DEV Community

Seif Ahmed
Seif Ahmed

Posted on Edited on AI-assisted

Building a password-protected link sharing workflow

Ever wondered how to build a clean, secure system for sharing user content via unique links? It gets interesting when you have to separate public access from password-protected private shares.

Here is a breakdown of how my markdown previewer handles this:

  • URL Activation: A user opens the link http://localhost:3000/?id=POST_ID.
  • ID Extraction: The frontend parses the URL and extracts the ID using URLSearchParams.
  • Request Initiation: If an ID is present, the frontend requests data from /api/v1/get/save-from-link/:id.
  • Backend Verification: The backend checks if the ID exists in the database.
  • Public Access: If the link is public, the backend returns the content (link.for.content).
  • Private Access: If the link is private, the backend responds with a success signal and need_password: true without sending any content.
  • Frontend Evaluation: The frontend checks the need_password flag.
  • Content Display: If false, it renders the public content.
  • Password Prompt: If true, a popup prompts the user to enter a password.
  • Rate Limiting: Users get 10 password attempts per 7 minutes across all private saves globally.
  • Password Validation: The frontend sends the ID and password to /api/v1/validate-save-password/:id.
  • Security Match: The backend queries the ID ensuring status: "private", then verifies the password using await bcrypt.compare(password, link.password).

Liked my Markdown Previewer? Please give it a ⭐ on GitHub at https://github.com/Hfs2024/Markdown-Previewer!

Top comments (0)