Restrict rendered template artifacts
This commit is contained in:
@@ -24,6 +24,12 @@ template, input, and output hashes. Otherwise Templates stores a bounded
|
||||
database payload. Review database and Files retention together before deleting
|
||||
render evidence.
|
||||
|
||||
Without Files, output payloads are bounded and retained by Templates. Ordinary
|
||||
users can list and download only output they rendered themselves; a principal
|
||||
with `templates:template:admin` can inspect all tenant render evidence. Consumer
|
||||
modules must not redistribute the Templates download URL directly when their
|
||||
resource access rules differ.
|
||||
|
||||
## Operations
|
||||
|
||||
Apply the module Alembic migration before startup. Monitor rejected renders for
|
||||
|
||||
Reference in New Issue
Block a user