Files

Authorization and collection binding

Knowing a file ID does not bypass authentication.

Administrator sessions can manage files. Service credentials require files:read or files:write. Uploads may bind metadata to a collection and record ID in the same metadata commit.

Application-user rules

Direct application-user file delivery through collection rules is not currently enabled. Use an authorized backend until record-aware file-rule evaluation is added.