Living Document Notice
Published 2026-09-10. The evolving architecture and connected notes for this dispatch live in the Stax Digital Garden.
Private Household Circles and Eliminating Public Bearer URLs
Commercial photo sharing platforms rely on unauthenticated bearer links that expose family media to anyone holding a URL token. Embers enforces an explicit denial-by-default boundary where every media request requires an authenticated household session, an album password, or an expiring cryptographic challenge token.
The Security Failure of Public Bearer Tokens
Mainstream cloud photo services implement sharing by generating 64-character unauthenticated URLs. Any agent possessing the link reads the full album contents without proving identity. These tokens leak into browser histories, corporate proxy logs, and automated scraper indexes. Revoking an exposed link invalidates access for all legitimate participants simultaneously.
Embers replaces bearer tokens with explicit authentication gates at the reverse proxy boundary. Unauthenticated requests receive HTTP 401 challenges rather than media assets.
Standard Cloud Bearer Sharing:
[Private Album] ---> [Public Bearer URL] ---> Unbounded Read Access
Embers Controlled Gateway:
[Private Album] ---> [Auth Challenge Gate] ---> [Household Member Session]
---> [Timed PIN Challenge]
---> [Expiring Guest Pass]Explicit Ingress Validation Middleware
Every media route in Embers validates access through an ingress gate before passing requests to the storage engine. The middleware resolves session cookies, album keys, or temporary PIN hashes against the local SQLite database:
// src/middleware/accessGate.ts
import { Request, Response, NextFunction } from 'express';
import Database from 'better-sqlite3';
export function createAccessGate(db: Database.Database) {
const stmt = db.prepare(`
SELECT permissions, expires_at
FROM access_tokens
WHERE token_hash = ? AND album_id = ?
`);
return (req: Request, res: Response, next: NextFunction): void => {
const albumId = req.params.albumId;
const token = req.headers['x-embers-token'] as string | undefined;
if (!token) {
res.status(401).json({ error: 'Authentication required' });
return;
}
const row = stmt.get(token, albumId) as { permissions: string; expires_at: number } | undefined;
if (!row || Date.now() > row.expires_at) {
res.status(403).json({ error: 'Access token expired or unauthorized' });
return;
}
next();
};
}Storage Isolation Invariant
Raw media assets remain inaccessible to the web root. Files reside outside public HTTP directories and stream exclusively through authenticated file descriptors:
# Verify filesystem permission boundary for media repository
ls -ld /var/lib/embers/storage
# Direct access attempt via loopback returns HTTP 401
curl -I http://127.0.0.1:3000/media/album-42/photo-108.jpg| Invariant Property | Operational Guarantee |
|---|---|
| System Invariant | All operations within embers execute with bounded local state, deterministic capability gates, and zero unauthenticated data transmission. |
# Verify guest access PIN requirement and zero public bearer URLs
curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:3000/media/stream/circle_01- Directus Target: embers
- Garden Source Reference: MOC - The Digital Necropolis and Cold Decadal Storage, MOC - Bosun PKM Tools
- Garden Source Reference: private-household-circles-and-eliminating-public-bearer-urls, embers-architecture, zero-bearer-links, household-privacy