# Change history: Upload

[← Changelog](/docs/changelog). Entries: 15.

- 2026-10-01 [NEW-1001-8: file size refusal on upload carries a hint](/docs/changelog/2026-10-01#new-1001-8-file-size-refusal-on-upload-carries-a-hint)
- 2026-09-16 [FIX-0916-9: storage: a file uploaded again under the same key no longer counts as several objects](/docs/changelog/2026-09-16#fix-0916-9-storage-a-file-uploaded-again-under-the-same-key-no-longer-counts-as-several-objects)
- 2026-09-14 [BC-0914-2: storage object delete and list received a per-account request limit](/docs/changelog/2026-09-14#bc-0914-2-storage-object-delete-and-list-received-a-per-account-request-limit)
- 2026-09-14 [BC-0914-7: storage object listing no longer counts the full set by default](/docs/changelog/2026-09-14#bc-0914-7-storage-object-listing-no-longer-counts-the-full-set-by-default)
- 2026-09-07 [FIX-0907-9: multipart upload replaces a large object under its existing key](/docs/changelog/2026-09-07#fix-0907-9-multipart-upload-replaces-a-large-object-under-its-existing-key)
- 2026-09-04 [FIX-0904-6: expiresAt of presigned URLs now equals their signature lifetime](/docs/changelog/2026-09-04#fix-0904-6-expiresat-of-presigned-urls-now-equals-their-signature-lifetime)
- 2026-09-03 [BC-0903-6: an app key without an employee session reads only app-shared files by name](/docs/changelog/2026-09-03#bc-0903-6-an-app-key-without-an-employee-session-reads-only-app-shared-files-by-name)
- 2026-09-03 [FIX-0903-8: a multipart upload distinguishes who holds the logical name](/docs/changelog/2026-09-03#fix-0903-8-a-multipart-upload-distinguishes-who-holds-the-logical-name)
- 2026-09-01 [FIX-0901-6: direct upload can be repeated after object deletion](/docs/changelog/2026-09-01#fix-0901-6-direct-upload-can-be-repeated-after-object-deletion)
- 2026-08-28 [BC-0828-7: incomplete public uploads are no longer anonymously accessible](/docs/changelog/2026-08-28#bc-0828-7-incomplete-public-uploads-are-no-longer-anonymously-accessible)
- 2026-08-28 [FIX-0828-9: concurrent direct uploads of one object are coordinated](/docs/changelog/2026-08-28#fix-0828-9-concurrent-direct-uploads-of-one-object-are-coordinated)
- 2026-08-25 [BC-0825-2: a read-only key no longer writes on platform endpoints](/docs/changelog/2026-08-25#bc-0825-2-a-read-only-key-no-longer-writes-on-platform-endpoints)
- 2026-08-25 [BC-0825-5: re-uploading a file now replaces its content instead of failing with 500](/docs/changelog/2026-08-25#bc-0825-5-re-uploading-a-file-now-replaces-its-content-instead-of-failing-with-500)
- 2026-07-10 [FIX-0710-24: storage: object sha256 is populated on direct upload](/docs/changelog/2026-07-10#fix-0710-24-storage-object-sha256-is-populated-on-direct-upload)
- 2026-07-05 [FIX-0705-3: multipart/create rejects XSS-prone content types for PUBLIC objects](/docs/changelog/2026-07-05#fix-0705-3-multipart-create-rejects-xss-prone-content-types-for-public-objects)
