dotnet/aspnetcore · error · Error

FileExtensions validator requires a non-empty "extensions"…

Error message

FileExtensions validator requires a non-empty "extensions" parameter.

What it means

The FileExtensions validator (client-side counterpart for [FileExtensions]) needs an 'extensions' parameter — a comma-separated, dot-prefixed list of allowed extensions (e.g. '.png,.jpg'). Without it the validator cannot build its match regex and throws before evaluating the value. The check runs first so a misconfigured rule fails loudly.

Solutions

  1. Ensure the file input renders data-val-fileextensions-extensions=".png,.jpg" (or your allowed set).
  2. Confirm the C# property has [FileExtensions(Extensions = ".png,.jpg,.gif")] so the tag helper emits the attribute.
  3. If registering the validator manually, pass { extensions: '.png,.jpg' } in params.
  4. Check no HTML sanitizer is stripping data-* attributes from file inputs.

Example fix

<!-- before -->
<input type="file" name="Avatar" data-val="true" data-val-fileextensions="Only images" />
<!-- after -->
<input type="file" name="Avatar" data-val="true" data-val-fileextensions="Only images" data-val-fileextensions-extensions=".png,.jpg,.gif" />
Defensive patterns

Strategy: validation

Validate before calling

function fileExtensionsConfigured(params: any): boolean {
  return !!params && typeof params.extensions === 'string' && params.extensions.length > 0;
}

Type guard

function hasExtensionsParam(p: unknown): p is { extensions: string } {
  return !!p && typeof (p as any).extensions === 'string' && (p as any).extensions.length > 0;
}

Prevention

When it happens

Trigger: Thrown at line 12 when params.extensions is falsy. Occurs when the validator is invoked via a data-val-fileextensions-extensions attribute (or programmatic registration) that is missing or empty.

Common situations: A [FileExtensions(Extensions = ".png,.jpg")] attribute whose client-side data-val-fileextensions-extensions attribute was stripped by a sanitizer or never emitted; a hand-built file input missing the data-val attribute; tag helper misconfiguration on the input tag.

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/ab50cb4ecc602f87. Report an issue: GitHub.

Appendix: source

Thrown at src/Components/Web.JS/src/Validation/Validators/FileExtensions.ts:12

// Licensed to the .NET Foundation under one or more agreements.
// The .NET Foundation licenses this file to you under the MIT license.

import { ValidationContext, ValidationResult, Validator, pass, fail } from '../ValidationTypes';

// Validates that the filename ends with an allowed extension (case-insensitive).
// Extensions param is comma-separated with dot prefix (e.g. ".png,.jpg,.gif").
// Throws if the mandatory `extensions` parameter is missing.
export const fileExtensionsValidator: Validator = (context: ValidationContext): ValidationResult => {
  const { value, params } = context;
  if (!params.extensions) {
    throw new Error('FileExtensions validator requires a non-empty "extensions" parameter.');
  }

  if (!value) {
    return pass();
  }

  // Build regex from comma-separated extensions, stripping dots and escaping regex metacharacters.
  const extensions = params.extensions.split(',')
    .map(ext => ext.trim().replace(/^\./, ''))
    .filter(ext => ext.length > 0)
    .map(ext => ext.replace(/[.*+?^${}()|[\]\\]/g, '\\$&'))
    .join('|');

  if (!extensions) {
    return pass();
  }

  return new RegExp(`\\.(${extensions})$`, 'i').test(value) ? pass() : fail();

View on GitHub (pinned to 3600ca084e)