@xyo-network/dapp-kit-cloudflare-r2
v2.1.4
Published
Cloudflare R2 resource adapters and qualification for headless XL1 dApps
Readme
@xyo-network/dapp-kit-cloudflare-r2
Cloudflare R2 specialization and qualification for dapp-kit deployments.
The package combines the portable @xyo-network/dapp-kit-s3 object store with:
- explicit R2 account endpoint construction;
- mandatory injected clients or explicit bucket-scoped credentials;
- credential-free, hash-bound resource plans;
- public custom-domain and browser CORS policy;
- a destructive prefix-confined credentialed qualification gate; and
- a read-only public URL/CORS audit.
R2 resource plans intentionally admit only datalakes, projection stores, and checkpoint stores. They do not classify R2 as a secret store, challenge store, queue, rate limiter, or high-contention effect journal. The admitted per-key write rate is part of the plan instead of being hidden behind “S3 compatible.”
import { CloudflareR2ObjectStore } from '@xyo-network/dapp-kit-cloudflare-r2'
const store = new CloudflareR2ObjectStore({
accountId,
bucket,
credentials: { accessKeyId, secretAccessKey },
maximumObjectBytes: 4 * 1024 * 1024,
prefix: 'my-dapp/public-projection',
})
// ...publish immutable generations and conditionally advance head.json...
store.close()Constructing a store is not qualification. Run qualifyCloudflareR2 against
the intended bucket using a CloudflareR2ObjectStore constructed with explicit
credentials, and retain its result as credentialed-cloudflare-r2 evidence.
The API refuses to issue that evidence class for an injected client.
probeCloudflareR2Capabilities is the lower-level fake/local gate and returns
capabilities without claiming credentialed R2 evidence.
