[E29-S01-T03] Object keys never contain original filename #304

Open
opened 2026-08-27 08:05:13 +00:00 by kpcto · 0 comments
Owner

Parent story: [E29-S01] Upload endpoint and validation (#112)

Intent

Generate safe object keys so the original filename never enters storage paths.

Acceptance criteria

  • Generate content-addressed object keys that never embed the original filename
  • Never trust the original path when producing object keys

Explicitly out of scope

  • Size and MIME rejection is covered by E29-S01-T01
  • Checksum de-duplication is covered by E29-S01-T02

Test plan

  • Upload a file with a distinctive name and assert the stored key contains no trace of it

Rollback note

  • Revert key generation; already-stored keys are unaffected

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E29-S01] Upload endpoint and validation (#112) ## Intent Generate safe object keys so the original filename never enters storage paths. ## Acceptance criteria - Generate content-addressed object keys that never embed the original filename - Never trust the original path when producing object keys ## Explicitly out of scope - Size and MIME rejection is covered by E29-S01-T01 - Checksum de-duplication is covered by E29-S01-T02 ## Test plan - Upload a file with a distinctive name and assert the stored key contains no trace of it ## Rollback note - Revert key generation; already-stored keys are unaffected ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint M milestone 2026-08-27 08:05:13 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 08:05:13 +00:00
Sign in to join this conversation.