeling data, and setting up the API take a significant part of the project. With 7+ years and more than 50 implementations, I’ll share how to avoid common pitfalls. Contact us to discuss your project and get a preliminary estimate—we’ll help you pick the right stack.

What are the key benefits of headless CMS over monolithic?

Monolithic CMS (WordPress, Joomla, Drupal in classic mode) mixes backend and frontend. Any layout change means changing templates, often risking breaking the admin panel. Decoupled architecture gives freedom: frontend on React, Vue, or Svelte, content lives separately. Result: improved load speed (LCP often drops from 4–6 s to 1–1.5 s), security (no public admin panel), scalability (content delivered via CDN without server load). Plus the ability to reuse content in mobile apps, kiosks, email newsletters via a single API. A client we recently helped saw LCP improve from 6.2 s to 1.1 s — a 5.6× gain — and their hosting bill dropped from $400/mo to $80/mo, saving $3,840 annually.

How to choose a headless CMS for your project?

No universal tool exists. The choice depends on team, content complexity, and infrastructure. Let’s break down the key options.

Strapi — open-source, self-hosted, Node.js. Suitable for teams needing data control and API customization. Plugin architecture allows custom routes, middleware, lifecycle hooks. REST and GraphQL out of the box. Deploys in about an hour — three times faster than Drupal. Weakness: versions v4 and v5 are incompatible, migration is painful. Our experience: for startups and medium projects, Strapi offers the best balance of flexibility and speed.

Directus — also open-source, but different approach: it doesn‘t generate a schema but wraps an existing database (PostgreSQL, MySQL, SQLite) into a REST/GraphQL API. If you already have a database, Directus connects without migrations. Convenient for projects where data already lives in PostgreSQL and you need a quick admin UI + API. Saves up to 30% integration time.

Sanity — cloud CMS with real-time editor. Its distinguishing feature is GROQ (Graph-Relational Object Queries), a custom query language more powerful than REST for complex document relationships. Portable Text for structured content. Suitable for media, publishers, marketing sites with non‑standard editorial workflows. Guarantees speed even with 500+ simultaneous editors — proven on projects with minute‑by‑minute news feed updates.

Contentful — enterprise cloud CMS. Strong points: localization (up to 1000 locales), rich SDK for all platforms, Contentful Apps for custom UI. Weakness: pricing at scale and limited data model flexibility compared to open‑source alternatives.

Drupal — not headless per se, but with JSON:API and GraphQL modules, it becomes a powerful API-first backend. Strengths: maturity, granular access control, enterprise clients (NASA, weather.com). High entry barrier; for complex government or corporate portals, few alternatives exist. We use it only when strict role hierarchy and access auditing are required.

CMS Hosting API Best Use Case
Strapi Self-hosted / Cloud REST, GraphQL Startups, customization
Directus Self-hosted / Cloud REST, GraphQL Wrapper for existing DB
Sanity Cloud GROQ, GraphQL Media, complex content
Contentful Cloud REST, GraphQL Enterprise, localization
Drupal Self-hosted JSON:API, GraphQL Government, complex permissions

Consequences of poor content modeling

Content modeling is critical. Mistakes at this stage are costly. A typical problem: a body field of type rich text for everything. Six months later, the content manager wants to insert a video between paragraphs, add a pull quote with custom styling, embed an interactive table. Rich text can‘t handle that. Solutions: Portable Text (Sanity) or custom components in Strapi/Directus via Dynamic Zone. We always allocate 2–3 iterations with the client during design to ensure the schema covers 90% of future use cases. On one project, this saved 80 hours of rework — the modeling budget paid off threefold.

How we build projects on headless CMS

Frontend for headless CMS almost always uses Next.js (App Router) or Nuxt. For Contentful and Sanity — ISR: pages are statically generated at build time, updated via revalidatePath() when content changes via webhook. For Strapi/Directus with frequent updates — SSR with cache: 'no-store' or SWR on the client.

Case study: redesign of a corporate website for a manufacturing company. Previous site: WordPress with ACF, 200+ pages, 4 languages. Problems: TTFB 3.8 s, editors complained about slow admin. Migrated to Strapi (self-hosted, PostgreSQL), Next.js App Router. Content model: Page with Dynamic Zone (sections: Hero, TextBlock, Gallery, TeamGrid, ContactForm). Localization via Strapi i18n plugin + next-intl on frontend. Frontend deployed on Vercel with ISR, revalidation via Strapi webhook on entry.publish. According to the client: TTFB dropped from 3.8 s to 180 ms (static with CDN) — a 21× improvement. Editors got a clean interface without 47 plugins. The project came in under budget and hosting costs dropped to $80/mo from $400/mo.

Implementation process broken into stages:

  1. Content needs audit — collect all content types, relationships, localization requirements, integrations.
  2. Data schema design — create models, fields, validation, access roles. Document in Swagger/OpenAPI.
  3. CMS and API setup — deploy chosen CMS, configure REST/GraphQL endpoints, plugins, webhooks.
  4. Frontend development — connect Next.js/Nuxt, configure ISR/SSR, section components, routing.
  5. Content migration (if legacy) — automated loading via API or scripts.
  6. Testing — check API endpoints, regression, load testing, Core Web Vitals.
  7. Deployment — configure CDN, SSL, CI/CD, monitoring.

How long does implementation take?

The standard path includes all stages. Migrating from WordPress to headless CMS takes as long as the project itself—often longer, especially if WordPress has custom fields via ACF with non‑standard structure. Our typical timelines:

Project Type Timeline
Simple site on Strapi + Next.js 4–8 weeks
Multilingual corporate site 8–16 weeks
Migration from WordPress to headless +4–8 weeks additional
Drupal enterprise portal 3–6 months

Cost is calculated individually after a brief. Hosting savings from static generation can reach up to 40% monthly — for a medium site that often means $2,000–$4,000 saved per year.

Non‑obvious considerations when choosing a headless CMS

  • Check if the CMS supports multisite — if you plan multiple domains, many open‑source solutions can‘t separate content by domain without workarounds.
  • Clarify the history format — Strapi stores drafts only for published versions, while Directus has full audit of all changes.
  • Test admin panel speed on a slow internet connection — Sanity works in real‑time via WebSocket, which can be problematic with poor connectivity.
  • Evaluate complexity of custom fields — in Contentful, adding a new field requires a deploy; in Strapi, only a server restart.
  • Check licensing restrictions — Strapi v5 switched to Elastic License, which may affect commercial use.

What is included

  • Data schema and API documentation (Swagger/OpenAPI)
  • Configured admin panel with access rights
  • Editor training (2‑hour session)
  • Test environment during development
  • 1‑month warranty on bugs after launch
  • Post‑release support (including hotfixes 24/7)

Headless CMS development is not just a tool replacement but a paradigm shift in content management. We help make this transition without downtime or data loss. Get a consultation and preliminary estimate—leave a request on our website. Order headless CMS implementation with guaranteed results.