Skip to content

Flowvault v1.5 — Encrypted File Send

Latest

Choose a tag to compare

@flowdeskadmin flowdeskadmin released this 08 May 04:11
· 5 commits to master since this release

Same shape as Encrypted Send, but for files. Drop a file (up to 10 MiB),
pick how long it lives (max 7 days) and how many times it can be
downloaded, share the link.

What's new

  • Encrypted File Send at /file/new. AES-256-GCM in your browser,
    ciphertext only on our storage, key in the URL fragment.
  • Two links per upload. A download link to share, and a separate
    secure delete link you keep for yourself — destroy the upload
    any time before its expiry or download cap is consumed.
  • Optional password gate (Argon2id, 64 MiB / 3 iter), same as
    Encrypted Send.
  • Sender-controlled expiry: 1 hour / 1 day / 3 days / 7 days.
  • Sender-controlled download cap: 1 / 2 / 5 / 10. Default 1.
  • Server-enforced: a Cloud Function atomically consumes a download
    and hard-deletes the upload on the final view. An hourly sweep
    purges expired and orphan objects.
  • New blog post: Encrypted File Send: 10 MiB self-destructing
    file uploads with a secure delete link
    .

What it doesn't do

  • Files larger than 10 MiB. Use Bitwarden Send / OnionShare / Magic
    Wormhole for those — Flowvault stays scoped to documents and
    screenshots.
  • Padding for size privacy. Encrypted ciphertext is the same length
    as your file plus 28 bytes of AEAD overhead.

Self-host upgrade notes

The feature uses Firebase Cloud Storage in addition to Firestore.
Three one-time setup steps — provision the default Storage bucket,
grant the deploy SA roles/firebasestorage.admin, grant the runtime
SA roles/iam.serviceAccountTokenCreator on itself, and apply the
bucket CORS config from storage.cors.json. Full instructions in
the README.

Open source as always — frontend, Cloud Functions, Firestore rules,
and Storage rules all in this repo.