basalt / files/src / FileRoutesOptions
Interface: FileRoutesOptions
Defined in: files/src/plugin.ts:74
Properties
authorize?
> optional authorize?: (action, record, user) => boolean | Promise<boolean>
Defined in: files/src/plugin.ts:83
Decides whether user may perform action on record. GET /files keeps only the records this allows for 'read'. Replaces the default policy.
Default (neither this nor shared): owner-only — a user reaches only the files whose uploadedBy is their own id. A file uploaded without uploadedBy is reachable by nobody through these routes.
Parameters
action
record
user
Returns
boolean | Promise<boolean>
download?
> optional download?: boolean
Defined in: files/src/plugin.ts:99
Serve the bytes from GET /files/:id/content, streamed. Default true. Authorized with the 'download' action, gated by the quarantine rules (423/403 before a single byte) and sent as Content-Disposition: attachment. Pass false for a deployment that only ever hands out signed URLs.
maxUrlTtl?
> optional maxUrlTtl?: DurationInput
Defined in: files/src/plugin.ts:91
Longest lifetime a client may request for a signed URL. Default '1h'.
present?
> optional present?: (record, user) => unknown
Defined in: files/src/plugin.ts:113
Shapes every record these routes answer with (GET /files, GET /files/:id, POST /files). Default toPublicFile: internal fields — the storage path, checksum, tenantId, uploadedBy, the scanner's detail — stay server-side. Return whatever the client should see; it runs after authorization, as the calling user.
Parameters
record
user
Returns
unknown
shared?
> optional shared?: boolean
Defined in: files/src/plugin.ts:89
Every authenticated user of the scope (the tenant, or the whole app without tenancy) may read, sign and delete every file in it — a shared drive. Ignored when authorize is given.
upload?
> optional upload?: FileUploadRouteOptions
Defined in: files/src/plugin.ts:105
Mount POST /files — a streamed multipart/form-data upload straight into storage. Off by default: the limits are yours to choose, so the route only exists once you state them.