Private file uploads
Activate bounded meal-image and voice uploads without exposing user content.
The production upload adapter is designed for the two included use cases—not as a public file manager. It uploads private meal images and temporary voice audio under the current user's identity.
Meal-image path
Before upload, the app reads only the selected file, normalizes it to a bounded JPEG, strips original metadata, and uses a cryptographically random path under the user ID. Supabase Storage remains private and Row Level Security blocks cross-user access.
Voice path
Voice recordings are capped at 60 seconds and 10 MB. They are temporary inputs for transcription, not a permanent audio library.
Prompt
Read agent-skills/wire-file-uploads.md and agent-skills/wire-ai-voice.md. Activate
the included private Supabase upload adapters. Apply the migration, keep both
buckets private, verify user-scoped RLS, preserve file bounds and immediate
cleanup, and schedule orphan cleanup every 15–30 minutes.Do not make the bucket public to fix an access error. The server creates a short-lived signed URL only after verifying ownership, type, and size.
Verify
Test JPEG, PNG, WebP, large/corrupt/unsupported files, your explicit HEIC decision, permission denial, offline/interrupted upload, repeated cleanup, signed-URL expiry, and account deletion. Attempt list/read/delete as another user and confirm it fails.
No local path, signed URL, raw image, or raw audio should appear in analytics, Sentry, or application logs.