Skip to content
scroll to zoom · drag to pan

assertSha

function assertSha(asset, fn): void;

Defined in: packages/asset-client/src/access.ts:262

Refuse a value whose sha is missing or malformed, instead of interpolating it into a URL.

It did the most natural thing there is — passed the result of upload() straight to transform() — and got:

https://8ok.uk/t/width=1280/undefined.webp

UploadResult carries sha256; every URL builder wants sha. TypeScript catches the mismatch, but an agent running through bun (or anyone in plain JS) sees no error at all: just a 200-shaped URL with the word undefined in it, which 404s later and somewhere else.

The house rule applies exactly as it does to private assets: a silence reads as “you can’t”. A builder that cannot name the asset must say so at the call site, not hand back a string that will fail far from here.

Parameter Type
asset { sha?: unknown; }
asset.sha? unknown
fn string

void