Skip to content
scroll to zoom · drag to pan

assertPublic

function assertPublic(
asset,
fn,
escapeHatch): void;

Defined in: packages/asset-client/dist/index.d.ts:106

Refuse to build a public URL for a private asset.

Doctrine of the house: a silence reads as “you can’t”. Returning https://8ok.uk/5/v/<sha>-lg.webp for a private asset is not a smaller failure than throwing — it is a URL that answers 404, in a platform where a 404 has always meant “that file does not exist”. The caller then debugs the wrong thing.

Only refuses when it was actually TOLD. A caller passing { sha } carries no visibility, and guessing would break every existing call site to protect assets that are not there.

Parameter Type Description
asset VisibilityHint -
fn string -
escapeHatch string The call to make instead — declared per call site, not guessed. Named escapeHatch, not escape: the bare name shadows the deprecated global escape, which biome flags as an error. Nothing here calls that global, so this was never a defect — but it is a lint error standing in a PUBLISHED package, and a parameter name is not part of the API, so the cost of clearing it is zero. It matters which one: getPrivateAssetUrl signs a STORED preset, and pointing a transform caller at it sends them to a function that cannot do what they asked for. The first version of this message named getPrivateAssetUrl for all seven builders; a test caught it.

void