The server generates and returns an arbitrary token, which is typically a hash or A few other fingerprint of the contents of the file. The browser doesn't need to know the way the fingerprint is produced; it only should ship it for the server on the next ask for. If https://hughk431nzj2.bcbloggers.com/profile