Frontend now uploads media directly to MinIO and sends only the
resulting object_key; the backend never touches file bytes. Mattermost
post bodies carry "<type>:<object_key>" instead of a permanent public
URL, and download links are signed fresh on every read (send + list)
so they can't outlive their expiry. Also wires up MINIO_SECURE, which
settings.py previously never read from env.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>