Files
Authorization and collection binding
Knowing a file ID does not bypass authentication.
Administrator sessions can manage files. Service credentials require files:read or files:write. Uploads may bind metadata to a collection and record ID in the same metadata commit.
Application-user rules
Direct application-user file delivery through collection rules is not currently enabled. Use an authorized backend until record-aware file-rule evaluation is added.