Upload Token System
Upload Token System
This is the authoritative reference for the generic public upload-token product implemented in skyhawk_site_fixes.
Architecture
- Public route:
/upload/{token}. - Admin route:
/admin/skyhawk/upload-tokens. - The public route is owned by
UploadTokenForm. - Drupal core
managed_fileowns file selection, AJAX transfer, validation, and temporary file entities. - Files are stored under
private://uploads/[token]/. - No custom synthetic mouse event or parallel direct-upload controller participates in the live product.
Token Lifecycle
- A token is valid when it exists, has status
active, and has not expired. - Generated tokens have a minimum lifetime of seven days.
- A token may be used for multiple upload sessions until expiry or explicit administrative revocation.
- A successful upload does not consume or invalidate the token.
uses_countrecords cumulative finalized files for administrative information only.uses_allowed = 0is retained as the unlimited-until-expiry/revocation sentinel for schema compatibility.
Upload Rules
- Multiple files may be selected.
- Maximum individual file size is 511 MiB (535,822,336 bytes).
- The hosting transport ceiling remains 512 MiB for an HTTP POST, so exceptionally large batches may need to be selected/uploaded separately even though each individual file is legal.
- After Drupal receives temporary managed files, final submission makes them permanent, records each file in
skyhawk_upload_file, increments cumulative file accounting, and sends the configured batch notification. - Completion notifications contain only the files finalized in that batch, not every historical file associated with the token.
Administration
- The admin form creates reusable tokens and sends the upload URL by email.
- The admin form can explicitly revoke an active token.
- Existing contact and purpose data are reused.
- The current history table remains operational; conversion to a Drupal View is a later Views-first improvement, not part of the uploader replacement.
Replacement State
The public and admin upload forms were replaced in toto after a discovery audit found contradictory one-use lifecycle logic, a redundant unrouted direct-upload controller, and a custom mobile workaround that duplicated Drupal core behavior.
The old UploadTokenController and upload_token_mobile_fix.js are retired into the timestamped replacement backup rather than destroyed during initial acceptance testing.
Functional acceptance remains pending until the Pixel test verifies: legal multi-file upload, final submission, private storage, history rows, notification, reuse of the same token, explicit revocation, expiry rejection, and oversize rejection.
Current Functional Failure
Proven working: The public Chatgpt 4 token page now uses Drupal core managed_file AJAX without custom AJAX or device-specific upload code. On the Pixel, one small file successfully AJAX-uploads into the widget, final submission makes the file permanent, the success message renders, and the same token remains active and reusable.
Current regression: Selecting the same three legal video files together, approximately 56.84 MB, 52.91 MB, and 120 MB (about 229.75 MB total), produces the managed-file spinning indicator and then returns to an empty No file chosen widget with a red validation state. Final submission therefore cannot begin for that batch.
Closed branches: Token validity, route ownership, single-file Pixel selection, Drupal core managed-file AJAX, temporary upload handling for a small file, final submission, redirect, success messaging, and reusable-token behavior are proven working and must not be reopened without contradictory evidence.
Current diagnostic boundary: Determine why the approximately 229.75 MB three-file AJAX request fails while the proven single-file request succeeds. Inspect PHP/LiteSpeed request ceilings, per-request transport state, Drupal errors, and file-entity aftermath before changing uploader code. No product redesign or device-specific workaround is authorized by this failure.
Current Regression Token
Chatgpt 4 remains the regression token while it is active and unexpired. Do not generate another token merely because an upload test fails.