Skip to content

feat(files): add the Project file backend and APIs - #8610

Draft
mzxchandra wants to merge 53 commits into
codex/file-ownership-foundationfrom
codex/project-files
Draft

mzxchandra wants to merge 53 commits into
codex/file-ownership-foundationfrom
codex/project-files

Conversation

@mzxchandra

@mzxchandra mzxchandra commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add the complete Project-file backend: folders, uploads, edits, history, copy, recursive listing/downloads, extraction, search, compiled documents, sharing and realtime persistence callbacks.
  • Reuse authorized application operations across sessions, v2/CLI and delegated callers. Writes require an organization admin, an admin in an active environment, or write access in every active environment; workspace API keys do not acquire Project authority.
  • Preserve canonical ownership and revision checks through storage, history, billing, retention, cross-owner copies and content delivery. Public/password/email/SSO sharing rechecks current policy and dependencies.
  • Keep Project operations behind the existing release gates. Execution files remain workspace scoped; chat ownership remains personal/organization scoped.

Stacked on #8609 above #8590, with #8762 as the lifecycle prerequisite. This PR contains the backend, HTTP API, CLI, documentation and the public-share viewer required for content delivery. Stacked #8781 adds authenticated Project Files UI, picker/mentions and Sim-side Mothership integration; Mothership #594 is its separate worker companion. No additional migration is introduced here.

Type of Change

  • New feature

Testing

  • Integrated backend: 263 real-Postgres checks and 84 live HTTP checks across authorization, browser queries, history, sharing, rendering, copying and realtime.
  • Four additional HTTP checks verify recursive pagination, unchanged root browsing, cursor scope binding and rejection of conflicting folder filters.
  • Full backend root suite previously passed all 19 workspace tasks; the latest bounded route change passes formatting and all 58 repository audits. Full-repository checks for the published head run in CI.
  • Fresh migration/replay/schema-drift, generated artifacts and backend contract checks passed. Live paired product/worker acceptance additionally verifies the backend through actual model read/write/copy and browser delivery.
  • CI is manually dispatched for the stacked branch; workflow triggers and timeouts are unchanged.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Relevant tests updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 9, 2026 12:06am UTC

Request Review

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 485 files

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Re-trigger cubic

Comment thread apps/sim/lib/file-retention/workspace-versions.ts
Comment thread apps/sim/lib/api/contracts/v2/project-file-extraction.ts
Comment thread apps/sim/lib/api/contracts/v2/openapi/project-file-shares.ts Outdated
Comment thread apps/sim/lib/api/contracts/project-file-uploads.ts Outdated
Comment thread apps/sim/app/api/projects/[id]/files/[fileId]/csv-preview/route.ts Outdated
Comment thread apps/sim/app/workspace/[workspaceId]/files/components/file-viewer/text-editor.tsx Outdated
Comment thread apps/sim/lib/api/contracts/v2/openapi/files-audit.ts
Reuse entity-owned file operations across Project UI, session APIs, v2/CLI,
and delegated Mothership callers. Add Project discovery, sharing, history,
copy, collaborative editing, and current-access invalidation while preserving
workspace execution boundaries and independent creator/payer attribution.

Keep activation gated behind the file-ownership compatibility foundation.
Run real HTTP suites through disposable fixture orchestration in CI.
@greptile-apps

greptile-apps Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical impact] The PR appears safe to merge based on this review; no outstanding finding or new in-scope issue was established.

Summary

Adds Project-owned file operations across the application backend, HTTP and v2 APIs, CLI, public sharing, and realtime persistence. It also extends file ownership handling to storage, history, copying, billing, and retention.

  • Project-file access is checked through shared application operations.
  • The previously reported findings are resolved; no new in-scope finding was established.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Client[Browser / CLI / API] --> Routes[Project file routes]
  Routes --> Operations[Authorized application operations]
  Operations --> Storage[Files and revisions]
  Operations --> Policy[Project access policy]
  Operations --> Sharing[Public sharing]
  Operations --> Realtime[Realtime persistence]
Loading

Reviews (19) · Last reviewed commit: "Merge attribution foundation alignment i..." · Reviewed by Greptile

Comment thread apps/sim/lib/projects/files/application/authorization.ts Outdated
Comment thread apps/sim/app/workspace/[workspaceId]/files/project-files.tsx Outdated
@mzxchandra
mzxchandra force-pushed the codex/project-files branch from 547eb7b to a9fd086 Compare October 6, 2026 00:44
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 485 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 391 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 391 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 391 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 391 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 391 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — 09c8b209 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant