Skip to content

Allow bounded private CDN signing-window reuse - #527

Merged
kvz merged 2 commits into
mainfrom
cdn-rotation
Sep 29, 2026
Merged

kvz merged 2 commits into
mainfrom
cdn-rotation

Conversation

@kvz

@kvz kvz commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Why

In the Convex production dogfood, cold private renditions took 1.91–2.60 seconds to the first
byte; fetching the exact same signed URL hit the CDN in 25–135 ms. A new signing window changes
the full-query cache key. Let an application reuse that URL for longer without extending its
maximum grant lifetime or caching authorization
.

Change

  • Add optional rotationIntervalMs to the runtime-neutral createStorageRoute.
  • Keep the current default: min(60000, floor(lifetimeMs / 2)). Require an explicit interval to
    be a positive safe integer no greater than half the lifetime.
  • Preserve per-request authorization, GET/HEAD behavior, private, no-store, and the maximum
    lifetime. No dependency, Next adapter, Node SDK signing default, or CDN configuration change.
  • Document the tradeoff and add a Viewer-only patch changeset; the package remains alpha.

At a five-minute maximum, an explicit 150-second window gives 150–300 seconds of remaining
validity instead of the default 240–300 seconds. It creates 24 signing windows/hour instead of
60. That may improve repeat-view reuse; it does not accelerate the first cold transform or
guarantee a particular production hit rate. Previously issued grants remain usable until expiry,
as before.

Verification

  • Red first: four action/window tests and seven invalid configurations fail against main.
  • Green: 101 route tests, 468 Viewer tests, root yarn verify:full and post-review yarn check.
  • Preview, crop, original and download: GET/HEAD reuse, exact clock boundaries, maximum/minimum
    remaining lifetime and same-window revocation. Existing cross-workspace, malformed-request,
    sanitized-error and header regressions remain covered.
  • Council review: no remaining findings.
  • Local Opus defensive security review: PASS, no supported P0–P3 findings. In-memory API tests only;
    no claim that this local review tests the production CDN. All 468 Viewer tests reran successfully
    on 3d3192e, with SHA and source/build checksums retained alongside the JSON report.
  • Exact-head CI is green on
    6206ca851835a926d868dcdb4c76694af6d045d8: build, release dry run, Verify fast/full, Node 20/22/24,
    real E2E, Supabase Edge, and the packed Next.js browser fixture. No test gate was disabled.
  • The local fixture
    first hit stale npm metadata (the pinned versions exist); an isolated fresh npm cache passed
    installation and seed/consumer type checks. Firefox extraction then stalled for ten minutes.
    Stopped only the owned installer processes; this is not a local browser PASS.

Follow-up

Publish through the normal Changesets flow, then explicitly opt the Convex demo into 150 seconds
with an unchanged 300-second maximum and repeat the live delivery check. Cross-window rendition
reuse in API2 is a separate design; this PR does not strip auth/expiry from Bunny's cache key.

@kvz kvz self-assigned this Sep 29, 2026
@kvz
kvz merged commit 716a2fe into main Sep 29, 2026
14 checks passed
@kvz
kvz deleted the cdn-rotation branch September 29, 2026 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant