A large export often begins as a server job rather than an immediate response. The server can prepare an artifact, expose a status resource, then let the browser download it as a normal file response. That path avoids converting the whole artifact into a JavaScript Blob merely to trigger Save, which can duplicate large bytes in memory. If the product supports resume, byte-range requests must refer to one immutable artifact version; an ETag or server-issued artifact ID protects against stitching bytes from different revisions. The server should set a safe filename, content type, length where known, and an expiry policy. A client must not call a download complete merely because an export job reached Ready.
Large Export Download and Integrity
Working case
Reviewer 29 requests a 740 MB case evidence export. Building it takes 47 seconds, so the API returns a job ID and a status route. When Ready, the UI offers a normal download link that streams the artifact; it does not fetch the whole file into an ArrayBuffer. The connection fails halfway. A resumed request is allowed only if the artifact ID and validator match the original bytes. If the server rebuilt the export from changed case data, start a new download rather than appending a new revision to the old half-file. Expired artifacts require a new job.
Implementation boundary
function mayResumeExport(saved, current) {
return saved.artifactId === current.artifactId && saved.etag === current.etag;
}
console.log(mayResumeExport({ artifactId: "case-47-v6", etag: "a9" }, { artifactId: "case-47-v7", etag: "b1" }));
// Output: falseThe comparison captures identity, while actual range support requires correct server responses and client handling. Keep export job authorization tied to the requesting account and case; a guessed artifact path must not bypass that check. Provide a normal anchor or browser navigation for download when possible, and let server headers describe the file. For a custom download manager, validate Content-Range, total length, and validator before appending bytes. Clean up temporary artifacts on expiry and report whether a cancelled client transfer also cancels server preparation, since those lifetimes can differ.
Cost and boundaries
Generating an export of b bytes takes at least O(b) output work and storage or transfer, while buffering it fully in browser JavaScript can add O(b) heap or Blob memory. A streamed download keeps application memory closer to a bounded chunk size, subject to browser and server implementation. Resumable ranges save repeated transfer after failure but add validator, storage-retention, and bookkeeping cost. Expiring artifacts too quickly forces costly rebuilds; retaining them too long increases storage and privacy exposure. Measure peak browser memory, preparation time, transfer restart bytes, and cleanup lag.
Failure trace
The UI fetches the 740 MB response, calls arrayBuffer(), creates a Blob, and builds an object URL. On a memory-constrained device the tab crashes before the save dialog appears. Use a normal download response or bounded streaming destination when supported. A second failure appends a resumed range from a new export revision because the filename matches. Compare immutable artifact identity and validator; reject mixed versions and restart. If status says Ready but the download returns an access denial, show a specific error instead of a false completion banner.
Verification
- A large download does not require a full JavaScript buffer.
- Range resume rejects bytes from a changed artifact.
- Artifact access and expiry stay tied to the requesting account.
Practice drill
Generate a large test export and compare browser memory for arrayBuffer buffering versus a normal download. Interrupt halfway, then attempt resume with the same artifact ID and with a changed validator. The latter must restart. Expire the artifact and ensure the status route explains how to create a new one. Try a second account's artifact ID and verify denial. Cancel preparation before Ready and confirm whether temporary files are removed or finish under a documented retention policy.
Decision note
Let the server own artifact production and identity; let the browser download bounded bytes without duplicating the whole file in application memory.
Common Mistakes
- Calling a Ready job a completed download.
- Buffering a huge response solely to trigger Save.
- Resuming by filename without an immutable artifact validator.
Connected lessons
Streaming and Large Data Interfaces; Incremental Response Framing and UTF-8; Stream Backpressure and Bounded Work; Stream Cancellation and Partial-Result Contract; Accepted Operations and Status Resources; Safe File Upload Pipeline; Authorization: check permission for this record on every request.
Apply and check
Build Project: streamed case activity and export and review Web Development: streams and interaction decisions quiz.
Further connections
Private Export Authorization and Artifact Scope; Export and Erasure Job State.
