Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Project: private evidence file lifecycle

Last updated: 5 Oct 20268 min read
project
IntermediateBy AITrove Editorial

Build file intake for case 47. Reviewer 29 may add up to four evidence files, each within a 23 MiB application limit for ordinary attachments; a separate large-video policy uses an owned resumable session. The browser shows sent-byte progress, but the case page says Processing until storage completion, integrity checks, and inspection finish. The server grants only an opaque pending object key after confirming current case rights and quota. It counts actual bytes, keeps abandoned parts on a cleanup schedule, and prevents a second reviewer from completing the session. The worker validates the full format, applies resource limits to parsing and preview generation, and records accepted or rejected state. Originals and previews stay private. At download, the server checks current case rights again. An assignment change blocks new grants; the retention workflow deletes raw, preview, and staging objects and keeps a deletion marker against restore.

Build contract

  • Bound actual bytes and concurrent sessions before storage; reject cross-tenant and forged object keys.
  • Resume a timed-out part from authoritative state and distinguish sending, assembling, inspecting, and ready.
  • Reject malformed or over-expanded content and retry a crashed inspection worker without stale previews.
  • Revoke current read rights and delete original, derivative, and incomplete storage under one asset inventory.

Implementation checkpoint

javascript
function assetReady(assembled, inspected, previewReady) {
  return assembled && inspected === "accepted" && previewReady;
}
console.log(assetReady(true, "pending", true));
// Output: false

Cost and boundaries

For n transferred bytes, intake and digest work are O(n); an in-memory receiver also consumes O(n) process memory, which a bounded stream avoids. Splitting n bytes into parts adds metadata and request overhead while reducing retransmission after a failure. Inspection may cost more than transfer when media decoding or archive expansion occurs, so the worker needs CPU, memory, output, and time caps. A proxy download consumes O(n) application egress; brief signed storage grants reduce that cost but leave a bounded revocation window. Track incomplete-part storage, pending age, inspection failures, orphaned derivatives, and denied reads.

Failure drill

Post a 24 MiB ordinary file while declaring 22 MiB, and verify reception stops at the actual cap. Time out after part four is stored, query the session, and resume without duplicating earlier parts. Finish transfer with a mismatched full-object digest and prove no ready asset appears. Crash inspection after a preview write and retry; only the matching source version may be exposed. Revoke reviewer 29’s case rights and attempt original and preview reads. Run expiry, restore old metadata, and confirm the deletion marker prevents reappearance.

Acceptance checks

  • A transferred object remains private until inspection and required outputs pass.
  • Parts, final object, and derivatives remain bound to one authorized asset.
  • Current authorization covers every original and preview read.
  • Expiry removes incomplete and completed storage without revival on restore.

Common Mistakes

  • Equating progress with a usable asset.
  • Using a browser filename as the storage key.
  • Protecting an original while exposing its preview.

Related lessons

Upload Intake Budgets and Storage Ownership; Resumable Transfer Parts and Integrity; File Quarantine, Inspection, and Derived Previews; Private Asset Downloads, Revocation, and Expiry.

web-tech
web-development
Storage details