Files
Files live in BSPK_FILE. Two blocks touch them: fieldInputFile puts one in, renderFile displays one.
Serving a file: authorisation by session grant
Images are public through /images/. Everything else — PDFs in particular — goes through /bspk-file, and its authorisation model is worth understanding because it is unusual.
The render is the authority. When renderFile.html emits an "open in a new tab" link, every display control has already been evaluated with the full context: block rights, page rights, domain rights, conditional display. At that moment the render records a grant:
Session.storage.vo_FileGrants[$fileUuid]:=Timestamp
The /bspk-file route then re-evaluates nothing. It serves the file if and only if the grant exists in that visitor's session (BSPK_WEB_ON_CONNECTION).
Why not check again? Because the route runs outside the render context: formulas that depend on process variables would produce false negatives, refusing files the visitor is legitimately looking at. A file never exposed by a visible block never gets a grant, so it can never be fetched.
In practice: a direct link to
/bspk-filefails in a fresh session, even for a file the user can see after loading the page. That is correct behaviour, not a bug: the page must render first.
Thumbnails
The dev panel's file manager gets its thumbnails from /bspk-thumb, served from BSPK_FILE.thumbnail, rather than inlining base64 in the markup. A zero-size BLOB means "no thumbnail, or a corrupt picture": it is not an error.
Thumbnails are generated lazily. After replacing an image, purge the derived images, or the old thumbnail keeps showing.
Writing a file through the API
The Claude API cannot write a BLOB. To replace an image, go through the version update method with the image in Resources/images/, then purge the derived images.
Also watch out for accents in an uploaded file name: on the curl side they need --data-binary @file, otherwise they arrive mangled.
File.name strips the extension
Use fullName. This one has silently produced files named invoice instead of invoice.pdf.
See also
- File — 26 properties, 15 of them conditional
- File input — upload, drag and drop, accepted types

