System Index
Menu

SecureShare

Temporary private sharing through secret links with expiration, access limits and revocation.

SecureShare system cover

Overview

SecureShare is a temporary sharing service for private text and files. Creators authenticate with GitHub, while recipients only need the generated capability link. Shares can expire, enforce access limits and be revoked without requiring recipient accounts. The public Next.js application acts as a BFF for a private Go API. PostgreSQL, Redis, Cloudflare R2 and a cleanup worker handle persistence, rate limiting, file storage and lifecycle recovery behind the public web layer.

Architecture

Engineering

Capability tokens are stored only as hashes, and one-time redemption is enforced atomically in PostgreSQL. Private file storage uses short-lived signed downloads and a recoverable lifecycle between upload, publication and cleanup. Authentication uses GitHub OAuth with PKCE and server-side revocable sessions. Additional controls include distributed rate limiting, creator quotas, audit events and browser-level privacy protections.