# createAccountPayableDocumentAttachment

## Overview

Creates an attachment metadata row (`AccountPayableDocumentAttachment`) for a vendor invoice and returns its `id`. The row's `file` file field is the storage slot for the binary: the caller follows up with an authenticated `PUT` of the file to the created record's `file.url`, and deletes the row again (via `deleteAccountPayableDocumentAttachment`) if that upload fails, so no orphan metadata is left behind.

Runs in a single transaction that locks the parent document (`FOR UPDATE`), verifies it exists, and enforces the per-document cap of 3 attachments before inserting. `originalFileName` is trimmed and must be non-blank. Requires the account-payable `updateAccountPayableDocument` permission.

## Modules Commands Used

- None. Direct TailorDB access — `AccountPayableDocumentAttachment` is an app-side table; no module command exists for attachment metadata.

## Exception Handling

| Error Code | Description |
| --- | --- |
| DomainError | Authentication is required, the caller lacks the update permission, the original file name is blank, the document does not exist, or the document already has 3 attachments. |
