Module: OpenLoam::Attachable
- Extended by:
- ActiveSupport::Concern
- Defined in:
- lib/open_loam/attachable.rb
Overview
Files on a record, via ActiveStorage:
equipment.files.attach(io: File.open(path), filename: "manual.pdf")
equipment.files.each { |file| url_for(file) }
KNOWN BOUNDARY: ActiveStorage blobs live in global tables that OpenLoam does NOT tenant-scope. The association is scoped (a record only ever lists its own files, and the record is tenant-scoped), but a signed blob URL is a bearer capability: whoever holds the link can fetch the file, with no tenant check. Gate access at the record — through its policy — and treat attachment URLs as secrets rather than as addresses.