Skip to content

STO · Files

Photos, scans and proofs live in private Supabase Storage buckets: documents, inspections, screening and payments. A row stores the file's path, and the app shows the file through a short-lived signed URL. Code STO.

These questions are open in #75. Each gets a rule with a new ID once it is answered.

  • STO open 1 · Bucket limits

R-STO-01 · Every Storage bucket is private

Section titled “R-STO-01 · Every Storage bucket is private”
  • Status: planned
  • Example: given the documents bucket, when a file's public URL is opened without a signed token, then nothing is served.
  • Refusal: none: Storage answers not found.
  • Who: every bucket.
  • Source: D9 (P15).

R-STO-02 · A file is stored at organization_id/table/row_id/file, with no pool in the path

Section titled “R-STO-02 · A file is stored at organization_id/table/row_id/file, with no pool in the path”
  • Status: planned
  • Example: given a KTP scan for driver 7f3e…, when it is uploaded, then its path is <organization_id>/driver_documents/<row_id>/ktp.jpg.
  • Refusal: none: an upload outside this pattern has no policy that allows it.
  • Who: every upload.
  • Source: D14, which replaces the path in P15.

R-STO-03 · Reading a file needs read access to its row, at the pool the row has now

Section titled “R-STO-03 · Reading a file needs read access to its row, at the pool the row has now”
  • Status: planned
  • Example: given a driver moved from PML to SBY, when an admin_driver scoped to SBY opens the driver's KTP scan, then it is served; the PML admin_driver who uploaded it can no longer open it.
  • Refusal: none: Storage answers not found.
  • Who: whoever may read the row; each table's read permissions are on its domain's page.
  • Source: D14; [Ref] Roles, policy matrix (storage objects).

R-STO-04 · Uploading a file needs write access to its row

Section titled “R-STO-04 · Uploading a file needs write access to its row”
  • Status: planned
  • Example: given a satpam, when he uploads an inspection photo, then it is refused; a checker at the inspection's pool may upload it.
  • Refusal: none: insufficient_privilege (42501).
  • Who: whoever may write the row; each table's write permissions are on its domain's page.
  • Source: [Ref] Roles, policy matrix (storage objects).

R-STO-05 · A row stores a file's path, never the file's content

Section titled “R-STO-05 · A row stores a file's path, never the file's content”
  • Status: planned
  • Example: given a payment, when proof_path is saved as data:image/jpeg;base64,…, then it is refused; a path in the payments bucket is accepted.
  • Refusal: none: check_violation (23514).
  • Who: every writer.
  • Source: D9 (P15); [Ref] Database rules and conventions, Personal data and files (no base64 in rows).