Build on the supported package contract
Use @absolutejs/secure-transfer-s3 through its supported public entry points.
@absolutejs/secure-transfer-s3v0.2.2betaPlatform & InfraAtomic AWS S3 and Cloudflare R2 storage adapter for @absolutejs/secure-transfer.
bun add @absolutejs/secure-transfer-s3AWS SDK storage adapter for @absolutejs/secure-transfer. It also works with S3-compatible services such as Cloudflare R2 when the SDK client is configured with that service's endpoint and credentials.
Writes use If-None-Match: ; a precondition failure becomes "exists" and is never retried as an unconditional write. Transient 409 conflicts are retried with the condition still attached, following AWS guidance. Configure bucket lifecycle expiration as defense in depth, and run sweepExpired() with its continuation cursor for a testable application-level cleanup path.
Protected receipts use ETags as compare-and-swap versions. Lease acquisition and checkpoint updates use If-Match; creation uses If-None-Match: . Completion first installs a conditional tombstone so a stale resumer cannot revive state, then removes it. Run sweepExpiredReceipts() for abandoned receipt state.
Revocation tombstones use conditional create-only writes, opaque SHA-256 keys, and required-retention metadata. Prefer a separately permissioned policy bucket; download authorization fails safely only when clients can trust this state. Run sweepExpiredRevocations() until its cursor is exhausted after retention ends.
Cloud credentials and paid object storage are bring-your-own. Managed credentials and scheduled lifecycle operations belong in AbsoluteJS PaaS.
Outcomes
Use @absolutejs/secure-transfer-s3 through its supported public entry points.
Hardening checklist
Follow in order
# @absolutejs/secure-transfer-s3
import { S3Client } from "@aws-sdk/client-s3";
import {
s3ProtectedReceiptStore,
s3SecureTransferRevocationStore,
s3SecureTransferStore,
} from "@absolutejs/secure-transfer-s3";
const store = s3SecureTransferStore({
bucket: "private-ciphertext",
client: new S3Client({ region: "us-east-1" }),
prefix: "secure-transfer/",
});
const receiptStore = s3ProtectedReceiptStore({
bucket: "private-ciphertext",
client: new S3Client({ region: "us-east-1" }),
prefix: "secure-transfer/",
});
const revocations = s3SecureTransferRevocationStore({
bucket: "trusted-transfer-policy",
client: new S3Client({ region: "us-east-1" }),
});Supported entry points declared by this package manifest.
Package entry point declared in package.json.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.