Validating an Uploaded CSV File
Validate the upload before reading its rows.
$file = $_FILES["dataset"] ?? null;
$errors = [];
if (!$file || $file["error"] !== UPLOAD_ERR_OK) {
$errors[] = "Choose a CSV file that uploaded successfully.";
}
if ($file && $file["size"] > 2 * 1024 * 1024) {
$errors[] = "The file must be 2 MB or smaller.";
}
$extension = $file ? strtolower(pathinfo($file["name"], PATHINFO_EXTENSION)) : "";
if ($extension !== "csv") {
$errors[] = "The file must use the .csv extension.";
}
A filename or MIME type alone can be misleading. Combine upload status, size, extension, readable content, header and row validation.
Never use the original filename as a server path. Process the temporary upload and store only what the application requires.
Check
Test missing files, oversized files, wrong extensions, empty files and malformed content. Every failure should produce a clear message and must not partially import data.