feat(inbox): direct-to-storage upload for files over the hosted body limit (#1551) (#2030)

Hosted uploads larger than the 4 MB multipart ceiling (Vercel's 4.5 MB request-body cap) now go POST /upload/create (signed PUT URL, rate-limited) -> PUT to the raw Storage URL -> POST /upload/complete (server-side magic-byte and size validation, sha256, WORM move, idempotent), reusing the #1378 pending-upload primitives. uploadAndExtract is split into uploadDocument + processArchivedDocument so both paths share the inbox pipeline. Dokumentinkorgen and the supplier-invoice form use the new path only above the threshold; files that fit keep the multipart route. Cap stays at 10 MB (the issue asks for 20 MB: founder call). Refs #1551
This commit is contained in:
Jakob Wennberg
2026-08-30 11:55:42 +02:00
committed by GitHub
parent 523fba0419
commit 749f90fe62
14 changed files with 1391 additions and 53 deletions
+7 -1
View File
@@ -33,7 +33,13 @@ export const maxDuration = 60
const log = createLogger('api/storage-proxy')
/** Above every caller's own cap (MCP upload 10 MB, document max 20 MB). */
/**
* Above every caller's own cap (MCP upload 10 MB, document max 10 MB). The
* browser inbox path does not come through here at all: this handler buffers
* the PUT body inside a function, so on hosted it sits under the same 4.5 MB
* platform ceiling, and the browser PUTs to the raw signed Storage URL
* instead (lib/documents/direct-upload.ts).
*/
const MAX_UPLOAD_BYTES = 50 * 1024 * 1024
const REQUEST_HEADERS_FORWARDED = [