Glossary
Plinks
Presigned URL
A URL that carries a signature and an expiry so a holder can GET or PUT without an account.
How it works
The signature is the credential. Anyone with the URL can use it until expiry. Early revoke means delete the object or retire the signing key. Clocks must be close or a fresh URL is already dead.
A worker signs a GET for 3 GB valid four hours. The client downloads once. A second URL signed for PUT lets a partner upload into one key. A leaked GET URL is not fixed by hiding it in the app. It works until 18:00.
How it differs
A presigned URL is the object-store form of an expiring link. An app-gated link can be revoked in a database. This cannot.
Signing with a powerful key widens the blast radius.
Sign with a scoped key.
On the ticket
- The practical close is a log line: time, actor, byte count, result.
- Without that line the transfer is a story.
- With it, the next person can see whether this door did what the ticket claimed.
- If the path is shared, say so in the partner profile so a later change does not silently pick a different limit, key, or region.
- On a real ticket, write down the door, the byte count, and the clock.
- For presigned url, that means naming the host or bucket, the expected size, and the time the other side must have a complete file.
- A progress bar is not that record.
- A 200 response that arrives before the complete call is not that record.
- If a retry is allowed, say how many and whether it resumes.
- If a person must approve the send, name the person.
- Partners who receive presigned url files should match on hash or size before they import.
- A same-length corrupt file passes a size check and fails a hash.
- Keep the published hash off the only channel an attacker can edit, or treat it as a corruption check rather than a substitution check.
- When the path changes, new key, new region, new cap, update the profile the same day so the next run does not use a stale limit.
Related
Sources
- AWS S3 user guide
Object store behavior