Asset library

Each project has a media library. A file is uploaded once and gets a stable id, and any record's image, video or file field refers to it by that id.

How an upload works

An upload has three steps. createFileUpload returns an upload URL that is valid for an hour, the client sends the bytes straight to storage, and a confirm call returns the file. The bytes never pass through the GraphQL endpoint. This route has no per-file size limit, and the check at confirmation is against your storage allowance. A single-call REST upload takes small files, up to 10 MB.

A signed-in user's browser can run the whole upload with a public key and that user's own token. The file is then theirs, and private by default.

What is read from an image

For JPEG, PNG, WebP and GIF, Fóir extracts the width, the height, a blurhash placeholder and a dominant colour when the upload is confirmed. An image field returns all four beside the URL. Other sizes and formats come from image transformations.

Folders, alt text and the CLI

A file can sit in a folder and carry alt text, and the public API returns both with the file. From a terminal, foir media uploads, lists, updates, deletes and restores files.

Deleting and restoring

A delete is soft, and a restore undoes it. Removing the stored object is a separate, permanent delete. Deleting needs the files:delete scope, which write access to files does not imply.

What is refused

HTML, JavaScript and XML uploads are refused. SVG is accepted, and one opened directly is served as a download under a policy that blocks scripts.

Read the detail

The media guide covers uploads, visibility, the CLI commands, crops and video.