List file attachments for a project
GET/api/projects/:id/files
List file attachments for a project. Project access and files.read in the project tenant are verified before metadata reads and URL signing.
Request
Responses
- 200
- 400
- 401
- 403
Successful response
A supplied taskId or issueId is not UUID-shaped. Rejected rather than ignored: dropping the filter would answer a request for one task’s files with every file in the project. Ordered after project authorization, so an inaccessible project still takes precedence.
Unauthorized — authentication credentials are missing or invalid
Project access or files.read in the project tenant is denied. Missing, malformed and inaccessible projects return the identical { error: "Forbidden", code: "FORBIDDEN" } body; a caller with project access but without files.read receives the nested MISSING_PERMISSION envelope with details.permission set to files.read. An invalid acting-organisation override uses the nested error envelope from the outer tenant wrapper.