STO · Files
Photos, scans and proofs live in private Supabase Storage buckets: documents, inspections, screening and payments. A row stores the file's path, and the app shows the file through a short-lived signed URL. Code STO.
Not yet a rule
Section titled “Not yet a rule”These questions are open in #75. Each gets a rule with a new ID once it is answered.
- STO open 1 · Bucket limits
R-STO-01 · Every Storage bucket is private
Section titled “R-STO-01 · Every Storage bucket is private”- Status: planned
- Example: given the documents bucket, when a file's public URL is opened without a signed token, then nothing is served.
- Refusal: none: Storage answers not found.
- Who: every bucket.
- Source: D9 (P15).
R-STO-02 · A file is stored at organization_id/table/row_id/file, with no pool in the path
Section titled “R-STO-02 · A file is stored at organization_id/table/row_id/file, with no pool in the path”- Status: planned
- Example: given a KTP scan for driver 7f3e…, when it is uploaded, then its path is <organization_id>/driver_documents/<row_id>/ktp.jpg.
- Refusal: none: an upload outside this pattern has no policy that allows it.
- Who: every upload.
- Source: D14, which replaces the path in P15.
R-STO-03 · Reading a file needs read access to its row, at the pool the row has now
Section titled “R-STO-03 · Reading a file needs read access to its row, at the pool the row has now”- Status: planned
- Example: given a driver moved from PML to SBY, when an admin_driver scoped to SBY opens the driver's KTP scan, then it is served; the PML admin_driver who uploaded it can no longer open it.
- Refusal: none: Storage answers not found.
- Who: whoever may read the row; each table's read permissions are on its domain's page.
- Source: D14; [Ref] Roles, policy matrix (storage objects).
R-STO-04 · Uploading a file needs write access to its row
Section titled “R-STO-04 · Uploading a file needs write access to its row”- Status: planned
- Example: given a satpam, when he uploads an inspection photo, then it is refused; a checker at the inspection's pool may upload it.
- Refusal: none: insufficient_privilege (42501).
- Who: whoever may write the row; each table's write permissions are on its domain's page.
- Source: [Ref] Roles, policy matrix (storage objects).
R-STO-05 · A row stores a file's path, never the file's content
Section titled “R-STO-05 · A row stores a file's path, never the file's content”- Status: planned
- Example: given a payment, when proof_path is saved as data:image/jpeg;base64,…, then it is refused; a path in the payments bucket is accepted.
- Refusal: none: check_violation (23514).
- Who: every writer.
- Source: D9 (P15); [Ref] Database rules and conventions, Personal data and files (no base64 in rows).