S3 Provider — Reference
Configure the endpoint, signing region and credentials used by object-storage actions.
Configure the endpoint, signing region and credentials used by object-storage actions.
Before you begin
Section titled “Before you begin”- An object-storage account with a test bucket and credentials limited to the intended operations.
Configure a storage connection
Section titled “Configure a storage connection”The provider definition creates a storage client for later actions. Selecting it in an action does not provision a bucket or make stored objects public. Definition fields appear when creating/editing the module; an ordinary action selects the existing provider.
Definition controls
Section titled “Definition controls”| Control | Meaning |
|---|---|
| Name | The reusable provider definition name used by storage actions. |
| Service | Selects the editor’s AWS, Digital Ocean, Vultr, Linode, Wasabi or Custom endpoint controls. A preset does not guarantee support for every API operation or current region. |
| Region / Endpoint | Preset services offer endpoint choices. Custom accepts an endpoint hostname and signing region. The installed wrappers prepend https://, so enter the host rather than a full URL with that scheme already included. Verify current service endpoints with the provider. |
| Access Key Id | The server-side credential identifier authorized for the intended bucket/key operations. |
| Secret Access Key | The corresponding secret. Do not expose it in page code, output or client upload configuration. |
| Force path style | Node.js passes this to the SDK to request path-style addressing. The installed PHP provider does not pass an equivalent flag, so do not assume identical behavior for a custom endpoint. |
Verify the least required operation
Section titled “Verify the least required operation”Save a test provider and start with the permitted read/list operation for an existing test bucket. Then test a new scoped object key and the required upload/download flow. A successful list call does not prove that writes, deletes, signed requests or cross-bucket copies are allowed.
ACLs and bucket ownership
Section titled “ACLs and bucket ownership”AWS disables ACLs by default for new buckets using Bucket owner enforced ownership. Such buckets accept uploads without an ACL or with bucket-owner-full-control; other ACLs can be rejected. Wappler’s Access control is therefore not a complete bucket-access policy. See AWS Object Ownership. Check the saved ACL option and your provider’s policy before changing access settings.
Presigned access is temporary permission
Section titled “Presigned access is temporary permission”A presigned URL grants the specified operation using the signer’s permissions until its effective expiry. It can be reused while valid, and uploading to an existing key can replace that object. Keep the URL private and choose an authorized destination before signing. See AWS presigned URLs. Signing is separate from transferring and validating bytes.
Use storage in a complete workflow
Section titled “Use storage in a complete workflow”Connect the storage operation to explicit server authorization, file validation and metadata persistence. Do not treat a generated Location string as proof that an object is public.
Check your result
Section titled “Check your result”You can select an endpoint/region and credential scope appropriate to the storage operations your application needs.