Jump to content

RefractTrack Attachments: Difference between revisions

From Pixel Refraction Studio
Created page with "== Attachments == Tasks support file attachments, gated by <code><nowiki>attachments:view</nowiki></code> / <code><nowiki>attachments:create</nowiki></code> / <code><nowiki>attachments:delete</nowiki></code>. === Storage === Uploaded files are stored on disk under <code><nowiki>uploads/tasks/<task_id>/</nowiki></code> with randomized filenames. By default only <code><nowiki>.jpg .jpeg .png .gif .webp .zip</nowiki></code> are accepted, and the allowed list is configura..."
 
No edit summary
Line 1: Line 1:
== Attachments ==
== Attachments ==


Tasks support file attachments, gated by <code><nowiki>attachments:view</nowiki></code> / <code><nowiki>attachments:create</nowiki></code> / <code><nowiki>attachments:delete</nowiki></code>.
Tasks can carry file attachments — a screenshot of a bug, a piece of reference art, a design doc, whatever's useful. By default, image files and zip archives are accepted; your admin can widen or narrow that list, and set a maximum file size, to suit your team.


=== Storage ===
=== Who can see what ===


Uploaded files are stored on disk under <code><nowiki>uploads/tasks/<task_id>/</nowiki></code> with randomized filenames. By default only <code><nowiki>.jpg .jpeg .png .gif .webp .zip</nowiki></code> are accepted, and the allowed list is configurable via <code><nowiki>ALLOWED_UPLOAD_EXTENSIONS</nowiki></code> in <code><nowiki>config/config.php</nowiki></code> (see [[RefractTrack_Configuration|Configuration]]). Maximum upload size is likewise configurable via <code><nowiki>MAX_UPLOAD_BYTES</nowiki></code>.
Attachments follow the same access rules as everything else in RefractTrack: only people with permission to view attachments — and access to that specific project — can open a file. There's no way to guess or share a direct link that bypasses those checks; every download is checked first.
 
=== Access control ===
 
Attachments cannot be downloaded directly from <code><nowiki>/uploads/tasks/*</nowiki></code> — that path is blocked at the <code><nowiki>.htaccess</nowiki></code> level. The only way to reach an attachment is through <code><nowiki>attachment.php</nowiki></code>, which:
 
# Checks <code><nowiki>attachments:view</nowiki></code>
# Verifies the requesting user has access to the attachment's project
# Only then streams the file
 
This means an attachment's protection matches the task's own project access, not just a permission flag a user can't reach a file for a project they haven't been granted access to even if they hold <code><nowiki>attachments:view</nowiki></code> globally.


=== Related pages ===
=== Related pages ===


* [[RefractTrack_Tasks|Tasks]]
* [[RefractTrack_Tasks|Tasks]]
* [[RefractTrack_Security|Security]]
* [[RefractTrack_Permissions_and_Roles|Permissions and Roles]]
* [[RefractTrack_Permissions_and_Roles|Permissions and Roles]]

Revision as of 00:13, 29 August 2026

Attachments

Tasks can carry file attachments — a screenshot of a bug, a piece of reference art, a design doc, whatever's useful. By default, image files and zip archives are accepted; your admin can widen or narrow that list, and set a maximum file size, to suit your team.

Who can see what

Attachments follow the same access rules as everything else in RefractTrack: only people with permission to view attachments — and access to that specific project — can open a file. There's no way to guess or share a direct link that bypasses those checks; every download is checked first.