## Block images

`POST /v1/pages/:pageId/blocks/:blockId/files`

Uploads an image as standard base64 only, JSON limit 40 MiB. Returns {fileId,url}; set nodes src to that URL. File is removed with its block. Non-image is 422.

Requires `landing` scope; READONLY keys receive 403 before Bitrix24 is called.

## Parameters

`pageId` and `blockId`: positive safe integers; the block must belong to the page. Optional query `scope=KNOWLEDGE|GROUP|MAINPAGE` selects the page context.

## Example

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/pages/42/blocks/7/files" \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"fileName":"pixel.png","contentBase64":"iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8/x8AAwMCAO+jRZkAAAAASUVORK5CYII="}'
```

## Response

```json
{
  "success": true,
  "data": {
    "fileId": 17,
    "url": "https://cdn.example.com/pixel.png"
  }
}
```

HTML is a data string: sanitize it before rendering. nodes/styles/attrs/cards absent in the Bitrix24 response become empty objects; stored values are visible in content.

## Errors

400 `INVALID_PARAMS` / `MISSING_REQUIRED_FIELDS` / `INVALID_SCOPE`; 403 `SCOPE_DENIED` / `WRITE_BLOCKED_READONLY_KEY`; 404 `ENTITY_NOT_FOUND`; 409 `LANDING_MODULE_NOT_ENABLED` / `PORTAL_ADDRESS_CHANGED`; 413 `PAYLOAD_TOO_LARGE`; 422 `BITRIX_ERROR`; 429 `LARGE_BODY_BACKEND_BUSY` / rate limit, 502, 503.
