File Uploads — download endpoint + upload records #501

Description

@adityapat24

Context

Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

Tasks

Upload records collection

  • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
    • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
  • Add a Mongo index on userId for fast "give me all this user's uploads."
    • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

recordUpload service function

  • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
    • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
  • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
    • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
  • Modify createSignedUploadUrl to call recordUpload internally.
    • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

Download endpoint

  • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
    • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
  • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
    • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
  • Signed download URLs expire in 15 minutes.
    • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

Auth gating

  • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
    • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
  • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
    • What this accomplishes: Same cleanup pattern as the other tickets.

End-to-end verification

  • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
    • What this accomplishes: Proves the full round trip works with real auth.
  • Sign in as a different user, try to download the first user's uploadId, confirm 403.
    • What this accomplishes: Proves the ownership check actually blocks cross-user access.
  • Sign in as an admin, download the first user's file, confirm it works.
    • What this accomplishes: Proves admin override works — critical for application review.

Definition of done

  • Every signed upload writes a corresponding record in the uploads collection.
  • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
  • Both endpoints are gated by requireUser().

Metadata

Metadata

Assignees

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    , 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
     blocks
    (function() {
    function addCopyButtons() {
    document.querySelectorAll('pre code').forEach(function(codeBlock) {
    if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
    codeBlock.parentElement.setAttribute('data-copy-added', 'true');
    var btn = document.createElement('button');
    btn.textContent = 'Copy';
    btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
    btn.onmouseover = function() { this.style.opacity = '1'; };
    btn.onmouseout = function() { this.style.opacity = '0.7'; };
    btn.onclick = function() {
    navigator.clipboard.writeText(codeBlock.textContent).then(function() {
    btn.textContent = 'Copied!';
    setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
    });
    };
    codeBlock.parentElement.style.position = 'relative';
    codeBlock.parentElement.appendChild(btn);
    });
    }
    addCopyButtons();
    // Re-run on dynamic content
    var observer = new MutationObserver(addCopyButtons);
    observer.observe(document.body, { childList: true, subtree: true });
    })();
    }
    } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
    })();
    (function(){
    try {
    var __m = "github.com";
    var __re = new RegExp('^' + "github\\.com" + '
    
    Skip to content

    File Uploads — download endpoint + upload records #501

    Description

    @adityapat24

    Context

    Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

    Tasks

    Upload records collection

    • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
      • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
    • Add a Mongo index on userId for fast "give me all this user's uploads."
      • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

    recordUpload service function

    • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
      • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
    • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
      • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
    • Modify createSignedUploadUrl to call recordUpload internally.
      • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

    Download endpoint

    • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
      • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
    • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
      • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
    • Signed download URLs expire in 15 minutes.
      • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

    Auth gating

    • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
      • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
    • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
      • What this accomplishes: Same cleanup pattern as the other tickets.

    End-to-end verification

    • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
      • What this accomplishes: Proves the full round trip works with real auth.
    • Sign in as a different user, try to download the first user's uploadId, confirm 403.
      • What this accomplishes: Proves the ownership check actually blocks cross-user access.
    • Sign in as an admin, download the first user's file, confirm it works.
      • What this accomplishes: Proves admin override works — critical for application review.

    Definition of done

    • Every signed upload writes a corresponding record in the uploads collection.
    • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
    • Both endpoints are gated by requireUser().

    Metadata

    Metadata

    Assignees

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
      Skip to content

      File Uploads — download endpoint + upload records #501

      Description

      @adityapat24

      Context

      Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

      Tasks

      Upload records collection

      • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
        • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
      • Add a Mongo index on userId for fast "give me all this user's uploads."
        • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

      recordUpload service function

      • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
        • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
      • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
        • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
      • Modify createSignedUploadUrl to call recordUpload internally.
        • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

      Download endpoint

      • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
        • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
      • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
        • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
      • Signed download URLs expire in 15 minutes.
        • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

      Auth gating

      • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
        • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
      • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
        • What this accomplishes: Same cleanup pattern as the other tickets.

      End-to-end verification

      • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
        • What this accomplishes: Proves the full round trip works with real auth.
      • Sign in as a different user, try to download the first user's uploadId, confirm 403.
        • What this accomplishes: Proves the ownership check actually blocks cross-user access.
      • Sign in as an admin, download the first user's file, confirm it works.
        • What this accomplishes: Proves admin override works — critical for application review.

      Definition of done

      • Every signed upload writes a corresponding record in the uploads collection.
      • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
      • Both endpoints are gated by requireUser().

      Metadata

      Metadata

      Assignees

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions

        , 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
        Skip to content

        File Uploads — download endpoint + upload records #501

        Description

        @adityapat24

        Context

        Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

        Tasks

        Upload records collection

        • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
          • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
        • Add a Mongo index on userId for fast "give me all this user's uploads."
          • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

        recordUpload service function

        • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
          • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
        • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
          • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
        • Modify createSignedUploadUrl to call recordUpload internally.
          • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

        Download endpoint

        • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
          • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
        • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
          • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
        • Signed download URLs expire in 15 minutes.
          • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

        Auth gating

        • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
          • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
        • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
          • What this accomplishes: Same cleanup pattern as the other tickets.

        End-to-end verification

        • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
          • What this accomplishes: Proves the full round trip works with real auth.
        • Sign in as a different user, try to download the first user's uploadId, confirm 403.
          • What this accomplishes: Proves the ownership check actually blocks cross-user access.
        • Sign in as an admin, download the first user's file, confirm it works.
          • What this accomplishes: Proves admin override works — critical for application review.

        Definition of done

        • Every signed upload writes a corresponding record in the uploads collection.
        • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
        • Both endpoints are gated by requireUser().

        Metadata

        Metadata

        Assignees

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
          Skip to content

          File Uploads — download endpoint + upload records #501

          Description

          @adityapat24

          Context

          Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

          Tasks

          Upload records collection

          • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
            • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
          • Add a Mongo index on userId for fast "give me all this user's uploads."
            • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

          recordUpload service function

          • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
            • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
          • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
            • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
          • Modify createSignedUploadUrl to call recordUpload internally.
            • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

          Download endpoint

          • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
            • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
          • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
            • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
          • Signed download URLs expire in 15 minutes.
            • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

          Auth gating

          • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
            • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
          • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
            • What this accomplishes: Same cleanup pattern as the other tickets.

          End-to-end verification

          • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
            • What this accomplishes: Proves the full round trip works with real auth.
          • Sign in as a different user, try to download the first user's uploadId, confirm 403.
            • What this accomplishes: Proves the ownership check actually blocks cross-user access.
          • Sign in as an admin, download the first user's file, confirm it works.
            • What this accomplishes: Proves admin override works — critical for application review.

          Definition of done

          • Every signed upload writes a corresponding record in the uploads collection.
          • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
          • Both endpoints are gated by requireUser().

          Metadata

          Metadata

          Assignees

          Projects

          No projects

            Milestone

            No milestone

            Relationships

            None yet

            Development

            No branches or pull requests

            Issue actions

            , 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
            Skip to content

            File Uploads — download endpoint + upload records #501

            Description

            @adityapat24

            Context

            Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

            Tasks

            Upload records collection

            • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
              • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
            • Add a Mongo index on userId for fast "give me all this user's uploads."
              • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

            recordUpload service function

            • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
              • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
            • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
              • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
            • Modify createSignedUploadUrl to call recordUpload internally.
              • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

            Download endpoint

            • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
              • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
            • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
              • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
            • Signed download URLs expire in 15 minutes.
              • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

            Auth gating

            • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
              • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
            • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
              • What this accomplishes: Same cleanup pattern as the other tickets.

            End-to-end verification

            • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
              • What this accomplishes: Proves the full round trip works with real auth.
            • Sign in as a different user, try to download the first user's uploadId, confirm 403.
              • What this accomplishes: Proves the ownership check actually blocks cross-user access.
            • Sign in as an admin, download the first user's file, confirm it works.
              • What this accomplishes: Proves admin override works — critical for application review.

            Definition of done

            • Every signed upload writes a corresponding record in the uploads collection.
            • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
            • Both endpoints are gated by requireUser().

            Metadata

            Metadata

            Assignees

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              File Uploads — download endpoint + upload records #501

              Description

              @adityapat24

              Context

              Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

              Tasks

              Upload records collection

              • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
                • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
              • Add a Mongo index on userId for fast "give me all this user's uploads."
                • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

              recordUpload service function

              • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
                • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
              • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
                • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
              • Modify createSignedUploadUrl to call recordUpload internally.
                • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

              Download endpoint

              • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
                • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
              • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
                • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
              • Signed download URLs expire in 15 minutes.
                • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

              Auth gating

              • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
                • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
              • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
                • What this accomplishes: Same cleanup pattern as the other tickets.

              End-to-end verification

              • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
                • What this accomplishes: Proves the full round trip works with real auth.
              • Sign in as a different user, try to download the first user's uploadId, confirm 403.
                • What this accomplishes: Proves the ownership check actually blocks cross-user access.
              • Sign in as an admin, download the first user's file, confirm it works.
                • What this accomplishes: Proves admin override works — critical for application review.

              Definition of done

              • Every signed upload writes a corresponding record in the uploads collection.
              • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
              • Both endpoints are gated by requireUser().

              Metadata

              Metadata

              Assignees

              Projects

              No projects

                Milestone

                No milestone

                Relationships

                None yet

                Development

                No branches or pull requests

                Issue actions

                , 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                Skip to content

                File Uploads — download endpoint + upload records #501

                Description

                @adityapat24

                Context

                Last sprint shipped the signed upload URL endpoint (POST /api/v1/uploads/sign). What's missing is the download side, persistent tracking of uploads in Mongo, and ownership enforcement.

                Tasks

                Upload records collection

                • Create a new Mongo collection uploads (or upload_records — pick a name and stick with it). Document shape: { _id: uploadId, userId, filename, mime, size, gcsPath, createdAt }.
                  • What this accomplishes: Tracks what files exist, who owns them, and where they live in GCS. Without this, files exist in GCS but can't be looked up by ID from the app.
                • Add a Mongo index on userId for fast "give me all this user's uploads."
                  • What this accomplishes: When an admin views an applicant, showing their resume requires finding the upload record by userId. Indexed lookup is essential at scale.

                recordUpload service function

                • Implement recordUpload({ uploadId, userId, filename, mime, size, gcsPath }) in src/lib/uploads/service.ts. Inserts a document into the uploads collection.
                  • What this accomplishes: The write side of the upload record. Called after a successful signing (or after successful upload confirmation from the client).
                • Decide when to call it: either at sign time (before the actual upload) or after the client confirms upload. Recommend at sign time, since it's simpler and orphan records (signed but never uploaded) are cheap to clean up later with a batch job.
                  • What this accomplishes: Trades some database noise for simplicity. Alternative (confirm-based) requires a second endpoint the client hits after upload succeeds.
                • Modify createSignedUploadUrl to call recordUpload internally.
                  • What this accomplishes: Sign requests now also persist the record, so a subsequent download request can look up the record by uploadId.

                Download endpoint

                • Implement createSignedDownloadUrl(uploadId, requester) in src/lib/uploads/service.ts. Looks up the upload record by ID. If the requester is the owner (requester.userId === record.userId) or is admin (requester.isAdmin), returns a signed download URL from GCS. Otherwise returns null (which the endpoint converts to a 403).
                  • What this accomplishes: Ownership check is centralized. Non-owners can never fish for other people's uploads by guessing IDs; admins can always download to review applications.
                • Wire GET /api/v1/uploads/[id] to call it. Returns { url, expiresAt } on success, 404 if the upload ID doesn't exist, 403 if the requester isn't allowed.
                  • What this accomplishes: The endpoint that the applicant form (to show "your uploaded resume") and the admin applicant detail page (to review resumes) both call.
                • Signed download URLs expire in 15 minutes.
                  • What this accomplishes: Matches the upload URL expiry. Short enough to limit damage from a leaked URL, long enough for normal use.

                Auth gating

                • Wire requireUser() into both POST /api/v1/uploads/sign and GET /api/v1/uploads/[id].
                  • What this accomplishes: Anonymous users can't request upload URLs or download files. Every request is tied to a specific user via session.
                • Remove the placeholder userId header/query-param handling from the sign endpoint. Use session.user.id from requireUser().
                  • What this accomplishes: Same cleanup pattern as the other tickets.

                End-to-end verification

                • Sign in, upload a file via /uploads-demo, note the returned uploadId, hit GET /api/v1/uploads/[id] with that ID, download the file at the returned URL, verify bytes match.
                  • What this accomplishes: Proves the full round trip works with real auth.
                • Sign in as a different user, try to download the first user's uploadId, confirm 403.
                  • What this accomplishes: Proves the ownership check actually blocks cross-user access.
                • Sign in as an admin, download the first user's file, confirm it works.
                  • What this accomplishes: Proves admin override works — critical for application review.

                Definition of done

                • Every signed upload writes a corresponding record in the uploads collection.
                • GET /api/v1/uploads/[id] returns a working signed download URL for the owner or an admin, 403 for anyone else, 404 for missing IDs.
                • Both endpoints are gated by requireUser().

                Metadata

                Metadata

                Assignees

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions