File uploads, attachments, archives and other content imported through the pipeline or webdav can be scanned for viruses using ClamAV. This topic covers how to configure and use ClamAV antivirus protection.
Configure Antivirus Scanner
Check Uploads for Viruses
When Antivirus protection is enabled, files uploaded via webdav or included as file attachments will be scanned by the configured provider, such as ClamAV. The process is:
- The file is uploaded to a protected "quarantine" location.
- The registered antivirus provider is sent a request and scans the file.
- If the antivirus provider determines the file is bad, it is deleted from the quarantine location and the user is notified.
- If the antivirus scan is successful, meaning no virus is detected, the file is uploaded from the quarantine location to the LabKey file system.
When virus checking is enabled, it is transparent to the users uploading virus-free files.
Virus Reporting
If the antivirus provider determines that a file is unsafe, it will not be uploaded. You'll see an error message like this one, whether you are attaching a file in an ELN, importing an assay run, uploading through a Files web part, or working anywhere else in the application:
For security reasons, we did not upload this file.
Please contact your internal IT or Information Security department for assistance in dealing with this potentially harmful file.
If one of your files is flagged, check with your own organization's IT or Information Security team first. Antivirus signatures can occasionally flag a file that isn't actually harmful, so your team is best positioned to confirm whether it's a genuine threat or a false positive.
Do not upload or send a flagged file to LabKey, even if you believe it to be a false positive. Contact your Account Manager if you have further questions.
Developer Notes
If a developer wishes to register and use a different virus checking service, they must do the following:
- Create a LabKey module. (See Java Modules.)
- Create an implementation of org.labkey.api.premium.PremiumService.AntiVirusProvider.
- Register the implementation using AntiVirusProviderRegistry.get().registerAntiVirusProvider() when the module starts up
Related Topics