File Upload & Scanning Pipeline · View 13 of 21 · Runtime
The two messages that matter
- Message 11 returns 202 with state scanning — the client is told the truth rather than success, which is what makes an honest product surface possible
- Message 19 re-checks state and authorisation at download-credential issuance, not once at upload: without it, a revoked verdict cannot stop a reader who already has a link
- The alternate at the end is the discipline: a bound hit yields indeterminate, never clean, which is the difference between a scanner and a rubber stamp
Decisions
- Admission runs before any credential is minted, so every refusable condition is refused at a cost of one HTTP call
- Finalisation asserts the block set and the whole-object hash, and the platform refuses to assemble a mismatch
- The queue lease is sized to the slowest permitted scan for the object's class, so a long legitimate scan is never redelivered as a duplicate
Stated assumptions
- Interactive lane, object under 10 MB: p50 2 s, p95 8 s, p99 30 s
- Write credential 60 minutes, renewable in session; read credential 5 minutes
- At-least-once delivery with idempotent verdict writes