AbsoluteJS

Secure Transfer Adapters

@absolutejs/secure-transfer-adaptersworkspacealphaPlatform & Infra

Interchangeable storage adapters for @absolutejs/secure-transfer.

#Installation

BASH
git clone https://github.com/absolutejs/secure-transfer-adapters.git

#Capabilities

Overview

Interchangeable storage adapters for @absolutejs/secure-transfer.

Package — Backend — Atomic create-only primitive

@absolutejs/secure-transfer-local — Local filesystem — same-filesystem hard link

Show 3 more

@absolutejs/secure-transfer-s3 — AWS S3, Cloudflare R2, MinIO, and compatible stores — PutObject with If-None-Match:

Both packages implement bounded, repeatable expiry sweeps for ciphertext left by crashed uploads. They deliberately do not emulate conditional creation with a HEAD followed by PUT; that sequence has a time-of-check/time-of-use race. They also provide trusted revocation stores with immutable, opaque tombstones and bounded retention sweeps. Keep their policy state separately permissioned from untrusted ciphertext storage.

The S3 behavior follows AWS's conditional-write guidance. Cloudflare's current R2 S3 compatibility table lists conditional PutObject operations, including If-None-Match, as supported.

Security

Storage sees opaque transfer IDs, record positions, sizes, and expiry times. It does not receive decryption capabilities or attachment metadata. Treat storage credentials as infrastructure secrets and restrict them to the configured prefix.

Repository composition

2 public packages and 0 private workspace projects are versioned and developed together.

Outcomes

What you can build

Overview

Interchangeable storage adapters for @absolutejs/secure-transfer.

Security

Storage sees opaque transfer IDs, record positions, sizes, and expiry times. It does not receive decryption capabilities or attachment metadata. Treat storage credentials as infrastructure secrets and restrict them to the configured prefix.

Hardening checklist

Production guidance

SecurityStorage sees opaque transfer IDs, record positions, sizes, and expiry times. It does not receive decryption capabilities or attachment metadata. Treat storage credentials as infrastructure secrets and restrict them to the configured prefix.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/secure-transfer-adapters example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#Workspace contents

2 public packages and 0 private workspace projects are maintained in this repository.

#Package commands

Scripts declared by this project’s package manifest.

bun run buildbun run --filter './*' build
bun run check:packagebun run --filter './*' check:package
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run testbun run --filter './*' test
bun run typecheckbun run --filter './*' typecheck
Workspace project
This workspace project is not published as a standalone npm package. Use its repository and the accurately labeled public or private workspace contents below.