Skip to content
YAADMIN
Download

APPLICATION REFERENCE

Files API

5 verified files routes: authentication, fields, responses, errors and approval boundaries.

VerifiedSource snapshot · 2026-10-02

Application boundary#

These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.

Verified routes#

5 routes

GET/api/files

Files.

Authentication
session
Permission
files.read
Request body
none
Query parameters
session_only=True, limit=100
Headers
none beyond shared session/CSRF
Response structure
{files, allowed_extensions, content_parsing}
Important errors
403, 409
Approval behavior
file HTTP permissions requiring approval fail 409; no one-time approval implementation.

Verified route registration · handler api_files. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/files

File upload.

Authentication
session
Permission
files.upload
Request body
raw upload stream, not multipart; filename is a required query parameter; content-type header is read
Query parameters
filename (required)
Headers
content-type
Response structure
{ok, file, content_parsing}
Important errors
400, 403, 409
Approval behavior
file HTTP permissions requiring approval fail 409; no one-time approval implementation.

Verified route registration · handler api_file_upload. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/files/{file_id}

File download.

Authentication
session
Permission
files.read
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
FileResponse(path, media_type=record.mime_type, filename=record.original_name)
Important errors
403, 404, 409
Approval behavior
file HTTP permissions requiring approval fail 409; no one-time approval implementation.

Verified route registration · handler api_file_download. Some definitions may be partially redacted; no missing fields are inferred.

DELETE/api/files/{file_id}

File delete.

Authentication
session
Permission
files.delete
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, file}
Important errors
403, 404, 409
Approval behavior
file HTTP permissions requiring approval fail 409; no one-time approval implementation.

Verified route registration · handler api_file_delete. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/files/{file_id}/media

Video media.

Authentication
session
Permission
files.read
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
FileResponse(path, media_type=media[record.extension], headers={'Cache-Control': 'private, no-store', 'X-Content-Type-Options': 'nosniff', 'Content-Disposition': "inline;
Important errors
403, 409
Approval behavior
file HTTP permissions requiring approval fail 409; no one-time approval implementation.

Verified route registration · handler video_media. Some definitions may be partially redacted; no missing fields are inferred.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.