Reuse private CDN signing windows for 150 s in the wedding demo - #38
Conversation
Red-first regression for the demo's private media route: requests within one 150 s window receive the same signed URL, a new URL never gets more than the five-minute grant, and every request still reauthorizes, so a revocation in the middle of a window returns 404 at once. It fails on Viewer 0.0.3, whose route rotates every 60 s. The published Viewer with rotationIntervalMs follows in this PR. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Pin @transloadit/viewer 0.0.5, which adds rotationIntervalMs, and sign private media per 150 s window with the five-minute lifetime unchanged. Repeat views within a window get the same URL and can hit the CDN cache; every request still reauthorizes and a new URL keeps 150-300 s of validity. The wedding-gallery docs no longer claim a once-a-minute rotation. Demo-only: Viewer is a dev dependency, so @transloadit/convex is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The wedding-gallery docs still named Viewer 0.0.3, and the route comment described the 150-300 s validity as "half its lifetime", which only holds while the interval stays half the lifetime. Both now state the actual values. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Independent production acceptance passed on September 29, 2026, after the merge and automatic deploy.
Nine visible private images decoded in the browser. Exact-URL network repeats in the initial sample were CDN HITs at 25–109 ms; cold image TTFBs were about 1.9–2.1 seconds. These are local samples, not a latency SLA or a controlled before/after benchmark. The wider signing window reduces cache-key churn; it does not remove cold transforms or per-request authorization. The first temporary probe stopped on an insufficiently instrumented assertion in its logout block. The UI shows the disabled login form while sign-out is still pending; the probe now waits for completion rather than visibility. The entire production sequence above was rerun successfully without a product change. The precise original failed predicate was not recovered. Existing synthetic media only; no asset uploads or deletions. Test guests were logged out. No bearer URLs, cookies, credentials, or response bodies retained in the evidence. |
Why
Private wedding photos redirect through
/api/transloadit/mediato signed Smart CDN URLs. Theroute re-signs every 60 s, and the CDN caches on the full signed query,
expincluded. So areload two minutes later gets new URLs, which are new cache keys and may need another cold
transform. The lead's production
sample showed six of six MISSes at about 2 s, while the same exact URLs returned HITs in
25–135 ms. transloadit/node-sdk#527 adds an optional
rotationIntervalMsto Viewer'screateStorageRoute, bounded by half the lifetime, with the default, maximum grant andper-request authorization unchanged.
What changes
A red-first route test (01b3344):
expexactly 300 s after its window start.media:forDelivery, and a revocation in the middle of a windowreturns 404 on the next request.
private, no-store.It failed on Viewer 0.0.3, which rotates every 60 s: expected
exp1790705100000, received1790705220000.
The fix (1eebcfc):
@transloadit/viewerto exactly0.0.5, with its exact age-gate preapproval. It waspublished by Version Packages node-sdk#528 (gitHead
db3b77f, SLSA provenance). Its integritymatches the publication handoff.
lifetimeMs: 300_000(unchanged) androtationIntervalMs: 150_000in the route.docs/wedding-gallery.md, which said signing "rotates at most once a minute".Council follow-up (dbea6d4): the docs now name Viewer 0.0.5, and the route comment states the
150-300 s validity instead of "half its lifetime".
The published tarball differs from 0.0.3 only in the
createStorageRouteoption, its types anddocs; 0.0.3 to 0.0.4 was docs only. The installed package is byte-identical to the verified
tarball, and its dependencies are unchanged.
This PR is demo-only. Viewer is a root dev dependency, and the PR adds no changeset, so
@transloadit/convexdoes not change. It includes no auth relaxation, no longer grant, no uploadsand no API2 or production config changes. The only configuration added is Root's branch-only
Vercel preview mapping for
NEXT_PUBLIC_CONVEX_URL.Checks
yarn check: format, lint and typecheck pass (only pre-existing infos in untouchedscripts/).Tests: 200/200, on 1eebcfc and again on dbea6d4.
council.ts review, no--post): Model B found no issues. The arbiter hit a providerusage limit, so these are raw reviews. Model A's findings:
next/server'srotationIntervalis unchanged since 0.0.3.
NEXT_PUBLIC_CONVEX_URLmaps to this branch's Convex preview.🤖 Generated with Claude Code