A ZIP file can exist and still be the wrong artifact to hand to an account owner. It may be incomplete, contain an unexpected path, or lack the documentation needed to interpret an encrypted field. Verification belongs between generation and availability.
Write to a partial path first
The export builder writes a ZIP to a temporary partial path rather than its final delivery name. It adds data, attachment blobs, offline documentation, manifest material, and checksums before anything is marked ready.
This avoids a state where a download endpoint finds a filename that looks complete while a worker is still writing it.
Reject entries outside the expected root
Inpages.me’s archive verifier checks that every ZIP entry lives under the one expected archive root. Entries that escape that root are rejected. The check protects the format itself and makes an unexpected archive layout a visible failure rather than something a later extraction tool must guess about.
The general file-handling context is documented in the Rails Active Storage guide; the export verifier is application-specific because this archive has an explicit on-disk contract.
Make every archive explain itself
The manifest records the format version, included domains, attachment metadata, counts, failures, and the fact that recovery material is not embedded. Documentation in the ZIP explains how protected fields can be handled offline. A user should not have to infer these facts from filenames.
That contract begins with account-scoped data exports.
Use SHA-256 as an integrity reference
After the archive is complete, Inpages.me computes a SHA-256 value and stores it with the export record. This gives the download workflow a stable identifier for the bytes it made available. It does not authenticate an unknown sender or replace secure transport; it is a record of the generated artifact.
Leave no verified-looking failure behind
If generation or verification fails, the partial artifact is purged and the export becomes failed with a short structured error code. The system avoids placing raw path or private file details in a user-facing message. That same discipline is discussed in privacy-safe Rails logging.
Commit only after verification
Only a verified archive moves from the partial path to the final path and receives a ready status. A later job gives delivery a limited lifetime. Continue with short-lived export downloads with Solid Queue for the operational half of that boundary.