Documents & files
Every file is tracked
Each upload — and every file a tool generates — is a file_metadata row owned by the user who created it. Only the owner can download or delete it.
| Endpoint | |
|---|---|
POST /api/files/upload | Upload a file |
GET /api/files/{id} | Metadata |
GET /api/files/{id}/download | Download the bytes |
GET /api/files/history | The caller's files |
DELETE /api/files/{id} | Delete the row and the file on disk |
Storage
By default files live under ./uploads/ relative to the backend, with sub-folders per category:
uploads/
├── <uuid>_<original-name>.pdf ← raw uploads
├── merged/ split/ compressed/ converted/
├── protected/ unlocked/
├── watermarked/ page-numbered/ pages-removed/
└── ocr/ redacted/ translated/ …
The base directory is configurable (FILE_UPLOAD_DIR). With Cloudinary configured (CLOUDINARY_*), media is stored there instead and the row keeps the public id.
The Documents page
/documents lists the caller's files with search and file-type badges so a PDF, a DOCX and an image are distinguishable at a glance. From here a file can be fed straight into a PDF tool or an e-signature flow.
Supported types
PDF is the primary format. The conversion tools also read and write DOCX, XLSX / XLS, PPTX, and common image formats (PNG, JPEG, BMP). See the project's work-details/ for the exhaustive list.
Deleting
Deleting a file_metadata row deletes the underlying file. A file referenced by a sign document is protected while that document is active.