tekir
All Packages
Storage & Parsingv0.1.5

@tekir/drive

Unified file storage with local, S3, R2, and GCS drivers.

Installation

$bun add @tekir/drive

Features

  • Local, S3, R2, and memory drivers
  • put(), get(), delete(), exists(), getUrl()
  • Signed URLs for private files
  • Drive manager with use() for disk switching
  • Lazy-initialized disk instances
  • DriveProvider for DI registration

Quick Example

TypeScript
import { Drive } from '@tekir/drive'

const drive = new Drive({ default: 'local', disks: {
  local: { driver: 'local', root: './storage' },
} })

await drive.use('local').put('avatar.jpg', fileBuffer)
const url = drive.use('local').getUrl('avatar.jpg')

Changelog

v0.1.5LatestSeptember 16, 2026
  • Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.4July 23, 2026
  • Package metadata now follows the shared compatible 0.1.x dependency range used by this coordinated Tekir release.
v0.1.3July 16, 2026
  • S3 SigV4 now signs query parameters and encoded object keys correctly, remote LIST/DELETE failures are surfaced, same-key moves are safe, and local/memory drivers close symlink and mutable-buffer escapes.
v0.1.2June 13, 2026
  • New serveDrive() fallback handler that, by default (requireSignature: true), requires a valid token+expires signature on every request under its URL prefix and returns 403 for a missing, wrong, or expired signature.
  • LocalDriver now enforces upload validation. A new upload option (allowed extensions plus max size, settable per disk in config/drive.ts) is applied in put(), including the streaming path, and helpers like sanitizeFilename/validateUpload are exported.
  • Local path handling is hardened: a key containing a null byte throws Path traversal detected, and getUrl/getSignedUrl resolve and per-segment URL-encode the key while keeping the signature round-trip intact.
  • The S3 list() now follows pagination to return every key and decodes XML entities in key names.
  • Found and fixed with Fable.
v0.1.1May 17, 2026
  • LocalDriver.getSignedUrl(...) now produces a real HMAC-SHA256 signature keyed by APP_KEY (or a constructor-passed secret) instead of returning the storage key and expiry as a base64 payload. The previous token could be decoded, edited, and re-encoded to forge access to any local file. The new LocalDriver.verifySignedUrl(key, token, expires) checks the signature in constant time and rejects expired URLs; call it from any custom handler that serves files behind signed URLs.
  • LocalDriver constructors that do not configure a signing secret now throw on the first getSignedUrl() call instead of returning a forgeable token silently. Set APP_KEY in the environment or pass secret per disk in config/drive.ts.
  • Windows cross-drive traversal is now blocked. A key resolving to a different drive letter than the disk's root (for example D:\\secret.txt against a C:\\app\\storage root) is rejected before any filesystem access. POSIX behaviour is unchanged.
v0.1.0April 1, 2026
  • Initial release

Other Storage & Parsing packages