assertPublic
function assertPublic( asset, fn, escapeHatch): void;Defined in: packages/asset-client/src/access.ts:215
Refuse to build a public URL for a private asset.
Doctrine of the house: a silence reads as “you can’t”. Returning
https://8ok.uk/5/v/<sha>-lg.webp for a private asset is not a smaller
failure than throwing — it is a URL that answers 404, in a platform where a
404 has always meant “that file does not exist”. The caller then debugs the
wrong thing.
Only refuses when it was actually TOLD. A caller passing { sha } carries no
visibility, and guessing would break every existing call site to protect
assets that are not there.
Parameters
Section titled “Parameters”| Parameter | Type | Description |
|---|---|---|
asset |
VisibilityHint |
- |
fn |
string |
- |
escapeHatch |
string |
The call to make instead — declared per call site, not guessed. Named escapeHatch, not escape: the bare name shadows the deprecated global escape, which biome flags as an error. Nothing here calls that global, so this was never a defect — but it is a lint error standing in a PUBLISHED package, and a parameter name is not part of the API, so the cost of clearing it is zero. It matters which one: getPrivateAssetUrl signs a STORED preset, and pointing a transform caller at it sends them to a function that cannot do what they asked for. The first version of this message named getPrivateAssetUrl for all seven builders; a test caught it. |
Returns
Section titled “Returns”void