Restrict rendered template artifacts

This commit is contained in:
2026-08-02 13:58:45 +02:00
parent b65b905b6e
commit 3551c48e14
6 changed files with 91 additions and 18 deletions
+6
View File
@@ -24,6 +24,12 @@ template, input, and output hashes. Otherwise Templates stores a bounded
database payload. Review database and Files retention together before deleting
render evidence.
Without Files, output payloads are bounded and retained by Templates. Ordinary
users can list and download only output they rendered themselves; a principal
with `templates:template:admin` can inspect all tenant render evidence. Consumer
modules must not redistribute the Templates download URL directly when their
resource access rules differ.
## Operations
Apply the module Alembic migration before startup. Monitor rejected renders for