Add attachment management CRUD to the /uploads API
Complete the read and update faces of the signed-in user's attachment
management over the existing attachments table:
- GET /uploads: paginated list of the user's own attachments, newest
first, with an optional linked/orphaned filter
- GET /uploads/{uid}: fetch one attachment (owner or admin)
- PATCH /uploads/{uid}: rename the display filename, always preserving
the original extension (owner or admin, audited as attachment.rename)
Adds get_user_attachments/get_user_attachment data helpers, the
rename_attachment operation, AttachmentRenameForm, the UploadItemOut and
UploadsListOut schemas, the Devii tools list_attachments/get_attachment/
rename_attachment, expanded API reference documentation for the full
lifecycle including delete, and api-tier tests.
This commit is contained in:
@@ -546,6 +546,21 @@ def delete_attachment(uid):
|
||||
_delete_attachment_row(row)
|
||||
|
||||
|
||||
def rename_attachment(uid, filename):
|
||||
row = get_table("attachments").find_one(uid=uid, deleted_at=None)
|
||||
if not row:
|
||||
return None
|
||||
ext = Path(row.get("stored_name", "")).suffix.lower()
|
||||
stem = Path(str(filename)).name.strip()
|
||||
if ext:
|
||||
stem = Path(stem).stem
|
||||
if not stem:
|
||||
return None
|
||||
clean = f"{stem}{ext}"
|
||||
get_table("attachments").update({"uid": uid, "original_filename": clean}, ["uid"])
|
||||
return clean
|
||||
|
||||
|
||||
def soft_delete_attachment(uid, deleted_by="system"):
|
||||
row = get_table("attachments").find_one(uid=uid)
|
||||
if not row or row.get("deleted_at"):
|
||||
|
||||
Reference in New Issue
Block a user