Skip to content

Repository files navigation

Echo Document Manager

Multi-tenant document management on Cloudflare Workers (Hono, D1 + KV + R2). Folders, file upload/versioning/download, token-gated public sharing, comments, trash with 30-day auto-purge, per-tenant analytics, Stripe subscription billing across four storage tiers, and AI-assisted summarization/auto-tagging via the fleet's engine runtime.

Endpoints

Access Method Path Description
Public GET /health, /status Health
Public GET /shared/:token, /shared/:token/download Public share links (own unguessable-token gate)
Public POST /webhooks/stripe Stripe webhook (own HMAC signature check)
Authenticated GET/POST/PUT/DELETE everything else Tenants, folders, files (upload/download/versions/comments), shares, trash, activity, analytics, plans, AI

Authentication

All routes other than the public ones listed above require X-Echo-API-Key, compared to env.ECHO_API_KEY in constant time. See SECURITY.md for what changed in this consolidation pass -- the repo as found exempted every GET request from auth, which meant /files/:id/download served real file content to anyone who could guess a file id.

Verify

npm install
npm test

Security

This service stores tenant document content and Stripe billing metadata. See SECURITY.md to report a vulnerability -- never as a public issue.

License

See LICENSE. Contributions: see CONTRIBUTING.md.

About

Multi-tenant document management (Cloudflare Worker, Hono, D1+KV+R2) -- folders, file upload/versioning/download, token-gated sharing, Stripe billing tiers, AI summarization.

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages