Multipart upload: Behavior and interfaces
Defines tenant-scoped resumable upload sessions with part checksums, expiry, complete-only-when-hash-matches, and abort cleanup so large files can resume without orphaned parts or cross-tenant keys.
Issues short-lived capability tokens for private objects, authorizes HTTP byte-range requests against the same token, forbids durable public URLs, and records the downloading identity in the audit trail.