A presigned object URL is a bearer capability for a specific request. Its usable lifetime is limited by the requested expiry, the signer’s underlying credential lifetime, and any policy conditions such as signature age or network path. Revoking an application session alone may not immediately revoke a URL already issued. Treat it as sensitive data, keep its scope narrow, and provide a clear response when clients retry after expiry.
Presigned object access: bound authority and expiry
Operational decision
A support portal allows a customer to download one invoice PDF. Authorize the customer against the invoice record before generating a URL for the exact object version and read operation. Use a short expiry derived from expected transfer time and client conditions; for a large file, allow a new authorized URL rather than issuing a day-long capability. Avoid recording the full query string in analytics, reverse-proxy logs, support tickets, or referrer-bearing pages. If a credential is rotated or disabled, test how outstanding URLs behave; do not promise instant revocation from an application database flag. For sensitive exports, consider a mediated download path that rechecks access, and use provider policy to restrict signature age or network reach where the product permits. Test clock skew, expired credentials, a copied URL used by a second client, and a retry after the URL expires. Monitor issuance volume and unusual download geography without logging the capability itself.
Invoice download capability review
Authorization: customer owns invoice record
Scope: one read of one object version
Expiry: shortest workable transfer window
Logging: omit signed query string
Reissue: require a fresh authorization check
Revocation test: signer credential and storage policy behaviorCost and verification
Issuing a URL is cheap, but mediated access adds an application hop and possibly bandwidth charges. A shorter expiry reduces the exposure window while increasing legitimate reissue attempts on slow networks. Measure denied reissues, expired-transfer retries, issuance rate, and downloads outside expected client conditions. The security cost of logging the token is independent of how short its expiry looks on a dashboard.
Common Mistakes
- Do not treat a presigned URL as bound to the first browser that opens it.
- Do not assume requested expiry outlives temporary signer credentials.
- Do not put the signed query string in telemetry or error reports.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Secret rotation rollout: update the issuer, consumer, and active connections
- Telemetry redaction: remove sensitive fields before an exporter or sampler sees them
- Encryption key rotation: keep old data decryptable during recovery
- Object version recovery: distinguish a delete marker from lost bytes
