Skip to content

CLOUD-4793: sign blob presign URLs through Upstash - #25

Open
ytkimirti wants to merge 2 commits into
DX-3059-blob-X-s3from
CLOUD-4793-presign
Open

ytkimirti wants to merge 2 commits into
DX-3059-blob-X-s3from
CLOUD-4793-presign

Conversation

@ytkimirti

Copy link
Copy Markdown
Contributor

Upgrades @upstash/blob to 0.0.7, which signs URLs through Upstash's /v1/presign instead of locally with the bucket's temporary credential, so URLs no longer leak a whole-bucket credential.
blob presign now defaults to and allows at most 600 seconds (the new cap), and its help and README no longer say links are bounded by the credential.

@linear-code

linear-code Bot commented Sep 28, 2026

Copy link
Copy Markdown

CLOUD-4793

@ytkimirti
ytkimirti added this pull request to stack #26 September 28, 2026 05:51
@ytkimirti
ytkimirti marked this pull request as ready for review September 28, 2026 05:51

@CahidArda CahidArda left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

realized this is the last PR in a stack, I haven't checked the other prs yet

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The SDK behavior, CLI validation, documentation, and dependency lockfile are consistent with the secure presigning change.

Review effort: Balanced
Findings: None

What changed in this PR

Updates Blob presigning to use Upstash’s secure signing service with a 10-minute limit.

Changes:

  • Upgrades @upstash/blob to 0.0.7.
  • Caps and defaults presigned URLs to 600 seconds.
  • Updates validation, help text, tests, and README examples.
File Description
src/​commands/​blob/​presign.ts Applies the new expiration limit and messaging.
tests/​unit/​blob-s3.test.ts Tests rejection above 600 seconds.
README.md Updates the presign example.
package.json Upgrades the Blob SDK.
package-lock.json Locks the upgraded dependency.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@CahidArda CahidArda left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, let's merge other prs first

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants