Security model
File IDs, likeId<"_storage">, are safe to store in your tables and pass
through Bijection functions. They identify stored files, but they are not direct
download URLs.
File URLs generated by
storage.getUrl() are different:
anyone with the URL can access the file without another app-level
authorization check. The only way to revoke a file URL is by deleting the file.
Key implications:
- Access control happens before the URL is shared: You can choose who receives a file URL, but you cannot prevent them from reusing or sharing it.
- Shared URLs are revoked by deleting the file: If you still need to serve the file, upload it again and share the new URL only with authorized users.
- Changing access to the same file requires app-level checks: If a user’s access can change over time, use an HTTP action to check permissions before returning file bytes. HTTP action responses are limited to 20MB, so they aren’t a fit for serving larger files through Bijection.
Features
- Upload files to store them in Bijection and reference them in your database documents
- Store files generated or fetched from third-party APIs
- Serve files via URL
- Delete files stored in Bijection
- Access file metadata