An export archive is useful because the account owner can retrieve it. It becomes a different risk when it stays available indefinitely, outlives its status record, or remains half-written after a worker failure. Delivery therefore has its own lifecycle.
Give the export an explicit lifecycle
An export record moves through queued, processing, ready or partial, failed, and expired states. Each state says something a download controller and a background worker can enforce. “File exists” alone is not an authorization or availability state.
Use durable generation work
Inpages.me schedules export generation through Rails jobs backed by Solid Queue. A job writes the archive, verifies it, records the digest and summary, then schedules its purge. Durable job state makes restart and failure handling more explicit than a request that tries to hold an open response while building a large archive.
Limit ready artifacts to a delivery window
When an archive becomes ready, it receives an expiry time. Download authorization checks both the account owner and that remaining availability. The delivery file is not a recovery copy, and an expired link does not become valid merely because the database row still exists.
This complements the key boundary in Recovery Keys without server key access.
Sweep stale work as well as expired files
A periodic sweeper expires ready artifacts, fails queued or processing work that has exceeded its allowed lifetime, removes abandoned partial paths, and clears retained terminal status. This makes failed work observable without leaving delivery artifacts indefinitely on disk.
The archive itself is only available after the checks in verifying ZIP data exports before download.
Use codes, not private diagnostics, for user-visible failures
Storage pressure, a missing archive, or a timed-out generation must guide a support or retry path without returning internal filesystem details. The record keeps a constrained error code; logs still require careful operational access controls.
For the log boundary, read privacy-safe Rails logging.
Do not confuse portability with backup
A portable archive lets an account owner take a copy. It does not prove a tested restoration process, a geographically separate copy, or possession of the Recovery Key needed for protected data. The clear scope starts in account-scoped data exports.