Skip to content

feat(intake): upload a request and enqueue processing atomically #5

Description

@Fluory

Goal

A clerk uploads an e-mail or loose documents. The system stores the originals privately, creates the request and its documents (status NEW) and enqueues processing in the same transaction; exact duplicates are flagged, never discarded.

Acceptance criteria

  • Upload accepts .eml, .msg, .pdf, .xlsx, .docx up to a configured size; other types are rejected with a clear message
  • Originals are stored under {companyId}/{requestId}/{documentId} in a private bucket; download only through an authenticated route with tenant check
  • Request, documents and the pg-boss job are committed in one transaction – a failure after the insert rolls back all three
  • Same Message-ID or same SHA-256 set within the company → request flagged as possible duplicate
  • Upload is recorded as an audit event

Not part of this task

  • Mailbox import, near-duplicate hints, the processing itself

Affected areas

  • src/features/intake/
  • src/features/documents/
  • src/features/storage/
  • src/features/audit/

Test plan

Criterion Check
atomic create + enqueue integration test with forced failure
duplicate fingerprint unit test
private access integration test: other tenant gets 404

Security/Privacy affected?

Yes – file upload (size/type limits), tenant-scoped storage paths, no public URLs.

Epic: #2 · Architecture: docs/decisions/ADR-0001-pilot-architecture.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

featureNew capabilityreadyDefinition of Ready met – may be claimedsecuritySecurity or privacy relevant

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions