AddThisFeature

Duplicate File Detection

Stop storing the same file over and over.

moderate Data & Content

What it adds

Content-hash deduplication of uploads within an ownership boundary, so identical bytes are stored once but tracked per record.

What your agent is told to do

6
  1. 1

    Hash the stored bytes on the server with a strong content hash, streaming rather than loading the whole file into memory.

  2. 2

    Never trust a filename, a size, or a client-supplied checksum as evidence of sameness. A client that can assert a hash can claim someone else's file.

  3. 3

    Deduplicate only within an explicit boundary — the tenant, the workspace, or the single owner. Sharing bytes across tenants leaks the fact that another tenant holds an identical file.

  4. 4

    Keep metadata separate from storage: filename, caption, uploader, timestamps, and permissions belong to each reference, not to the shared object.

  5. 5

    Reference-count the stored object and only delete the bytes when the last reference goes.

  6. 6

    Do NOT tell an uploader 'this file already exists' when the existing copy belongs to someone they cannot see. Deduplicate silently instead.

Edge cases it handles

7
  • Two uploads of the same file arriving at once must not both create the object — make the write conditional or unique-indexed.
  • A hash collision check that compares only hashes is fine for a modern hash; a check that compares only file size is not.
  • Deleting one record's copy must not remove the bytes another record still points at.
  • Files that are transformed after upload (compressed, watermarked) change hash — decide whether you dedupe the original, the derivative, or both.
  • Retention and legal-hold rules apply per reference; one tenant's deletion request cannot be satisfied by leaving shared bytes in place unless the boundary makes that lawful.
  • Encrypted-at-rest storage with per-tenant keys makes cross-record deduplication impossible; check before assuming it works.
  • Re-uploading a file the user deleted must work normally, not resurrect the old record's metadata.

Definition of done

8
  • Hashes are computed server-side from the stored bytes, streamed.
  • Client-supplied hashes are never trusted for deduplication decisions.
  • Deduplication never crosses the defined ownership boundary.
  • Each reference keeps its own filename, metadata, and permissions.
  • Stored bytes are removed only when the last reference is deleted.
  • Concurrent identical uploads produce exactly one stored object.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.