Storage & Parsingv0.1.5
@tekir/drive
Unified file storage with local, S3, R2, and GCS drivers.
Installation
$
bun add @tekir/driveFeatures
- Local, S3, R2, and memory drivers
- put(), get(), delete(), exists(), getUrl()
- Signed URLs for private files
- Drive manager with use() for disk switching
- Lazy-initialized disk instances
- DriveProvider for DI registration
Quick Example
TypeScript
import { Drive } from '@tekir/drive'
const drive = new Drive({ default: 'local', disks: {
local: { driver: 'local', root: './storage' },
} })
await drive.use('local').put('avatar.jpg', fileBuffer)
const url = drive.use('local').getUrl('avatar.jpg')Changelog
v0.1.5LatestSeptember 16, 2026
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.4July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.3July 16, 2026
- S3 SigV4 now signs query parameters and encoded object keys correctly, remote LIST/DELETE failures are surfaced, same-key moves are safe, and local/memory drivers close symlink and mutable-buffer escapes.
v0.1.2June 13, 2026
- New
serveDrive()fallback handler that, by default (requireSignature: true), requires a validtoken+expiressignature on every request under its URL prefix and returns403for a missing, wrong, or expired signature. LocalDrivernow enforces upload validation. A newuploadoption (allowed extensions plus max size, settable per disk inconfig/drive.ts) is applied input(), including the streaming path, and helpers likesanitizeFilename/validateUploadare exported.- Local path handling is hardened: a key containing a null byte throws
Path traversal detected, andgetUrl/getSignedUrlresolve and per-segment URL-encode the key while keeping the signature round-trip intact. - The S3
list()now follows pagination to return every key and decodes XML entities in key names. - Found and fixed with Fable.
v0.1.1May 17, 2026
LocalDriver.getSignedUrl(...)now produces a real HMAC-SHA256 signature keyed byAPP_KEY(or a constructor-passedsecret) instead of returning the storage key and expiry as a base64 payload. The previous token could be decoded, edited, and re-encoded to forge access to any local file. The newLocalDriver.verifySignedUrl(key, token, expires)checks the signature in constant time and rejects expired URLs; call it from any custom handler that serves files behind signed URLs.LocalDriverconstructors that do not configure a signing secret now throw on the firstgetSignedUrl()call instead of returning a forgeable token silently. SetAPP_KEYin the environment or passsecretper disk inconfig/drive.ts.- Windows cross-drive traversal is now blocked. A
keyresolving to a different drive letter than the disk'sroot(for exampleD:\\secret.txtagainst aC:\\app\\storageroot) is rejected before any filesystem access. POSIX behaviour is unchanged.
v0.1.0April 1, 2026
- Initial release