Plinks
Private link
A URL that serves the file only after the server checks a credential tied to a person or a service, and refuses everyone else.
RFC 9110 uses 401 when authentication is missing and 403 when the authenticated caller is not allowed. A private link that returns the file to a logged-out browser is a public link with a misleading label.
The credential is the difference from a public link and from a password link. A public link's secret is the URL. A password link's secret is a shared word. A private link's secret is an account the server can disable: a user session, a signed-in email, an OAuth token. Forwarding the URL does not forward the access. The recipient's colleague hits the same path and gets a login page.
A law firm drops a 500 MB production set at a path only `ada@client.example` may read. Ada opens it on the firm portal, the session cookie is checked, the GET proceeds. She forwards the URL to a teammate. The teammate's browser has no session, the server returns 401, and the access log shows the deny. If the app instead set a cookie that any visitor received, the forward works and the private label was decorative. Disabling Ada's account at 18:00 stops her next download. It does not delete the copy she saved at 17:00.
Private does not mean encrypted at rest, and it does not mean the administrator cannot read the object. It means the request had to name an allowed identity. Service accounts count. A nightly job with a key is a private fetch if the key is scoped to that prefix and can be revoked. A job with the bucket root key is private in name and universal in practice. AC-3 in SP 800-53 is the control family for that enforcement: the system allows the approved identity and denies the rest, and someone can show the rule.
Related
Sources
- RFC 9110, HTTP Semantics
401 and 403 when the client lacks credentials
- NIST SP 800-53 Rev. 5, AC-3
Access enforcement on an authorized identity