Module: OpenLoam::Attachable

Extended by:
ActiveSupport::Concern
Defined in:
lib/open_loam/attachable.rb

Overview

Files on a record, via ActiveStorage:

equipment.files.attach(io: File.open(path), filename: "manual.pdf")
equipment.files.each { |file| url_for(file) }

KNOWN BOUNDARY: ActiveStorage blobs live in global tables that OpenLoam does NOT tenant-scope. The association is scoped (a record only ever lists its own files, and the record is tenant-scoped), but a signed blob URL is a bearer capability: whoever holds the link can fetch the file, with no tenant check. Gate access at the record — through its policy — and treat attachment URLs as secrets rather than as addresses.