Ever wondered how to build a clean, secure system for sharing user content via unique links? It gets interesting when you have to separate public access from password-protected private shares.
Here is a breakdown of how my markdown previewer handles this:
- URL Activation: A user opens the link
http://localhost:3000/?id=POST_ID. - ID Extraction: The frontend parses the URL and extracts the ID using
URLSearchParams. - Request Initiation: If an ID is present, the frontend requests data from
/api/v1/get/save-from-link/:id. - Backend Verification: The backend checks if the ID exists in the database.
- Public Access: If the link is public, the backend returns the content (
link.for.content). - Private Access: If the link is private, the backend responds with a success signal and
need_password: truewithout sending any content. - Frontend Evaluation: The frontend checks the
need_passwordflag. - Content Display: If false, it renders the public content.
- Password Prompt: If true, a popup prompts the user to enter a password.
- Rate Limiting: Users get 10 password attempts per 7 minutes across all private saves globally.
- Password Validation: The frontend sends the ID and password to
/api/v1/validate-save-password/:id. - Security Match: The backend queries the ID ensuring
status: "private", then verifies the password usingawait bcrypt.compare(password, link.password).
Liked my Markdown Previewer? Please give it a ⭐ on GitHub at https://github.com/Hfs2024/Markdown-Previewer!
Top comments (0)