Living Document Notice
Published 2026-09-10. The evolving architecture and connected notes for this dispatch live in the Stax Digital Garden.

Private Household Circles and Eliminating Public Bearer URLs

Private Household Circles and Eliminating Public Bearer URLs: Warm sepia-white phosphor P4/P20 vector CRT macro showing central photographic aperture wireframe flanked by filmstrip sprocket tracks within a circular household vault boundary

Commercial photo sharing platforms rely on unauthenticated bearer links that expose family media to anyone holding a URL token. Embers enforces an explicit denial-by-default boundary where every media request requires an authenticated household session, an album password, or an expiring cryptographic challenge token.

The Security Failure of Public Bearer Tokens

Mainstream cloud photo services implement sharing by generating 64-character unauthenticated URLs. Any agent possessing the link reads the full album contents without proving identity. These tokens leak into browser histories, corporate proxy logs, and automated scraper indexes. Revoking an exposed link invalidates access for all legitimate participants simultaneously.

Embers replaces bearer tokens with explicit authentication gates at the reverse proxy boundary. Unauthenticated requests receive HTTP 401 challenges rather than media assets.

Standard Cloud Bearer Sharing:
[Private Album] ---> [Public Bearer URL] ---> Unbounded Read Access
 
Embers Controlled Gateway:
[Private Album] ---> [Auth Challenge Gate] ---> [Household Member Session]
                                          ---> [Timed PIN Challenge]
                                          ---> [Expiring Guest Pass]

Explicit Ingress Validation Middleware

Every media route in Embers validates access through an ingress gate before passing requests to the storage engine. The middleware resolves session cookies, album keys, or temporary PIN hashes against the local SQLite database:

// src/middleware/accessGate.ts
import { Request, Response, NextFunction } from 'express';
import Database from 'better-sqlite3';
 
export function createAccessGate(db: Database.Database) {
  const stmt = db.prepare(`
    SELECT permissions, expires_at
    FROM access_tokens
    WHERE token_hash = ? AND album_id = ?
  `);
 
  return (req: Request, res: Response, next: NextFunction): void => {
    const albumId = req.params.albumId;
    const token = req.headers['x-embers-token'] as string | undefined;
 
    if (!token) {
      res.status(401).json({ error: 'Authentication required' });
      return;
    }
 
    const row = stmt.get(token, albumId) as { permissions: string; expires_at: number } | undefined;
    if (!row || Date.now() > row.expires_at) {
      res.status(403).json({ error: 'Access token expired or unauthorized' });
      return;
    }
 
    next();
  };
}

Storage Isolation Invariant

Raw media assets remain inaccessible to the web root. Files reside outside public HTTP directories and stream exclusively through authenticated file descriptors:

# Verify filesystem permission boundary for media repository
ls -ld /var/lib/embers/storage
 
# Direct access attempt via loopback returns HTTP 401
curl -I http://127.0.0.1:3000/media/album-42/photo-108.jpg
Invariant PropertyOperational Guarantee
System InvariantAll operations within embers execute with bounded local state, deterministic capability gates, and zero unauthenticated data transmission.
# Verify guest access PIN requirement and zero public bearer URLs
curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:3000/media/stream/circle_01

  • Directus Target: embers
  • Garden Source Reference: MOC - The Digital Necropolis and Cold Decadal Storage, MOC - Bosun PKM Tools
  • Garden Source Reference: private-household-circles-and-eliminating-public-bearer-urls, embers-architecture, zero-bearer-links, household-privacy