--- name: storage-uploads description: "Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle. Use when working with S3/R2-compatible storage, attachments or multipart uploads; separate transient transfer state from durable application ownership." trigger: "Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle. Use when working with S3/R2-compatible storage, attachments or multipart uploads; separate transient transfer state from durable application ownership." version: 1.0.1 required-capabilities: [filesystem.read] required-tools: [] optional-capabilities: [filesystem.write, execution.shell, verification.run, web.research] metadata: routing-group: data domain: "data" --- # Storage Uploads ## Selection card - Task: Implement owned object storage and upload lifecycle. / TR: Sahipliği tanımlı nesne deposu ve yükleme yaşam döngüsü uygula. - Start: Identify the data owner, query/schema, consistency and recovery contract. - Finish: apply the acceptance checks below; report observed results and unresolved constraints. ## Overview Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle. Checked AWS S3 JavaScript SDK target: 3.1148.0 on 2026-10-09. Verify provider-specific API/binding support; S3-compatible does not mean every operation or signature setting is identical. ## Rules 1. Define object ownership, allowed content/size, retention and access before choosing bucket/key layout. 2. Validate upload metadata and content at the appropriate trusted boundary; client MIME/extension alone is insufficient. 3. Scope signed URLs/temporary credentials by operation, object and expiry; avoid broad public access as a workaround. 4. Model incomplete/multipart uploads, retries, orphan objects and application database references. 5. Keep private objects isolated by authorization, not guess-resistant names alone. 6. Distinguish checksum/integrity, malware/content checks and successful upload; they are different evidence. ## Workflow 1. Inspect provider/bucket policies, SDK/bindings and existing file metadata. 2. Implement bounded upload/download and durable reference transitions. 3. Test size/type rejection, unauthorized access, retry and incomplete transfer cleanup. 4. Verify retrieval/expiry/retention in an isolated authorized storage environment. 5. Record provider-specific constraints and actual object/application consistency. ## Before returning Ownership/access and transfer limits explicit; interrupted/retried operations handled; private objects protected; integrity and live storage proof scoped. ## Sources Versioned facts checked 2026-10-09; refresh authoritative sources before new installs/upgrades. [AWS S3 docs](https://docs.aws.amazon.com/AmazonS3/latest/userguide/Welcome.html), [Cloudflare R2](https://developers.cloudflare.com/r2/). ## Skills in scope - api-design — api design contracts and verification. - data-governance — data governance contracts and verification. - database-development — implement database access, models and queries with explicit consistency, transactions and bounded results. - backup-recovery — design and verify backups and restoration for owned databases, files and application state.