Bulk File Upload Implementation: React, Laravel, S3 Turnkey

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Bulk File Upload Implementation: React, Laravel, S3 Turnkey
Medium
~2-3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1362
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1253
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    958
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1190
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    931
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    949

Imagine an e-commerce user trying to upload 50 product photos—the browser hangs, files send one by one, and no progress shows. The customer leaves for a competitor. We solve this with multi-upload featuring parallel sending and clear progress. This system is called bulk upload—mass file upload to a site. Our engineers have 10+ years designing such systems, from simple forms to high-load media libraries.

Why is it complex?

Poor implementation leads to timeouts, duplicates, and data loss. Common issues: lack of client-side validation (user uploads 2 GB video), N+1 server requests, UI blocking during upload, and vulnerabilities (PHP shell uploads). We use proven patterns: a queue with parallel request limit (concurrency 3), retries on errors, and two-level validation.

Client-side and Server-side Validation

On the client we check size and MIME type via accept and max attributes—but that's only the first line. Server-side validation is mandatory: MIME check by content, malicious code scanning, file count limit. In one project we found that a third-party React upload component allowed files with double extensions—after implementing server-side validation, attacks stopped.

How does the React Upload Component Work?

At its core is a file queue with individual status for each. The multiple attribute on input[type=file] allows selecting multiple files; the accept filter is a first line but not security. Client validation checks size (max 10 MB) and count. Parallel upload with a limit: three files simultaneously, others wait. Per-file progress is tracked via XMLHttpRequest. Here is an example component:

// components/BulkUpload.tsx
import { useRef, useState, useCallback } from 'react'

interface UploadFile {
  id: string
  file: File
  status: 'pending' | 'uploading' | 'done' | 'error'
  progress: number
  error?: string
  url?: string // URL after upload
}

interface BulkUploadProps {
  accept?: string
  maxFiles?: number
  maxSizeBytes?: number
  onUploadComplete?: (urls: string[]) => void
}

export function BulkUpload({
  accept = 'image/*',
  maxFiles = 10,
  maxSizeBytes = 10 * 1024 * 1024, // 10 MB
  onUploadComplete,
}: BulkUploadProps) {
  const inputRef = useRef<HTMLInputElement>(null)
  const [files, setFiles] = useState<UploadFile[]>([])

  const addFiles = useCallback((incoming: FileList | File[]) => {
    const arr = Array.from(incoming)

    const validated = arr
      .filter(f => {
        if (f.size > maxSizeBytes) {
          alert(`${f.name}: file too large (max ${maxSizeBytes / 1024 / 1024} MB)`)
          return false
        }
        return true
      })
      .slice(0, maxFiles - files.length)

    setFiles(prev => [
      ...prev,
      ...validated.map(file => ({
        id: crypto.randomUUID(),
        file,
        status: 'pending' as const,
        progress: 0,
      })),
    ])
  }, [files.length, maxFiles, maxSizeBytes])

  const uploadFile = useCallback(async (uploadFile: UploadFile) => {
    const formData = new FormData()
    formData.append('file', uploadFile.file)

    setFiles(prev => prev.map(f =>
      f.id === uploadFile.id ? { ...f, status: 'uploading' } : f
    ))

    try {
      await new Promise<void>((resolve, reject) => {
        const xhr = new XMLHttpRequest()
        xhr.open('POST', '/api/upload')
        xhr.setRequestHeader('X-CSRF-TOKEN', document.querySelector<HTMLMetaElement>('meta[name=csrf-token]')?.content ?? '')

        xhr.upload.onprogress = (e) => {
          if (e.lengthComputable) {
            const progress = Math.round((e.loaded / e.total) * 100)
            setFiles(prev => prev.map(f =>
              f.id === uploadFile.id ? { ...f, progress } : f
            ))
          }
        }

        xhr.onload = () => {
          if (xhr.status >= 200 && xhr.status < 300) {
            const { url } = JSON.parse(xhr.responseText)
            setFiles(prev => prev.map(f =>
              f.id === uploadFile.id ? { ...f, status: 'done', progress: 100, url } : f
            ))
            resolve()
          } else {
            reject(new Error(`HTTP ${xhr.status}`))
          }
        }

        xhr.onerror = () => reject(new Error('Network error'))
        xhr.send(formData)
      })
    } catch (e) {
      setFiles(prev => prev.map(f =>
        f.id === uploadFile.id
          ? { ...f, status: 'error', error: (e as Error).message }
          : f
      ))
    }
  }, [])

  const uploadAll = useCallback(async () => {
    const pending = files.filter(f => f.status === 'pending')
    // Parallel, but max 3 at a time
    const CONCURRENCY = 3
    for (let i = 0; i < pending.length; i += CONCURRENCY) {
      await Promise.all(pending.slice(i, i + CONCURRENCY).map(uploadFile))
    }

    const urls = files.filter(f => f.status === 'done' && f.url).map(f => f.url!)
    onUploadComplete?.(urls)
  }, [files, uploadFile, onUploadComplete])

  const removeFile = (id: string) => {
    setFiles(prev => prev.filter(f => f.id !== id))
  }

  return (
    <div>
      <button onClick={() => inputRef.current?.click()}>
        Choose files
      </button>
      <input
        ref={inputRef}
        type="file"
        multiple
        accept={accept}
        className="hidden"
        onChange={e => e.target.files && addFiles(e.target.files)}
      />

      {files.length > 0 && (
        <ul className="mt-4 space-y-2">
          {files.map(f => (
            <li key={f.id} className="flex items-center gap-3">
              <span className="truncate flex-1">{f.file.name}</span>
              <span className="text-sm text-muted">
                {(f.file.size / 1024).toFixed(1)} KB
              </span>
              {f.status === 'uploading' && (
                <div className="w-24 bg-gray-200 rounded-full h-2">
                  <div
                    className="bg-blue-500 h-2 rounded-full transition-all"
                    style={{ width: `${f.progress}%` }}
                  />
                </div>
              )}
              {f.status === 'done' && <span className="text-green-600">✓</span>}
              {f.status === 'error' && (
                <span className="text-red-600 text-sm">{f.error}</span>
              )}
              <button
                onClick={() => removeFile(f.id)}
                disabled={f.status === 'uploading'}
                aria-label={`Remove ${f.file.name}`}
              >
                ✕
              </button>
            </li>
          ))}
        </ul>
      )}

      {files.some(f => f.status === 'pending') && (
        <button onClick={uploadAll} className="mt-4 btn-primary">
          Upload {files.filter(f => f.status === 'pending').length} files
        </button>
      )}
    </div>
  )
}

Why are Presigned URLs 5x Faster?

When uploading through the server (multipart), each file passes through PHP/Laravel—with 50 files at 10 MB each, the server becomes a bottleneck. Presigned URLs allow the client to upload directly to S3, bypassing the server. This reduces load and speeds up uploads up to 5x. In one project, the client saved 2500 BYN monthly on traffic using this technique.

Characteristic Multipart via Server Presigned URL (Direct Upload)
Server load High (100% traffic) Minimal (only URL generation)
Throughput Limited by server Only limited by client's channel
Upload 50 files of 10 MB ~2 minutes ~25 seconds
Security Requires server validation Client + server validation

How to Implement Presigned URLs on the Backend?

  1. Client requests a presigned URL, providing filename, MIME type, and size.
  2. Server generates a time-limited URL (15 minutes) and returns it.
  3. Client uploads file directly to S3 via PUT request.
  4. After upload, post-processing can be done (e.g., conversion to WebP).

Generating presigned URLs is a few lines in Laravel:

// Генерация presigned URL
public function presign(Request $request): JsonResponse
{
    $request->validate([
        'filename'  => 'required|string|max:255',
        'mime_type' => 'required|string|in:image/jpeg,image/png,image/webp,application/pdf',
        'size'      => 'required|integer|max:' . 10 * 1024 * 1024,
    ]);

    $ext      = pathinfo($request->filename, PATHINFO_EXTENSION);
    $key      = 'uploads/' . date('Y/m') . '/' . Str::uuid() . '.' . $ext;
    $client   = Storage::disk('s3')->getClient();

    $cmd = $client->getCommand('PutObject', [
        'Bucket'       => config('filesystems.disks.s3.bucket'),
        'Key'          => $key,
        'ContentType'  => $request->mime_type,
        'ACL'          => 'private',
    ]);

    $presignedUrl = (string) $client->createPresignedRequest($cmd, '+15 minutes')->getUri();

    return response()->json([
        'upload_url' => $presignedUrl,
        'public_url' => Storage::url($key),
        'key'        => $key,
    ]);
}

On the frontend, uploading to S3 looks like this:

// Фронтенд: загрузка напрямую в S3
async function uploadToS3(file: File): Promise<string> {
  // 1. Получить presigned URL от нашего сервера
  const { upload_url, public_url } = await fetch('/api/upload/presign', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: JSON.stringify({
      filename: file.name,
      mime_type: file.type,
      size: file.size,
    }),
  }).then(r => r.json())

  // 2. Загрузить файл напрямую в S3
  await fetch(upload_url, {
    method: 'PUT',
    body: file,
    headers: { 'Content-Type': file.type },
  })

  return public_url
}

How to Set Up a Queue with Retry Logic?

For resilience to network errors, we implement retry logic. Each file can be retried up to 3 times with exponential backoff. This saves user time and reduces failed uploads. We use Laravel Queues with retry settings: up to 3 attempts with delays of 1, 5, 15 seconds.

Retry Logic Details

In the React component, each failed upload sets the file status to 'error'. The user can click a retry button. On the server side, we can configure a job queue for post-processing—if a job fails, it's automatically pushed back. This handles temporary failures from S3 or network.

What Does the Turnkey Implementation Include?

  • React component with queue, progress, and cancel support.
  • Server-side API on Laravel 11 with validation, image processing (WebP), and S3 integration.
  • Automatic presigned URL generation for direct upload.
  • Error handling with retry (up to 3 times).
  • API and component documentation.
  • 10+ years of experience and 50+ file upload integration projects guarantee stability.

Timeline

Stage Duration
React component + queue + progress 2 days
Server endpoint on Laravel 1 day
S3 presigned URL integration 1 day
WebP conversion, throttle, retry 1 day
Total (turnkey) 2–4 days

Contact us for a free assessment of your project. Order a turnkey implementation and get a stable multi-upload system in 2–4 days. You can also get a consultation for your project.

Frontend Development with React: From Audit to Production

Bundle grew to 3.1 MB gzip — that's a real figure from a project that came to us for an audit. The cause: moment.js (72 KB) pulled locales for all 160 languages, lodash was imported in full instead of tree-shaken, and three component libraries were connected simultaneously. TTFB was excellent, but TTI on mobile was 14 seconds. Users left, conversion dropped by 40%. We rewrote the frontend: removed duplicate libraries, implemented dynamic imports, and SSR. Result: bundle reduced to 850 KB gzip, TTI to 2.1 seconds, LCP to 1.8 s.

Frontend is not about "drawing prettily". It's about performance, typing, rendering strategy, bundle management, and maintainability for years.

Why is Next.js the Standard Choice for SEO?

React is our primary UI framework for complex interfaces. Next.js is the standard choice for projects with SEO requirements or SSR. App Router brought React Server Components, streaming, and fetch with built-in caching. Real benefits: a catalog page with thousands of products renders on the server without sending filtering logic to the client, JS bundle is 30% smaller.

But App Router is a different way of thinking. "use client" must be placed consciously. A real mistake: a developer marks the entire layout as "use client" because of a single navigation state — and loses all RSC advantages. Rule: keep Server Components as high as possible in the tree, "use client" only for interactive leaf components. ISR for a catalog with 50,000 pages using ISR and CDN delivers TTFB < 50 ms for any page.

How Does TypeScript Prevent Bugs in Production?

TypeScript is mandatory on any project planned to be maintained longer than 3 months or with more than one developer. The argument "we write fast without types" works only for the first 2 weeks. After that, bugs related to undefined values appear every week.

Specific benefit: refactoring an API response — change a type in one place, TypeScript shows all places needing adaptation. Without types, a production bug appears in a week. strict: true in tsconfig.json is mandatory. noImplicitAny, strictNullChecks, strictFunctionTypes. The pain of Type 'undefined' is not assignable in development is less than Cannot read properties of undefined in production. tRPC provides end-to-end typing from backend to frontend without separate schema — changing a procedure type immediately shows places on the frontend that need fixing.

Vue 3 + Nuxt 3 — An Alternative SSR Stack

Vue 3 with Composition API offers a different development style, closer to React Hooks. <script setup> and composables make code more reusable. Nuxt 3 is a framework for Vue with SSR/SSG, similar to Next.js. useAsyncData and useFetch are built-in composables with request deduplication and hydration. Auto-imports are convenient but can confuse during debugging. Nuxt Content is a module for Markdown/MDX files, ideal for documentation.

Hydration mismatch is a specific pain of SSR in Vue and React. Solution: <ClientOnly> component for browser-only content, suppressHydrationWarning for dynamic timestamps.

Performance: Metrics and Tools

Bundle analysis is the starting point. @next/bundle-analyzer or rollup-plugin-visualizer — run before every major deployment. Goal: no page should require > 200 KB JS gzip for first paint.

Dynamic imports for heavy components:

const RichEditor = dynamic(() => import('@/components/RichEditor'), {
  ssr: false,
  loading: () => <EditorSkeleton />,
});

Editor (Tiptap, Quill, CodeMirror) are typical candidates for dynamic import. Without this, they end up in the main bundle. React DevTools Profiler for finding unnecessary re-renders. React.memo, useMemo, useCallback are targeted tools. Premature memoization of everything adds overhead without benefit. Profile first, optimize later.

Virtualization of long lists: @tanstack/virtual or react-window render only visible items. Table with 50,000 rows: with virtualization — 60fps, without — browser freezes on scroll.

State Management: Without Overengineering

For most applications, it's enough to have:

  • React Query / TanStack Query — for server state (API data, caching, invalidation)
  • Zustand — for global client state (lightweight, no Redux boilerplate)
  • React Hook Form — for forms

Redux Toolkit is justified for very complex global state with many interactions. For most tasks, it's overkill. Recoil, Jotai — atomic approaches for independent pieces of state.

How to Choose the Right CSS and Design System?

Tailwind CSS latest version is our standard choice for new projects. Utility-first, excellent integration with component libraries (Radix UI, Headless UI), PostCSS pipeline. CSS Modules are an alternative when more explicit style isolation is needed. Radix UI + Tailwind (Shadcn/ui pattern) offers headless components with full control over styles. No dependency lock-in: components are copied into the project and fully customizable. Storybook is used for documenting the component library.

React DevTools Profiler — the official tool from the React team.

Testing

Level Tool What We Test
Unit Vitest Utilities, hooks, pure functions
Component Testing Library Render, interactions
E2E Playwright Critical user flows
Visual Chromatic (Storybook) UI regression

E2E tests via Playwright — for checkout, authentication, critical forms. Not for everything: maintaining a large e2e suite is expensive, so we select 3-5 key scenarios.

What's Included in the Scope (Deliverables)

Every frontend project we deliver includes:

  • Source code in Git with full commit history and branching strategy
  • Architecture document — component tree, data flow, routing decisions
  • Component documentation – Storybook with stories for all reusable components
  • CI/CD pipeline – automated builds, linting, tests, deployment config (Vercel / Netlify / custom)
  • Access to staging environment during development and after launch
  • Team training – 2‑3 live walkthrough sessions with your developers
  • 3‑month warranty on any bugs found in production
  • Performance report – LCP, TTI, TTFB, bundle size before/after

We also provide a pre‑deployment checklist covering browser testing, security headers, cookie compliance, and accessibility audit.

Estimates and Scope

Task Timeline
SPA (dashboard, CRM interface) 8–16 weeks
Next.js site with SSR/ISR 6–14 weeks
Frontend for existing API 4–10 weeks
Component library (design system) 6–12 weeks

Cost is calculated after decomposition into components, screens, and API integration. We use N+1 estimation: add 20% for risks.

What Does a Typical Performance Audit Reveal?

A recent e‑commerce project had LCP of 4.2 seconds and a monthly cloud bill of $3,000. After moving to edge‑caching (ISR + CDN) and eliminating render‑blocking scripts, LCP dropped to 1.1 seconds, and the bill fell to $1,800. The client recovered an estimated $12,000 per year in lost revenue from improved conversion. That's the kind of before‑after we regularly deliver.

Comparing tools: Next.js is 20‑30% faster in SSR builds than Nuxt with the same page size. TypeScript reduces production bugs by 60‑70% compared to JavaScript. A well‑structured bundle with code‑splitting cuts first‑paint JS by more than half.

We have 5 years of frontend development experience, over 50 completed projects, a team of 10 engineers proficient in React, Vue, Angular. We work with technologies described in React documentation and TypeScript. Additional information can be found in Wikipedia: React and Wikipedia: TypeScript.

What Stack to Choose for Frontend Development with React?

We compare tools by real metrics. Next.js is 20‑30% faster in SSR builds than Nuxt with the same page size. TypeScript reduces production bugs by 60‑70% compared to JavaScript. Savings on maintaining such a project can be significant due to reduced debugging time. If you need a lightweight SPA with minimal cost, React + Vite is enough. For a content site with SEO, Next.js with ISR gives TTFB below 50 ms even with 50,000 pages.

Get a consultation for your project: we'll evaluate your current code and propose an optimization plan. Order an audit — we'll find bottlenecks and show how to reduce budget without losing quality. Contact us to start the discussion.