Also, files being publicly available and only prot...
# prisma-whats-new
a
Also, files being publicly available and only protected by authentication on obtaining its secret is going to be a very big showstopper for using graphcool. Any news on that?
n
@agartha a good approach here is to use an external service that offers signing URLs like Imgix. Then you will never expose the secret file URLs to your client apps. Using the permission system you can prevent anyone from querying the file secret. Would that be a possibility for you?
a
Imgix seems to be focused on images. Do you know of any alternatives for other files?
So, let's try to get that workflow straight. Whenever a user uploads a file, the response contains the 'secret URL' already... Or is it possible to hook into the transform_payload event of the File schema? I'm also still a bit puzzled with the relation between using the File endpoint, and how a record ends up in the File schema? Anyway, after we get that part sorted out, how do I get a one-time download link for that file?
Okay @nilan , I think I get it now. 1. Reduce the permissions on the secret column of the file, so it's not returned in the response when a user uploads a file. 2. Create a webtask that will take the id of the file, check permissions, and acts as a proxy for the file endpoint. Just have to figure out now how to build a proxy for the download stream in webtask.io... Or use a external service, but I haven't found any... Does that sound about right, and thanks for your help.
n
A file upload will always contain the secret of the new file in its response. Why are you concerned about that? There should be no harm when a user uploading a file can download it later 🙂
When a file is uploaded, a new node automatically appears as part of the
File
type
a
For example, a user is part of a team, uploads a file, gets the secret back. Is subsequently removed from the team, but can still access all files directly because downloading a file using the secret bypasses all authentication and authorization...
n
well that person can't suddenly download all files, only the one he uploaded
if you never expose the file secrets to your client app
a
Thinking about it, to prevent that, I'll have to proxy both uploading and downloading using a webtask. I was probably going to do that anyway, to be able to upload a file and associated metadata in one call.
n
yea that's a great approach
how do you want to proxy the download?
a
Something along the lines of https://www.npmjs.com/package/express-http-proxy. I just perform my authentication, lookup the secret based on the id, and proxy the file API request that you wouldn't normally use directly