Sign a branding logo upload
Changed onSigns a branding_logos S3 upload for a caller with branding capability.
The shipped django-s3direct signing view (POST /s3direct/get_upload_params/) is a plain Django view authenticated only by session cookie -- it never reaches DRF's JWTAuthentication, so the JWT-only frontend SPA gets AnonymousUser there and is refused unconditionally. This view is the REST sibling of the GraphQL create_branding_logo_upload mutation (public_api.mutations.Mutation), reusing the same sign_branding_logo_upload signing helper so the S3 key/credential logic has one implementation.
Gated on organizations.manage_branding and the branding eligibility check (organizations.permissions.check_branding_read_eligibility -- parentless AND entitled) rather than on the write gate. The two admit the same set now that the write gate's slug condition is retired, but the split is kept: the frontend uploads a logo on file-picker change, before the branding PUT on form submit, so this surface deliberately depends on the read-side gate. Matches OrganizationBrandingView.get's read gate.
Request
- The document declares no server URL.
- Auth: one of:
- HTTP bearer
- API key in cookie sessionid
Headers
Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.
Request body
Response
Changes
- ○
endpoint added
- ○
- ▲
api path removed without deprecation
- ▲