I am working with aws sdk with js. Recently I am using signed url to protect user content after they uploaded the files. I understand that the expire time can be set by seconds and default is 3600 as mentioned in documentation.
I have created the signed url in return successfully. I have my code below
const adapter = require('skipper-better-s3')({
adapter: require('skipper-better-s3'),
key: key,
secret: secret_key,
saveAs: path,
bucket: bucket,
s3params: {
ACL: 'public-read'
},
})
adapter.url('getObject', { s3params: { Key, Expires: 10 } });
Things does work fine, but the problem I am having now which I am not too sure what caused it is that for example, if I use chrome to open up the signed url, I can keep on using the signed url even after 10 seconds which is the Expires I set but that is IF I opened the url once already.
Let's say if I generated the signed url, if I did not open the url within the 10 seconds, I open it then I will get blocked which is totally correct BUT if I opened the url within the 10 seconds, then even after 10 minutes I am still able to re-use that url, if I use new tab / new window, I still can open it with that url. But if I use a private / congnito window then I would be blocked or if I use a different browser then I will get blocked.
So what is causing the browser to keep on able to open that url though, even if with new tab or new window. I want to disable this as I do not want the cache being there and wants it to expire at the same time.
Hopefully my explanation is clear enough.
Thanks in advance for any suggestions / advices.