mirror of
https://github.com/Nezumi-2711/google-drive-s3.git
synced 2026-09-22 05:31:47 +00:00
I.R.I.S. frontend integration docs
I.R.I.S. exposes a focused S3-compatible API on top of Google Drive. The live API reference is available from every enabled Worker deployment at /docs, with the source OpenAPI document at /openapi.yaml.
Start here
- Configure the Worker with
CORS_ALLOWED_ORIGINSfor every browser origin that will upload or download objects. - Keep
SECRET_KEYin a backend-for-frontend (BFF), not in browser code. - Let the BFF issue short-lived presigned URLs for a constrained bucket/key/method.
- Upload or download through the presigned URL from the browser.
| Document | Purpose |
|---|---|
| Integration guide | Browser upload, multipart upload, listing, CORS, and recommended architecture. |
| Authentication | The precise AWS Signature V4 behavior enforced by I.R.I.S. |
| Limitations | Unsupported S3 features and Google Drive operational limits. |
examples/bff-presign.ts |
A Workers BFF endpoint that creates short-lived PUT URLs. |
examples/browser-upload.ts |
Single object upload from a browser. |
examples/browser-multipart.ts |
Strictly sequential browser multipart upload. |
Browser security model
Browser ── POST /presign ──> BFF (holds SECRET_KEY)
│ │
└──── presigned S3 request ────┴──> I.R.I.S. Worker ──> Google Drive
The browser never receives SECRET_KEY. Presigned URLs must be short lived and scoped to the single object operation the browser needs.