What a customer may attach¶
Photos are optional and can be switched off entirely. When they are on, these are the rules, and none of them is configurable — a second set of limits is how two screens learn to contradict each other.
| Rule | Value |
|---|---|
| Accepted names | .jpg, .jpeg, .png, .webp, .gif |
| Accepted contents | image/jpeg (stored as .jpg), image/png (stored as .png), image/webp (stored as .webp), image/gif (stored as .gif) |
| Largest one photo | 5.0 MB |
| Most per line | 3 |
| Most per request | 10 |
| An unsubmitted upload is swept after | 24 hours |
The contents decide, not the name. A file is accepted on what its bytes actually are, checked twice by two different means that have to agree, and it is stored under an extension derived from the verified type. The name the browser sent survives only as a label on the screen. There is no SVG: it is XML, and it is the one image format that can execute when a browser opens it.
Files are kept under your store's storage/returns_portal/photos/
directory, outside the web root, and are served only through the portal and
the admin — deliberately not under Tools > Uploads, which sweeps its own
directory and would empty a request you still hold the record of.