AbsoluteJS

@absolutejs/secure-transfer-s3

@absolutejs/secure-transfer-s3v0.2.2betaPlatform & Infra

Atomic AWS S3 and Cloudflare R2 storage adapter for @absolutejs/secure-transfer.

#Installation

BASH
bun add @absolutejs/secure-transfer-s3

#Capabilities

Overview

AWS SDK storage adapter for @absolutejs/secure-transfer. It also works with S3-compatible services such as Cloudflare R2 when the SDK client is configured with that service's endpoint and credentials.

Writes use If-None-Match: ; a precondition failure becomes "exists" and is never retried as an unconditional write. Transient 409 conflicts are retried with the condition still attached, following AWS guidance. Configure bucket lifecycle expiration as defense in depth, and run sweepExpired() with its continuation cursor for a testable application-level cleanup path.

Protected receipts use ETags as compare-and-swap versions. Lease acquisition and checkpoint updates use If-Match; creation uses If-None-Match: . Completion first installs a conditional tombstone so a stale resumer cannot revive state, then removes it. Run sweepExpiredReceipts() for abandoned receipt state.

Show 2 more

Revocation tombstones use conditional create-only writes, opaque SHA-256 keys, and required-retention metadata. Prefer a separately permissioned policy bucket; download authorization fails safely only when clients can trust this state. Run sweepExpiredRevocations() until its cursor is exhausted after retention ends.

Cloud credentials and paid object storage are bring-your-own. Managed credentials and scheduled lifecycle operations belong in AbsoluteJS PaaS.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/secure-transfer-s3 through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/secure-transfer-s3 version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/secure-transfer-s3 example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#@absolutejs/secure-transfer-s3 quick start

Partial snippet

# @absolutejs/secure-transfer-s3

TS
import { S3Client } from "@aws-sdk/client-s3";
import {
  s3ProtectedReceiptStore,
  s3SecureTransferRevocationStore,
  s3SecureTransferStore,
} from "@absolutejs/secure-transfer-s3";

const store = s3SecureTransferStore({
  bucket: "private-ciphertext",
  client: new S3Client({ region: "us-east-1" }),
  prefix: "secure-transfer/",
});
const receiptStore = s3ProtectedReceiptStore({
  bucket: "private-ciphertext",
  client: new S3Client({ region: "us-east-1" }),
  prefix: "secure-transfer/",
});
const revocations = s3SecureTransferRevocationStore({
  bucket: "trusted-transfer-policy",
  client: new S3Client({ region: "us-east-1" }),
});

#Public entry points

Supported entry points declared by this package manifest.

Package entry point declared in package.json.

@absolutejs/secure-transfer-s3@absolutejs/secure-transfer-s3/manifest@absolutejs/secure-transfer-s3/manifest.json

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --root src --sourcemap --target=bun --external @absolutejs/secure-transfer --external @aws-sdk/client-s3 --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

5 symbols
s3ProtectedReceiptStoreexportPermalinkSource
TS
s3ProtectedReceiptStore
Exported from @absolutejs/secure-transfer-s3