Private files
Every file in Fóir is public or private, and the setting belongs to the file. A public file is served from a plain URL, and a private file through a signed link that expires.
How each kind is served
A public file has a direct URL that the CDN can cache and anyone holding the link can fetch. A private file's URL carries a signed token, and the CDN refuses a request without a valid one. A token opens one file and expires, after an hour by default. Keep the file's id and read its URL again when you need it, because an older URL stops working.
A file has its own owner and visibility
Both are set on the file, and referencing it from a record changes neither. A public file stays fetchable by its URL whatever the visibility of the record that points at it.
When a record that references a private file is read, Fóir signs the file's URL only if the caller may reach the file itself. Otherwise the URL goes out unsigned and the CDN refuses it.
Defaults
The default follows ownership. A file owned by one of your users is stored private, whether they uploaded it or an operation they triggered created it. A file no user owns is stored public, which covers uploads by your team, with a secret key or by an organisation. Naming a visibility at upload overrides the default.
Changing visibility and listing
setFileVisibility moves a stored file between public and private. It needs the files:write scope and works only for a caller allowed to edit that file.
Listing is decided separately from serving. A signed-in user lists their own files and the shared library, and another user's private file reads as null. Listing across every user takes a secret key with the files:list.all scope.
Private video
A private video is covered end to end. Its thumbnail, preview and HLS manifest are signed, and the token is carried onto every rendition and segment.
Read the detail
The files reference covers visibility, the default for each kind of upload, signed URLs and who can list which files.