-- Migration: Add file_uploads tracking table for authenticated file access -- Closes audit findings 1.2 (S3 file auth) and 1.3 (local uploads auth) CREATE TABLE IF NOT EXISTS "file_uploads" ( "id" serial PRIMARY KEY NOT NULL, "organization_id" integer NOT NULL REFERENCES "organizations"("id") ON DELETE CASCADE, "uploaded_by" integer NOT NULL REFERENCES "users"("id") ON DELETE CASCADE, "file_key" varchar(500) NOT NULL, "original_name" varchar(500), "size_bytes" integer, "task_id" integer, "field_id" integer, "created_at" timestamp DEFAULT now() ); ALTER TABLE "file_uploads" ADD CONSTRAINT "file_uploads_file_key_key" UNIQUE ("file_key"); CREATE INDEX IF NOT EXISTS "file_uploads_org_idx" ON "file_uploads" ("organization_id"); CREATE INDEX IF NOT EXISTS "file_uploads_key_idx" ON "file_uploads" ("file_key");