Branding

Sign a branding logo upload

Changed on

Signs a branding_logos S3 upload for a caller with branding capability.

The shipped django-s3direct signing view (POST /s3direct/get_upload_params/) is a plain Django view authenticated only by session cookie -- it never reaches DRF's JWTAuthentication, so the JWT-only frontend SPA gets AnonymousUser there and is refused unconditionally. This view is the REST sibling of the GraphQL create_branding_logo_upload mutation (public_api.mutations.Mutation), reusing the same sign_branding_logo_upload signing helper so the S3 key/credential logic has one implementation.

Gated on organizations.manage_branding and the branding eligibility check (organizations.permissions.check_branding_read_eligibility -- parentless AND entitled) rather than on the write gate. The two admit the same set now that the write gate's slug condition is retired, but the split is kept: the frontend uploads a logo on file-picker change, before the branding PUT on form submit, so this surface deliberately depends on the read-side gate. Matches OrganizationBrandingView.get's read gate.

post/branding/logo-upload-params/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Request body

file_namestring required
file_typestring required
file_sizeinteger required

Response

object_keystring required
upload_urlstring uri required
expires_ininteger required

Changes