Delete an attached file for good (spec D133): the uploader, or a company admin for any file
delete_attachmentDelete an attached file for good (spec D133): the uploader, or a company admin for any file.
Removes the stored object and the attachment row at once — no trash, no restore (the web asks to confirm). Who: the person who uploaded it (uploaded_by) unless they are a viewer of the project; a company admin of the attachment's company for any file of an issue they can read (even as a viewer). An AI agent (token) only for files that same token uploaded (agent_token_id), never with admin power, and not when its user is a viewer. Allowed while the company is read-only or suspended (frees storage). Everyone else → 403 forbidden. Unknown id, a pending upload, or a project the caller cannot read → 404 not_found. Links to the file in the issue body or comments are not edited: they render as "file deleted". Publishes files.object.deleted and writes the audit event files.attachment_deleted (category content_delete, target {type: attachment, id, label: filename}).
Deletes an attached file for good (no undo); get the attachment_id from list_attachments. An agent may delete only files this same token uploaded (agent_token_id), else 403 forbidden. Ask the user before deleting.
You act with exactly the rights of the user who owns this token; a project you cannot see returns not_found.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| attachment_id | Yes |