**Blocked by:** T4-4 (#23), T1-4 (#7) · **Blocks:** frontend media (Epic 2, story 2.5) - [ ] An upload endpoint accepts images and PDFs, tied to a **section** - [ ] The file type is checked from the **file's actual contents**, not its name or the browser's claim. Anything else is rejected - [ ] A size limit, with a clear error when exceeded (decide the number: something like 10 MB for images and 25 MB for PDFs) - [ ] Files are stored privately. Reading one returns a **signed link valid for 5 minutes**, never a public URL - [ ] Nothing is reachable without going through the API - [ ] File uploads use `multer`, which is already installed with NestJS. No new dependency for that part **Needs approval:** the AWS S3 client (`@aws-sdk/client-s3` and `@aws-sdk/s3-request-presigner`). --- _Source: `docs/backend-tickets.md`_
Blocked by: T4-4 (#23), T1-4 (#7) · Blocks: frontend media (Epic 2, story 2.5)
multer, which is already installed with NestJS. No new dependency for that partNeeds approval: the AWS S3 client (
@aws-sdk/client-s3and@aws-sdk/s3-request-presigner).Source:
docs/backend-tickets.md