-
Notifications
You must be signed in to change notification settings - Fork 0
Advanced Sharing and Client Portals
Secure File Distribution, Granular Access Controls, Dynamic Watermarking & Public Client Portals
The Brum Sharing Center is a native Core Function enabling users to generate authenticated, expiring, and granularly controlled public links for files and directories. It turns any Brum instance into a professional client portal, 3D design showcase, or secure file distribution hub with zero third-party cloud dependencies.
- Core Architecture & Security Flow
- Dual-Mode Sharing Center Interface
- Creating & Configuring Share Links
- Granular Permissions & Access Controls
- Dynamic Watermarking & View-Only Galleries
- Public Client Portal & Integrated Viewers
- Managing Shares, Revocation & Audit Logs
- REST API Reference
flowchart TD
A["Brum User / Admin"] -->|"Right-Click -> Create Share Link"| B["Sharing Center Engine"]
B -->|"Generate 32-char Random Token"| C["Brum SQLite Database (shares table)"]
D["External Recipient / Client"] -->|"Visits /share/:token"| E["Public Share Gateway"]
E --> F{"Active & Unexpired?"}
F -->|"No / Revoked"| G["404 / 410 Expired Screen"]
F -->|"Yes"| H{"Password Protected?"}
H -->|"Yes"| I["Verify Argon2id / Hash"]
H -->|"No"| J{"Email Whitelist?"}
I --> J
J -->|"Yes"| K["Verify Allowed Email / Domain"]
J -->|"No"| L["Render Responsive Client Portal"]
K --> L
L --> M{"Action"}
M -->|"View File"| N["Internal Viewer (Img/Video/PDF/3D CAD/Doc) + Optional Watermark"]
M -->|"Download"| O{"Downloads Allowed & Within Cap?"}
O -->|"Yes"| P["Stream Binary Payload + Increment Counter"]
O -->|"No"| Q["Download Forbidden (403)"]
M -->|"Upload"| R{"Uploads Allowed?"}
R -->|"Yes"| S["Receive File to Target VFS Directory"]
- Zero-Cloud Footprint: Direct point-to-point delivery served natively by the Rust/Axum HTTP engine.
- Cryptographic Token Entropy: 32-character high-entropy alphanumeric access tokens resistant to URL enumeration.
-
Granular ACL Enforcement: Permission flags (
allow_view,allow_download,allow_upload) strictly verified per HTTP request. - Comprehensive Audit Trail: Every view, download, password verification, and upload logs client IP, user-agent, action, and timestamp.
Sharing Center operates in Brum's universal dual-mode architecture:
- Floating Window Mode: A resizable, draggable floating dialog for inspecting shares, logs, and token links while continuing file management.
- In-Pane Docking Mode: Dock directly into Panel 1 or Panel 2 to manage all active shares alongside your active directory structure.
You can create a share link for any file, folder, or media collection:
- In either file panel, right-click on the file or folder (or long-press on touch devices).
- Select Create Share Link....
- Configure the sharing options in the modal:
-
Share Name: Descriptive label (e.g.
Client Design Proposal - Rev 2). - Expiration: Auto-expire after 1 hour, 24 hours, 7 days, 30 days, or Never.
- Password Protection: Optional passphrase for access gating.
- Download Limits: Maximum allowable downloads before auto-revocation.
-
Email Whitelist: Restrict access to specific email addresses or domains (e.g.
client@example.com,@partner-studio.com). - Watermark: Enable dynamic text watermark overlay for confidential reviews.
- Permissions: Toggle View Only, Allow Download, and Allow Uploads.
-
Share Name: Descriptive label (e.g.
- Click Generate Share Link.
- Copy the generated public URL (
https://your-domain.com/share/abc123xyz...).
- Open the Sharing Center from the Tools Launchpad or Settings (F10).
- Click + New Share.
- Select the target path and configure permissions.
Brum's sharing engine decouples viewing from downloading, enabling flexible delivery scenarios:
| Permission Profile | View in Browser | Download Binary | Upload Files | Ideal Use Case |
|---|---|---|---|---|
| Protected Showcase | Yes | No | No | Design studios, confidential drafts, client proofs, photo galleries, 3D CAD models |
| Standard Distribution | Yes | Yes | No | Software releases, client deliverables, document distribution |
| Client Upload Dropzone | No | No | Yes | Homework submission, client document collection, raw footage drops |
| Collaborative Hub | Yes | Yes | Yes | Shared project workspaces, partner folders |
- Password Verification: Passwords are cryptographically verified before metadata or file previews are unlocked.
-
Email Verification: When
Require Emailis enabled, the visitor must enter an email matching the allowed list/domain patterns before access is granted. -
Download Counter Caps: When
Max Downloads(e.g.,5) is reached, downloading is automatically disabled while viewing remains permitted. -
Auto-Expiration: Once the specified expiration time passes, all public endpoints immediately return
410 Gone.
For creative professionals, architects, and agencies presenting pre-release drafts or design mockups:
-
Watermark Engine:
- When
Watermark Enabledis checked, Brum injects a dynamic, semi-transparent diagonal watermark across previewed assets. - Custom watermark text can include client names, confidentiality notices, or dynamic tags (e.g.
CONFIDENTIAL - REVIEW COPY ONLY - DO NOT DISTRIBUTE).
- When
-
Download Prevention:
- Disabling
Allow Downloadremoves all download buttons and zip download actions from the public portal. - Internal viewers prevent standard direct-link extraction and right-click context scraping.
- Disabling
Visitors accessing /share/:token are presented with a clean, branded, responsive public portal:
- Single File Shares: Direct preview with media player, image studio, 3D CAD viewer, or document reader.
- Directory Shares: Multi-file explorer with grid/list view toggles, breadcrumb navigation, and search filter.
-
Integrated Native Viewers:
-
3D CAD Models: Interactive Three.js WebGL rendering for
.stl,.obj,.gltf,.glb,.3mf, and.stepwith orbit rotation, wireframe toggles, and mesh stats. - Images: High-resolution viewer with pan, zoom, and EXIF metadata.
- Video & Audio: Web media player supporting MP4, WebM, MP3, WAV, FLAC, OGG with seeking.
- Documents & PDF: Visual PDF studio and markdown/text reader with syntax highlighting.
- Code: Syntax highlighted code viewer with line numbers.
-
3D CAD Models: Interactive Three.js WebGL rendering for
-
Upload Dropzone:
- When
Allow Uploadis enabled on folder shares, visitors see a drag-and-drop file upload target with multi-file progress indicators.
- When
-
Responsive Layouts: Fully responsive across Phone (
<600px), Tablet (600-1024px), and Desktop (>1024px).
Access the centralized Sharing Center anytime via Tools Launchpad or openSharesManager():
- Active vs Revoked Filter: Inspect active, expired, and revoked shares.
- One-Click Revoke / Restore: Instantly pause access without deleting configuration or access logs.
- Edit Permissions: Modify expiration dates, toggle watermarks, or update passwords on existing live shares.
-
Audit Trail & Logs:
- Click Logs on any share to review all access events:
- Records Timestamp, IP Address, User Agent / Browser, and Action (
view,download,upload,verify).
All share management endpoints are authenticated with standard JWT Bearer tokens:
-
Endpoint:
POST /api/shares -
Headers:
Authorization: Bearer <token>,Content-Type: application/json - Payload:
{
"path": "/home/user/Projects/Design2026",
"name": "Design Drafts 2026",
"is_dir": true,
"allow_view": true,
"allow_download": false,
"allow_upload": false,
"password": "OptionalPassword123",
"expires_in_hours": 72,
"max_downloads": 0,
"require_email": true,
"allowed_emails": "client@example.com, @agency.com",
"watermark_enabled": true,
"watermark_text": "CLIENT DRAFT - CONFIDENTIAL"
}-
Endpoint:
GET /api/shares -
Headers:
Authorization: Bearer <token> -
Response: Array of
ShareItemobjects with access counts, expiration, and status.
-
Endpoint:
PUT /api/shares/:id -
Headers:
Authorization: Bearer <token>,Content-Type: application/json
-
Endpoint:
POST /api/shares/:id/revoke -
Payload:
{"revoke": true}
-
Endpoint:
GET /api/shares/:id/logs - Response:
[
{
"id": 1,
"share_id": 4,
"ip": "203.0.113.42",
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)...",
"action": "view",
"details": "previewed model.stl",
"created_at": "2026-09-24T10:15:30Z"
}
]-
Endpoint:
DELETE /api/shares/:id
-
GET /share/:token— Render responsive public share web portal. -
GET /api/public/shares/:token— Fetch public share metadata (name, is_dir, permissions, password_required). -
POST /api/public/shares/:token/verify— Verify password and obtain temporary access session. -
POST /api/public/shares/:token/verify-email— Verify guest email against allowed list. -
GET /api/public/shares/:token/preview— Stream asset preview (respectswatermark_enabledandallow_view). -
GET /api/public/shares/:token/download— Stream binary download (respectsallow_downloadandmax_downloads). -
POST /api/public/shares/:token/upload— Upload multipart file to shared directory (respectsallow_upload).
Brum — Multi-Pane Web Environment (File Commander/Manager)
Creator & Lab: Bolt J Woofson @ Woofsons Lab (www.arf.ac) • MIT License