server_storage 0.1.3
server_storage: ^0.1.3 copied to clipboard
Framework-agnostic storage runtime (portable, from server_data/storage).
Changelog #
0.1.3 - 2026-08-29 #
- Added a first-class
S3StorageDiskfor AWS S3 and compatible services, including endpoint, region, temporary-credential, key-prefix, path-style, public-URL, and optional bucket-bootstrap configuration. - Added application-scoped Laravel-style filesystem access through
StorageManager.storage()/drive()for both built-in local and S3 disks. - Added
StorageManager.temporaryUrl()andtemporaryUploadUrl()so applications can issue provider-signed URLs without accessingfile_cloudor an underlying cloud adapter. - Added
StorageManager.registerFilesystem()for host-native object stores that exposestorage_fsoperations without apackage:filefilesystem. - Added
StorageFileHandlerand explicit path-resolution capability checks so host-native filesystems can back framework static endpoints without importingdart:ioin the portable handler. - Added
SftpStorageDisk, backed byfile_sftp, with password/private-key authentication, rooted remote paths, read-only mode, lazy connections, and explicit connection cleanup. - Widened the
storage_fs,file_cloud, andfile_sftpdependency ranges to<1.0.0so applications can select compatible 0.x adapter versions. - Hardened cloud object-key resolution against absolute paths and parent-path escapes.
- Fixed local visibility changes so
chmodtargets the configured storage root and reports command failures. - Fixed prefixed S3 public URLs so they point at the stored object key.
- Fixed storage-backed static directory detection for index and listing requests on hierarchical filesystems.
- Added
StorageSignedUrlSignerandSignedStorageFileHandlerfor HMAC-SHA256, time-limited private downloads with timing-safe verification. - Made ordinary storage-backed static serving require truthful public visibility and filter private entries from directory listings.
- Made S3 storage private by default: public visibility requests are rejected and failed presigning no longer falls back to an unsigned public URL.
- Made HTTPS the S3 default and require an explicit development-only opt-in for cleartext HTTP endpoints.
- Ensured both SFTP connections are offered cleanup and removed secrets and capability URLs from signed-URL validation errors.
0.1.2 - 2026-08-25 #
- Migrated package analysis to
very_good_analysisand completed public API Dartdoc coverage. - Expanded storage-manager, local-disk, cloud-disk, and static-file lifecycle guidance, including path-boundary behavior.
0.1.1 #
- Hardened local-disk path resolution against directory escapes and invalid disk names.
- Added file handling needed by storage-backed static mounts.
0.1.0 #
- Initial extraction from server_data/src/storage (PR H)