Overview
Interchangeable storage adapters for @absolutejs/secure-transfer.
@absolutejs/secure-transfer-adaptersworkspacealphaPlatform & InfraInterchangeable storage adapters for @absolutejs/secure-transfer.
git clone https://github.com/absolutejs/secure-transfer-adapters.gitInterchangeable storage adapters for @absolutejs/secure-transfer.
Package — Backend — Atomic create-only primitive
@absolutejs/secure-transfer-local — Local filesystem — same-filesystem hard link
@absolutejs/secure-transfer-s3 — AWS S3, Cloudflare R2, MinIO, and compatible stores — PutObject with If-None-Match:
Both packages implement bounded, repeatable expiry sweeps for ciphertext left by crashed uploads. They deliberately do not emulate conditional creation with a HEAD followed by PUT; that sequence has a time-of-check/time-of-use race. They also provide trusted revocation stores with immutable, opaque tombstones and bounded retention sweeps. Keep their policy state separately permissioned from untrusted ciphertext storage.
The S3 behavior follows AWS's conditional-write guidance. Cloudflare's current R2 S3 compatibility table lists conditional PutObject operations, including If-None-Match, as supported.
Storage sees opaque transfer IDs, record positions, sizes, and expiry times. It does not receive decryption capabilities or attachment metadata. Treat storage credentials as infrastructure secrets and restrict them to the configured prefix.
2 public packages and 0 private workspace projects are versioned and developed together.
Outcomes
Interchangeable storage adapters for @absolutejs/secure-transfer.
Storage sees opaque transfer IDs, record positions, sizes, and expiry times. It does not receive decryption capabilities or attachment metadata. Treat storage credentials as infrastructure secrets and restrict them to the configured prefix.
Hardening checklist
Follow in order
2 public packages and 0 private workspace projects are maintained in this repository.
Scripts declared by this project’s package manifest.