# assertPublic

```ts
function assertPublic(
   asset, 
   fn, 
   escapeHatch): void;
```

Defined in: packages/asset-client/dist/index.d.ts:106

Refuse to build a public URL for a private asset.

Doctrine of the house: **a silence reads as "you can't"**. Returning
`https://8ok.uk/5/v/<sha>-lg.webp` for a private asset is not a smaller
failure than throwing — it is a URL that answers 404, in a platform where a
404 has always meant "that file does not exist". The caller then debugs the
wrong thing.

Only refuses when it was actually TOLD. A caller passing `{ sha }` carries no
visibility, and guessing would break every existing call site to protect
assets that are not there.

## Parameters

| Parameter | Type | Description |
| ------ | ------ | ------ |
| `asset` | [`VisibilityHint`](/api/nitida/sdk/type-aliases/visibilityhint/) | - |
| `fn` | `string` | - |
| `escapeHatch` | `string` | The call to make instead — declared per call site, not guessed. Named `escapeHatch`, not `escape`: the bare name shadows the deprecated global `escape`, which biome flags as an error. Nothing here calls that global, so this was never a defect — but it is a lint error standing in a PUBLISHED package, and a parameter name is not part of the API, so the cost of clearing it is zero. It matters which one: `getPrivateAssetUrl` signs a STORED preset, and pointing a transform caller at it sends them to a function that cannot do what they asked for. The first version of this message named `getPrivateAssetUrl` for all seven builders; a test caught it. |

## Returns

`void`