Skip to content

feat(files): add the Project file backend and APIs - #8610

Draft
mzxchandra wants to merge 45 commits into
codex/file-ownership-foundationfrom
codex/project-files
Draft

mzxchandra wants to merge 45 commits into
codex/file-ownership-foundationfrom
codex/project-files

Conversation

@mzxchandra

@mzxchandra mzxchandra commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add the complete Project-file backend: folders, uploads, edits, history, copy, recursive listing/downloads, extraction, search, compiled documents, sharing and realtime persistence callbacks.
  • Reuse authorized application operations across sessions, v2/CLI and delegated callers. Writes require an organization admin, an admin in an active environment, or write access in every active environment; workspace API keys do not acquire Project authority.
  • Preserve canonical ownership and revision checks through storage, history, billing, retention, cross-owner copies and content delivery. Public/password/email/SSO sharing rechecks current policy and dependencies.
  • Keep Project operations behind the existing release gates. Execution files remain workspace scoped; chat ownership remains personal/organization scoped.

Stacked on #8609 above #8590, with #8762 as the lifecycle prerequisite. This PR contains the backend, HTTP API, CLI, documentation and the public-share viewer required for content delivery. Stacked #8781 adds authenticated Project Files UI, picker/mentions and Sim-side Mothership integration; Mothership #594 is its separate worker companion. No additional migration is introduced here.

Type of Change

  • New feature

Testing

  • Integrated backend: 263 real-Postgres checks and 84 live HTTP checks across authorization, browser queries, history, sharing, rendering, copying and realtime.
  • Four additional HTTP checks verify recursive pagination, unchanged root browsing, cursor scope binding and rejection of conflicting folder filters.
  • Full backend root suite previously passed all 19 workspace tasks; the latest bounded route change passes formatting and all 58 repository audits. Full-repository checks for the published head run in CI.
  • Fresh migration/replay/schema-drift, generated artifacts and backend contract checks passed. Live paired product/worker acceptance additionally verifies the backend through actual model read/write/copy and browser delivery.
  • CI is manually dispatched for the stacked branch; workflow triggers and timeouts are unchanged.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Relevant tests updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 8, 2026 7:17pm UTC

Request Review

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 485 files

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Re-trigger cubic

Comment thread apps/sim/lib/file-retention/workspace-versions.ts
Comment thread apps/sim/lib/api/contracts/v2/project-file-extraction.ts
Comment thread apps/sim/lib/api/contracts/v2/openapi/project-file-shares.ts Outdated
Comment thread apps/sim/lib/api/contracts/project-file-uploads.ts Outdated
Comment thread apps/sim/app/api/projects/[id]/files/[fileId]/csv-preview/route.ts Outdated
Comment thread apps/sim/app/workspace/[workspaceId]/files/components/file-viewer/text-editor.tsx Outdated
Comment thread apps/sim/lib/api/contracts/v2/openapi/files-audit.ts
Reuse entity-owned file operations across Project UI, session APIs, v2/CLI,
and delegated Mothership callers. Add Project discovery, sharing, history,
copy, collaborative editing, and current-access invalidation while preserving
workspace execution boundaries and independent creator/payer attribution.

Keep activation gated behind the file-ownership compatibility foundation.
Run real HTTP suites through disposable fixture orchestration in CI.
@greptile-apps

greptile-apps Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical impact] The PR appears safe to merge based on the reviewed changes and resolved prior findings.

Summary

The PR adds Project-file storage and application operations, HTTP and v2 APIs, CLI commands, public delivery, and realtime file-list support.

  • The changes since the previous review replace single-owner invalidation-room joins with independent per-owner subscriptions and update their tests.
  • All five previous Greptile threads are resolved; no new actionable finding was established.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Client[Browser or CLI] --> API[Project file APIs]
  API --> Ops[Authorized file operations]
  Ops --> Data[File metadata and storage]
  Ops --> Relay[Realtime invalidation]
  Relay --> Viewers[Subscribed viewers refetch]
  Share[Public share request] --> Grant[Current share policy]
  Grant --> Data
Loading

Reviews (11) · Last reviewed commit: "fix(realtime): preserve concurrent owner..." · Reviewed by Greptile

Comment thread apps/sim/lib/projects/files/application/authorization.ts Outdated
Comment thread apps/sim/app/workspace/[workspaceId]/files/project-files.tsx Outdated
@mzxchandra
mzxchandra force-pushed the codex/project-files branch from 547eb7b to a9fd086 Compare October 6, 2026 00:44
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 485 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/lib/projects/files/application/artifacts.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 389 files

Confidence score: 4/5

  • In apps/sim/lib/workspace-files/api/archive-presenter.ts, canceling while downloadFileStream() is pending can leave the storage stream open once it resolves. Ensure that stream is destroyed on this cancellation path.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/workspace-files/api/archive-presenter.ts">

<violation number="1" location="apps/sim/lib/workspace-files/api/archive-presenter.ts:44">
P2: Canceling the archive while `downloadFileStream()` is pending destroys the wrapper before this generator enters its `try/finally`, leaving the subsequently opened storage stream undestroyed. Arrange to destroy a stream if acquisition resolves after `closed` aborts.</violation>
</file>

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/uploads/server/image-derivative.ts
Comment thread apps/sim/lib/workspace-files/api/archive-presenter.ts Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 389 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

Regarding “Project admins can be denied”: this scenario is excluded by the current database invariant. The member schema defines member_user_id_unique on member.userId. Migration 0136 creates that UNIQUE index, and no later SQL migration drops it. Each user therefore has at most one membership row, so limit(1) cannot choose a different row among multiple organization memberships. The admin predicate also requires an exact match to the canonical Project organization before checking the role. No authorization change is needed while this invariant holds.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 390 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 391 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — ebfa1c3e Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant