Allow bounded private CDN signing-window reuse - #527
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
In the Convex production dogfood, cold private renditions took 1.91–2.60 seconds to the first
byte; fetching the exact same signed URL hit the CDN in 25–135 ms. A new signing window changes
the full-query cache key. Let an application reuse that URL for longer without extending its
maximum grant lifetime or caching authorization.
Change
rotationIntervalMsto the runtime-neutralcreateStorageRoute.min(60000, floor(lifetimeMs / 2)). Require an explicit interval tobe a positive safe integer no greater than half the lifetime.
private, no-store, and the maximumlifetime. No dependency, Next adapter, Node SDK signing default, or CDN configuration change.
At a five-minute maximum, an explicit 150-second window gives 150–300 seconds of remaining
validity instead of the default 240–300 seconds. It creates 24 signing windows/hour instead of
60. That may improve repeat-view reuse; it does not accelerate the first cold transform or
guarantee a particular production hit rate. Previously issued grants remain usable until expiry,
as before.
Verification
yarn verify:fulland post-reviewyarn check.remaining lifetime and same-window revocation. Existing cross-workspace, malformed-request,
sanitized-error and header regressions remain covered.
no claim that this local review tests the production CDN. All 468 Viewer tests reran successfully
on
3d3192e, with SHA and source/build checksums retained alongside the JSON report.6206ca851835a926d868dcdb4c76694af6d045d8: build, release dry run, Verify fast/full, Node 20/22/24,real E2E, Supabase Edge, and the packed Next.js browser fixture. No test gate was disabled.
first hit stale npm metadata (the pinned versions exist); an isolated fresh npm cache passed
installation and seed/consumer type checks. Firefox extraction then stalled for ten minutes.
Stopped only the owned installer processes; this is not a local browser PASS.
Follow-up
Publish through the normal Changesets flow, then explicitly opt the Convex demo into 150 seconds
with an unchanged 300-second maximum and repeat the live delivery check. Cross-window rendition
reuse in API2 is a separate design; this PR does not strip auth/expiry from Bunny's cache key.