KamoCRM

Short-lived signed public URLs for marketing assets

FeatureMediaService
Shipped
8 ஜூலை, 2026 அன்று 1:09 AM UTC
Author
Kamo
Commit
34f2809

Lets social providers (Meta) and email fetch a specific material for a bounded window without exposing the private imaging-materials bucket. - MaterialUrlSigner: HMAC-SHA256 (platform.enc-key) token = imgId:orgId:exp, 1h TTL - MaterialsController: POST /api/media/materials/link (auth → mint URL for an org-owned MATERIALS image) + GET **************** (unauth → serve bytes for a valid token; org + assoc checked). Rides the existing sessionless /api/media/** forward — no APIService change needed.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing