Glossary

Plinks

Public link

A URL that serves the file to anyone who has it, with no account and no password.

The only secret is the URL itself. RFC 9110 lets a server answer GET with the representation and no challenge. If the server does not challenge, the link is public, whether or not the product screen said "private."

"Anyone with the link" is the product phrase for this. It is not private. People forward mail, chat logs retain URLs, and browser history keeps them. A long random path raises the cost of guessing. It does not stop a forward. Expiry and a download cap shrink the window. They do not change the fact that possession of the URL is the credential.

Worked example

A photographer puts a 2 GB gallery at `https://cdn.example/g/8f3a…` and marks it public so a magazine editor can grab it without an account. The editor's intern pastes it into a 40-person Slack channel. By evening the origin has served the gallery 600 times. There is no user to disable. The fix is link revocation: delete or replace the object, purge the CDN, and send a new path. An S3 account with Block Public Access on would have refused the public ACL in the first place. That account setting is a backstop against a bucket policy, not a property of the URL string.

A public link can still use HTTPS. Encryption in transit hides the bytes from the coffee-shop network. It does not hide them from the other 39 people in the channel. Search engines may index a public URL that is linked from a public page. An unguessable path that is never linked is obscure, not access-controlled. Obscurity holds only until the first forward.

Related

Sources

  1. RFC 9110, HTTP Semantics

    A GET needs no credential unless the server demands one

  2. AWS S3, Access control block public access

    Account-level block that stops a bucket from going public