The case of users without an account
A transfer is designed to cross the border of the Secrecy user base. Both of its ends — creating a link and reading one — are available as standalone functions exported by @secrecy/lib, so they work without a secrecyClient and therefore without a Secrecy account.
Create a link without an account
The standalone createPublicDataLink function takes the same input as its client counterpart — dataId, name, expireAt and an optional slug — and falls back to a guest api client when none is given. Its apiClient property lets you pass your own client when you already have one.
import { createPublicDataLink } from '@secrecy/lib';
const createLinkAsGuest = async ({
dataId,
name,
}: {
dataId: string;
name: string;
}) => {
try {
// No secrecyClient here, a guest api client is used under the hood
const link = await createPublicDataLink({
dataId,
name,
expireAt: null,
});
return link;
} catch (error) {
console.error(error);
return null;
}
};Read a link without an account
The standalone downloadDataFromLink function is what the recipient of a link calls. It needs the dataLinkSlug and the crypto credentials you delivered out of band, and returns the decrypted bytes. The optional dataUrl property targets another data host than the default one.
import { downloadDataFromLink, fetchDataLinkMetadata } from '@secrecy/lib';
const readLinkAsGuest = async ({
dataLinkSlug,
key,
password,
}: {
dataLinkSlug: string;
key: string;
password: string;
}) => {
try {
// The public metadata tells the name and the size before downloading
const metadata = await fetchDataLinkMetadata(dataLinkSlug);
const bytes = await downloadDataFromLink({
dataLinkSlug,
crypto: { key, password },
});
return { metadata, bytes };
} catch (error) {
console.error(error);
return null;
}
};Delivering the secret
The slug travels in the URL, but the key and the password must never travel with it: anyone intercepting both would read the data. Send them through a separate channel. The generatePassword helper exported by @secrecy/lib produces a strong password when you mint one yourself rather than using the one returned by uploadData.