Glossary

Blinks

Branded download page

A web page the recipient sees before a file download, with your name, the filename, and the expiry.

How it works

The page is not the file. It can require a password, show a hash, and then 302 to the object. A raw object URL skips the page and the instructions. Track clicks on the page separately from completed downloads.

A client opens a page showing a 2.4 GB name, a hash, and a 6-hour clock, then clicks download. A direct object URL in an old mail still works and shows no filename warning. They expire the raw URL and keep the page.

How it differs

A branded page is not a portal. There may be no account. It is one delivery's front door.

A page that only looks at the file and never links a download wastes the visit.

Put the hash on the page.

On the ticket

  • The practical close is a log line: time, actor, byte count, result.
  • Without that line the transfer is a story.
  • With it, the next person can see whether this door did what the ticket claimed.
  • If the path is shared, say so in the partner profile so a later change does not silently pick a different limit, key, or region.
  • On a real ticket, write down the door, the byte count, and the clock.
  • For branded download page, that means naming the host or bucket, the expected size, and the time the other side must have a complete file.
  • A progress bar is not that record.
  • A 200 response that arrives before the complete call is not that record.
  • If a retry is allowed, say how many and whether it resumes.
  • If a person must approve the send, name the person.
  • Partners who receive branded download page files should match on hash or size before they import.
  • A same-length corrupt file passes a size check and fails a hash.
  • Keep the published hash off the only channel an attacker can edit, or treat it as a corruption check rather than a substitution check.
  • When the path changes, new key, new region, new cap, update the profile the same day so the next run does not use a stale limit.