Application boundary#
These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
GET/api/files⌄
Files.
- Authentication
- session
- Permission
- files.read
- Request body
- none
- Query parameters
- session_only=True, limit=100
- Headers
- none beyond shared session/CSRF
- Response structure
{files, allowed_extensions, content_parsing}- Important errors
- 403, 409
- Approval behavior
- file HTTP permissions requiring approval fail 409; no one-time approval implementation.
Verified route registration · handler api_files. Some definitions may be partially redacted; no missing fields are inferred.
POST/api/files⌄
File upload.
- Authentication
- session
- Permission
- files.upload
- Request body
- raw upload stream, not multipart; filename is a required query parameter; content-type header is read
- Query parameters
- filename (required)
- Headers
- content-type
- Response structure
{ok, file, content_parsing}- Important errors
- 400, 403, 409
- Approval behavior
- file HTTP permissions requiring approval fail 409; no one-time approval implementation.
Verified route registration · handler api_file_upload. Some definitions may be partially redacted; no missing fields are inferred.
GET/api/files/{file_id}⌄
File download.
- Authentication
- session
- Permission
- files.read
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
FileResponse(path, media_type=record.mime_type, filename=record.original_name)- Important errors
- 403, 404, 409
- Approval behavior
- file HTTP permissions requiring approval fail 409; no one-time approval implementation.
Verified route registration · handler api_file_download. Some definitions may be partially redacted; no missing fields are inferred.
DELETE/api/files/{file_id}⌄
File delete.
- Authentication
- session
- Permission
- files.delete
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
{ok, file}- Important errors
- 403, 404, 409
- Approval behavior
- file HTTP permissions requiring approval fail 409; no one-time approval implementation.
Verified route registration · handler api_file_delete. Some definitions may be partially redacted; no missing fields are inferred.
GET/api/files/{file_id}/media⌄
Video media.
- Authentication
- session
- Permission
- files.read
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
FileResponse(path, media_type=media[record.extension], headers={'Cache-Control': 'private, no-store', 'X-Content-Type-Options': 'nosniff', 'Content-Disposition': "inline;- Important errors
- 403, 409
- Approval behavior
- file HTTP permissions requiring approval fail 409; no one-time approval implementation.
Verified route registration · handler video_media. Some definitions may be partially redacted; no missing fields are inferred.
Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.