# assertSha

```ts
function assertSha(asset, fn): void;
```

Defined in: packages/asset-client/dist/index.d.ts:142

Refuse a value whose `sha` is missing or malformed, instead of interpolating
it into a URL.

## Found by a Haiku agent, 2026-08-23

It did the most natural thing there is — passed the result of `upload()`
straight to `transform()` — and got:

    https://8ok.uk/t/width=1280/undefined.webp

`UploadResult` carries `sha256`; every URL builder wants `sha`. TypeScript
catches the mismatch, but an agent running through `bun` (or anyone in plain
JS) sees no error at all: just a 200-shaped URL with the word `undefined` in
it, which 404s later and somewhere else.

The house rule applies exactly as it does to private assets: **a silence
reads as "you can't"**. A builder that cannot name the asset must say so at
the call site, not hand back a string that will fail far from here.

## Parameters

| Parameter | Type |
| ------ | ------ |
| `asset` | \{ `sha?`: `unknown`; \} |
| `asset.sha?` | `unknown` |
| `fn` | `string` |

## Returns

`void`