basalt / storage/src / TemporaryUploadUrlOptions
Interface: TemporaryUploadUrlOptions
Defined in: storage/src/index.ts:157
Options for Disk.temporaryUploadUrl.
Properties
allowedContentTypes?
> optional allowedContentTypes?: readonly string[]
Defined in: storage/src/index.ts:175
Facade-enforced allowlist for the declared contentType (like PutOptions.allowedContentTypes).
checksumSha256?
> optional checksumSha256?: string
Defined in: storage/src/index.ts:168
Base64-encoded SHA-256 of the body. Signed on S3 (S3 verifies it); unsupported on GCS.
contentLength?
> optional contentLength?: number
Defined in: storage/src/index.ts:166
Exact body size in bytes. Signed on S3; a size range on GCS; not bindable on Azure.
contentType
> contentType: string
Defined in: storage/src/index.ts:164
Required. The only Content-Type the upload may declare — signed into the URL, so the client cannot upload text/html to a URL minted for image/png.
endpoint?
> optional endpoint?: string
Defined in: storage/src/index.ts:189
Sign the URL for this base endpoint instead of the driver's own — the SAME bucket reached under another host.
The case this exists for: an isolated worker (or a browser) that must upload to a bucket it reaches under a different name than the API does — http://minio:9000 on a container network vs the app's public endpoint. Deployment concern, never client input: a signature minted for a host you do not control is a credential handed to that host.
S3 signs for it (region, path style and SSE unchanged); Azure and GCS refuse it — their SDKs derive the signed URL from the account/bucket host.
expiresIn
> expiresIn: DurationInput
Defined in: storage/src/index.ts:159
URL lifetime. Capped by maxTemporaryUploadUrlTtl (default 1 hour).
maxBytes?
> optional maxBytes?: number
Defined in: storage/src/index.ts:173
Facade-enforced cap on the declared contentLength (like PutOptions.maxBytes). When set, contentLength becomes mandatory — the signature is what enforces it.