- Staged files are now served through a signed URL (Django signing, 24h) so <img>/<video> tags can load previews without an Authorization header; the file endpoint accepts header auth or a valid signature, rejects tampered signatures, and still scopes access to the owner - Serializer responses now carry the request context so URLs are signed per user - Add .webp to the allowed extensions (backend + upload hint)