File Server
APIEngine's File Server is a generic upload / download / retrieve service for files associated with SBN entities - attachments, dealer logos, report artifacts, etc. Files are stored on disk under a configured base path and indexed in Sybase by GUID + tags.
Setup
In apiengine.settings, set FileServer.Path (SettingsDataObject.FileServer.Path, defined in APIEngine/API/_fileServer/FileServerDataClasses.cs) to the base directory, for example D:\Innovative\FileServer\ or a UNC share. The setter normalizes a trailing slash. On Windows the IIS application pool identity must have Modify permission on this path; on Linux (v96 and later) the account the APIEngine service runs as needs write access:
If FileServer.Path is empty, the model concatenates an empty base with the GUID, so files land relative to the worker process CWD - effectively broken. Always set FileServer.Path explicitly. (An older fallback to a file_server virtual directory under the site root exists in commented-out code only and is not active.)
Auth
Every File Server route requires a valid token. v96 and later accept an Authorization: Bearer <jwt> header or a User-Token: <jwt> header. v95 and earlier read only User-Token (header, then user-token query string or form field). See APIEngine/Authentication for token issuance.
Endpoints
| Verb | Route | Purpose |
|---|---|---|
| POST | /api/v1/fileserver/inject/{description?} | Upload one file. Body: multipart/form-data. Query string: tag key/value pairs. Returns the assigned GUID. |
| GET | /api/v1/fileserver/retrieve/{guid} | Download the file by GUID. |
| GET | /api/v1/fileserver/retrieve/thumbnail/{guid} | Return a PNG thumbnail of the file. |
| GET | /api/v1/fileserver/list | List files matching all tag filters supplied in the query string. |
| GET | /api/v1/fileserver/list/showhidden | Same as list, but includes soft-deleted files. |
| GET / POST / DELETE | /api/v1/fileserver/delete/{guid} | Soft-delete (file remains on disk; flagged hidden). |
| GET / POST | /api/v1/fileserver/undelete/{guid} | Reinstate a soft-deleted file. |
| GET / PATCH | /api/v1/fileserver/update/{guid} | Replace the tag set on a file (new tags via query string). Reserved security tags are skipped. |
| GET / PATCH | /api/v1/fileserver/audit/guid/{value} | List users who have accessed a given file. |
| GET / PATCH | /api/v1/fileserver/audit/user/{value} | List files a given user has accessed. |
| GET | /api/v1/fileserver/verify/{guid} | Authenticity check (file present + matches index). |
The routes are the same in v95 and v96 and later. Source:APIEngine/API/_fileServer/FileServerController.cs. Theauditaction binds both routes to a single{value}parameter and discriminates by inspecting the path foruser.updateandauditacceptPATCHin addition toGET;deletealso acceptsPOSTandDELETE.
Tags
Tags are arbitrary key/value pairs supplied via query string on inject, list, and update. Invalid characters in tag keys (e.g. #) are normalized to _ on store - so ?s#ins=1 is indexed as s_ins=1. Use the underscore form when querying.
inject requires at least one tag, and at least one of those tags must be a security tag (unless the caller passes ForceTagSecurity=false internally). The current security-tag set is:
s_ins, alid, alaid, cid, s_wo, s_inc, floorplan, s_ctr, s_acc, quote_no, s_comm, deal, deal_id, s_br
GUID format
The returned GUID is a plain UUID (Guid.NewGuid().ToString("D"), e.g. 4567524b-aa12-4f0a-9b8e-2c1d3e4f5a6b) - no extension is appended. Subsequent calls (retrieve, delete, update, etc.) take the bare GUID. The original filename is stored separately in the index and recovered server-side; the on-disk path is <FileServer.Path>\<guid>\<original-filename> with a sibling thumbnail file when one was generated.
History: an earlier revision did append.<ext>to the GUID; the change marker08.94.12527 - guid no longer needs extension(seeFileServerModel.csheader) records the switch.