Skip to content
Code Recycle

Component · for humans & their agents

Blob Write Mode

verified · first-partyactively maintained$0 during beta (was $9)

A missing storage token once turned private document writes into publicly-fetchable URLs. This is the decision that refuses instead — four tests and forty lines, guarding the branch where "degrade gracefully" means "publish the customer's financials."

by saltyhash · Code Recycle admin

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Building it yourself: Generate this one yourself — it is about one pass of agent time and you would spot any mistake.

4 tests. One pure function, zero runtime dependencies, ESM.

The bug this exists to prevent

The original code was reasonable-looking:

  if (blobEnabled) {
    if (privateToken) return writePrivate();
    return writePublic();      // fall back so the write still succeeds
  }
  return writeLocal();

A fallback that keeps working when configuration is incomplete is normally good practice. Here it is the whole defect. When the private store's token was absent — a rotated credential, a new environment, an env pull that returned an empty string — the write succeeded, the document was stored, the app showed no error, and the bytes were at a public URL.

Every observable signal said it worked. The upload returned 200. The document appeared in the list. It opened correctly when clicked. The only difference was that anyone holding the URL could fetch it too, and nothing anywhere said so.

The rule: blob-enabled with no private token is a HARD ERROR

resolveBlobWriteMode() returns 'private' or 'local', and throws for the third case. There is no public mode in the return type — the type itself makes the old fallback unrepresentable.

  • blob enabled + private token present → 'private'
  • blob enabled + private token absent → throws
  • blob not enabled → 'local' (the ordinary development path)

Refusing is correct even though it takes the feature down. A failed upload is a support ticket; a public one is a disclosure you find out about later, from someone else.

Why this is a package and not four lines you write yourself

It is four lines. The value is knowing which four, and the ordering — that "is a blob store configured" and "can I write privately" are two separate questions, and that answering the second with a fallback is what published the documents.

Anyone can write this correctly once they have seen it go wrong. This is the cheapest available way to see it go wrong.

What this does NOT do

No I/O. It does not write, upload, or talk to any storage provider. It resolves two env-derived booleans into a decision, so the security-relevant branch is unit-testable without a blob store, a network, or a credential.

Verified

4 tests: the production path, the development path, and — the one that matters — that the blob-enabled-without-private-token case throws rather than returning anything at all.

01Capabilities

Does

  • + Secret management
  • + Data exposure boundary
  • + Configuration precedence

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 7 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
0.1.0stableAug 11, 2026Initial extraction.