AddThisFeature

Secure File Downloads

Serve private files without turning storage URLs into permanent public links.

involved Security & Reliability

What it adds

Authorization checked at download time, followed by a short-lived signed URL that the storage layer serves directly.

What your agent is told to do

5
  1. 1

    Route every download through an app endpoint that checks the current user's authorization for that specific file, then redirects to a signed URL with a short expiry.

  2. 2

    Keep the expiry measured in minutes. A signed link is a bearer credential and will end up in browser history, chat messages, and referrer headers.

  3. 3

    Set Content-Disposition to attachment and a conservative Content-Type for user-uploaded files so the browser downloads rather than renders them.

  4. 4

    Let the storage layer handle range requests and large transfers; the app issues the URL and gets out of the way.

  5. 5

    Do NOT rely on an unguessable storage path as the access control. Unguessable is not private — it is a permanent public link nobody has found yet.

Edge cases it handles

6
  • Authorization must be re-checked at every download, not cached from when the page listing the file was rendered.
  • Removing a user from a workspace must break their outstanding signed URLs faster than those URLs expire, or the expiry is too long.
  • Filenames from users can contain newlines, quotes, and non-ASCII characters — sanitise and encode them or the header is an injection point.
  • SVG and HTML uploads execute script when served inline. Force attachment disposition, or serve user content from a separate origin.
  • A resumed or partially failed download must not require a fresh authorization round-trip mid-transfer.
  • Log who downloaded what and when; for private files that record is often the point.

Definition of done

8
  • Every download re-checks authorization for the specific file at request time.
  • Signed URLs are short-lived and never stored or shared as permanent links.
  • User-uploaded files are served with attachment disposition and a safe content type.
  • Filenames are sanitised and encoded in headers.
  • Large files and range requests are served by storage, not proxied through the app.
  • Access changes invalidate outstanding links promptly.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.