PrivShare

Verification guide

Verify It Yourself

This walkthrough is for technical users who want to inspect what PrivShare sends over the network during normal share creation and retrieval.

Use Test Data Only

Do not use real secrets for this walkthrough. Use a harmless sentinel value that you can safely search for in DevTools.

Creation request:
POST /api/shares

Retrieval request:
POST /api/shares/[id]/retrieve

Fragment-key link:
/s/[id]#key=...

Password-share link:
/s/[id]

Network Check

The goal is to confirm that plaintext stays out of request URLs, request bodies, and responses.

  1. 1Open browser DevTools and switch to the Network tab.
  2. 2Create a test text share with a harmless sentinel value that is not a real secret.
  3. 3Inspect the creation request.
  4. 4Confirm the request contains ciphertext, IV, lifecycle fields, and verifier or password-protection metadata only.
  5. 5Confirm your sentinel plaintext is absent from the request URL, request body, and response.
  6. 6Open the generated recipient link in a fresh tab.
  7. 7Confirm the fragment key is present only in the visible URL for fragment-key shares and is not sent in HTTP requests.
  8. 8Trigger decryption in the browser.
  9. 9Inspect the retrieval request.
  10. 10Confirm retrieval sends only a verifier and receives ciphertext/IV or encrypted-file download metadata.

Additional Checks

Repeat the same inspection for other share modes when you can do so safely.

  • Password shares: confirm the raw share password is absent from requests.
  • Environment-variable shares: confirm variable names, values, comments, and variant names are absent from requests.
  • File shares: confirm file upload requests carry encrypted bytes only. Provider-console metadata verification is owner-side QA.
  • Recipient emails: confirm delivered emails contain keyless /s/[id] links only.

What This Does Not Prove

DevTools inspection is useful, but it is not a complete audit.

  • It does not prove future deployments will serve identical JavaScript.
  • It does not prove production Vercel, email, S3, CloudFront, or database settings are correct.
  • It does not prove strict script CSP, custom rate limiting, or production observability are implemented.
  • It does not protect against compromised devices, malicious extensions, or recipients copying plaintext after decryption.