[E29-S01] Upload endpoint and validation #112

Open
opened 2026-08-27 00:03:23 +00:00 by kpcto · 0 comments
Owner

Parent epic: [E29] Media pipeline (#55)

Intent

Deliver the media upload endpoint that validates every upload before it is stored, rejecting oversized or forged files and de-duplicating by checksum.

Acceptance criteria

  • Reject oversized uploads with a clear error before the request body is read
  • Determine content type from magic bytes, never trusting the client header or file extension
  • Return the existing media record when an ingested SHA-256 checksum matches a stored duplicate
  • Generate content-addressed object keys that never contain the original filename
  • Never trust the original path and never serve executable content from application code locations

Explicitly out of scope

  • Image re-encoding and derivative generation are covered by E29-S02
  • Video upload handling is covered by E29-S04

Test plan

  • Upload an oversized file and assert the clear rejection error
  • Upload a file with a forged Content-Type and assert magic-byte detection
  • Upload identical bytes twice and assert a single matching record is returned

Rollback note

  • Roll back the endpoint deployment; no data migration is introduced

Owning stream

platform

Risk quadrant

agent-full

> Parent epic: [E29] Media pipeline (#55) ## Intent Deliver the media upload endpoint that validates every upload before it is stored, rejecting oversized or forged files and de-duplicating by checksum. ## Acceptance criteria - Reject oversized uploads with a clear error before the request body is read - Determine content type from magic bytes, never trusting the client header or file extension - Return the existing media record when an ingested SHA-256 checksum matches a stored duplicate - Generate content-addressed object keys that never contain the original filename - Never trust the original path and never serve executable content from application code locations ## Explicitly out of scope - Image re-encoding and derivative generation are covered by E29-S02 - Video upload handling is covered by E29-S04 ## Test plan - Upload an oversized file and assert the clear rejection error - Upload a file with a forged Content-Type and assert magic-byte detection - Upload identical bytes twice and assert a single matching record is returned ## Rollback note - Roll back the endpoint deployment; no data migration is introduced ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint M milestone 2026-08-27 00:03:23 +00:00
kpcto added the
kind
story
status
proposed
labels 2026-08-27 00:03:23 +00:00
Sign in to join this conversation.