- Shipped
- August 9, 2026 at 6:11 AM UTC
- Author
- Kamo
- Commit
- 3e21710
These are the only two things an organization stores that carry no size anywhere in the database — branding assets go straight into the public bucket under the organization's domain prefix, the docs workspace under its id — so both read as zero until something reads the object store back. Attribution runs backwards, prefix to organization. Deriving each organization's prefixes and scanning those would silently miss anything stored under a prefix nobody thought to derive; instead every top-level prefix is mapped back through widget, share, default, plus anything loose at the bucket root) lands in no customer's total. The members/ subtree is excluded deliberately. Avatars live under a fixed, organization-independent prefix by design, and counting the legacy per-domain copies would charge one organization for a file another organization's user owns. The trigger endpoint follows LosInternalApplyController: constant-time compare against the cluster secret, failing closed when it is unconfigured.