Skip to content

basalt / storage/src / TemporaryUrlOptions

Interface: TemporaryUrlOptions ​

Defined in: storage/src/driver.ts:124

How a pre-signed URL serves the object. The Disk layer always passes an explicit value — 'attachment' unless the caller deliberately opts into 'inline' — so a client-declared text/html or SVG object can never render top-level off the bucket/CDN origin (stored-XSS vector; review 2026-08-b, S-3). Embedded uses (<img>, <video>) are unaffected by disposition.

Properties ​

disposition? ​

> optional disposition?: "inline" | "attachment"

Defined in: storage/src/driver.ts:125


endpoint? ​

> optional endpoint?: string

Defined in: storage/src/driver.ts:135

Sign for this base endpoint instead of the driver's own — the SAME bucket reached under another host (an internal service name, a public CDN alias). Validated by the Disk layer: absolute http:/https: URL, no credentials.

A driver that cannot sign for another endpoint MUST refuse it with STORAGE_TEMPORARY_URL_UNSUPPORTED rather than ignore it — a URL signed for the wrong host is a silently broken one.

Released under the MIT License.