- upload-file use-case is now the single save path with dedup policy
(hash / bucket-key / none), partPrefix + signatureBuffer inputs,
fileHash in UploadOutput, and owned temp-file cleanup; pass temp
path (not open stream) to telegram service for testability
- upload-controller (multipart + JSON) and web-api upload delegate
to the use-case; JSON body via JsonUploadPayloadSchema; responses
built from use-case output via buildUploadResponse
- web-api download 302 redirect -> proxy stream (closes bot_token
leak); shared CORS + sanitizeFilenameHeader
- file-controller drops double file-info cache layer (pool caches)
- bot handler uses DI singletons instead of direct construction
- get-file RedirectRetrieval.redirectUrl marked deprecated, URL via
shared builder; chunked-storage URL via buildTelegramFileUrl
(no inline api.telegram.org/file/bot left in src/)