Sending a file
Operations that take aFile are sent as multipart/form-data following the GraphQL multipart request spec. The server accepts this format natively.
The request body has three kinds of fields:
operations: a JSON string of the normal{ query, variables }payload, withnullin place of each file.map: a JSON string mapping each file field name to the dotted path(s) inoperationsit should fill, for example{ "0": ["variables.file"] }.- One form field per file, named as in
map.
operations field, and requires both operations and map to be JSON strings.
Client libraries that implement the spec (for example apollo-upload-client for Apollo) produce this format automatically when a variable holds a File or Blob; plain JSON is used when no variable holds a file.
Operations that accept a File include uploadChemicalSds, uploadEquipmentManual, uploadUserAvatar, uploadUserDocument, uploadIbcMeetingDocument, uploadMarkdownImage, processChemicalLabel, parseWasteManifest (a list of files) and CreateIncidentInput.photos. The reference lists every field typed File.
Validation
Every upload is validated before it is stored. A failed check is returned as a GraphQL error withextensions.code set as shown.
Each operation validates against one of five contexts:
image
image
image/png, image/jpeg, image/gif, image/webp. Used for incident photos.pdf
application/pdf.document
document
application/pdf, application/msword, application/vnd.openxmlformats-officedocument.wordprocessingml.document, application/x-iwork-pages-sffpages, image/png, image/jpeg.embed
embed
image/png, image/jpeg, image/gif, image/webp, video/mp4, video/webm. Used for the images and videos embedded in protocol steps.protocol-file
protocol-file
application/pdf, application/vnd.openxmlformats-officedocument.wordprocessingml.document, video/mp4, video/quicktime, video/webm, application/vnd.openxmlformats-officedocument.spreadsheetml.sheet, application/vnd.apple.numbers, text/csv.Reading a file back
Every uploaded file is identified by an opaque key that the API returns as a string.Incident.photos, for example, is declared as [File!]! on output as well as input, and on output it lists the keys of the incident’s photos. Treat keys as identifiers: their format is not part of the API and may change.
A file is read back from GET /files/<key> on the app host, using the same authentication as the API:
PNG, JPEG, GIF, WebP, PDF, MP4 and QuickTime files are served inline; every other type is served as a download.
The same pattern applies to every file the API hands back by key, such as protocol files and embedded images.