You cannot make the file field sticky, I think. Even if Rails provides the initial value, most browsers simply ignore it (or, otherwise, some smart-aleck can set the default file to /etc/passwd, and if you do not pay attention, then the following, that you know, your field is rooted.
, , , - , , , , , , .
:. , . , root. "" - , , - , Rails, , , .
, , ...
2: " " , " ". , , : innocent.txt CAPTCHA. , CAPTCHA , innocent.txt ~/.ssh/id_rsa. ( ), CAPTCHA submit. SSH-.