> ## Documentation Index
> Fetch the complete documentation index at: https://pavan-c90e8846.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and Access Control in File Transfer Pavan

> Learn how File Transfer Pavan protects uploads with PINs, bcrypt password hashing, Supabase Row-Level Security, cryptographic tokens, and HTTPS-enforced storage.

File Transfer Pavan uses a multi-layered security model. Every upload is validated by the server first, protected by cryptographically secure tokens, and stored behind Supabase Row-Level Security policies. Passwords are never hashed on the client side. This guide covers the architecture, access controls, and protections you can rely on.

## Security Features

| Feature | Details |
| - | - |
| Server-side validation | `validate_file_upload()` RPC runs before every upload to enforce size and type rules |
| Cryptographic tokens | `generate_share_token()` produces URL-safe, secure random tokens. Base64 variants are handled for cross-platform compatibility |
| PIN protection | `generate_share_pin()` creates numeric PINs required to access the download page |
| Password hashing | Bcrypt is applied inside PostgreSQL via `insert_file_with_password()`. The client never hashes or stores the raw password |
| Row-Level Security | Supabase RLS policies restrict all `SELECT`, `INSERT`, `UPDATE`, and `DELETE` to authenticated owners or valid share tokens |
| Signed URLs | File access URLs expire after one hour, preventing long-lived unauthenticated access |
| HTTPS enforced | Supabase Storage automatically serves all content over HTTPS |
| Audit logs | Admin actions are tracked in the `audit_logs` table for accountability |
| Error boundaries | The `ErrorBoundary` component prevents stack traces or internal state from leaking to the client on crashes |

## Authentication

File Transfer Pavan authenticates users through Supabase Auth with email and password. Session state is managed globally by the `AuthContext` React context. Protected routes, including the Dashboard, Admin panel, and Profile pages, are wrapped with the `AuthGuard` component.

If a user is not authenticated when visiting a protected route, they are redirected to the sign-in page. Once authenticated, the route renders.

## Admin Access Control

The admin panel (`AdminDashboard.tsx`, approximately 130 KB) is reserved for users with elevated privileges. Admins can perform the following actions:

* **User management**: view, edit, ban, or delete user accounts
* **File moderation**: review uploaded files, quarantine suspicious items, and delete violations
* **Audit log review**: inspect entries from the `audit_logs` table for forensic review
* **Bulk notifications**: send announcements or alerts to all users or filtered subsets

Only authenticated admin users can access these features. The underlying RLS policies enforce this at the database level as well.

<Warning>
  Never expose `VITE_SUPABASE_SERVICE_KEY` on the client side. This key is for server-level or admin operations only. Use it only in secure server contexts, Supabase Edge Functions, or your CI environment. Exposing it in the browser compromises your entire database.
</Warning>

## Database Schema

The following abbreviated schema defines the core tables that enforce access control and audit behavior:

**uploaded\_files**

| Column | Type | Notes |
| - | - | - |
| id | uuid | Primary key |
| user\_id | uuid | Owner reference, protected by RLS |
| share\_token | text | Unique, URL-safe token for sharing |
| share\_pin | text | Optional numeric PIN |
| password\_hash | text | Optional bcrypt hash |
| download\_count | integer | Counter incremented per download |
| expires\_at | timestamp | Optional expiration timestamp |

**file\_collections**

| Column | Type | Notes |
| - | - | - |
| id | uuid | Primary key |
| user\_id | uuid | Owner reference, protected by RLS |
| share\_token | text | Unique token for the collection |
| share\_pin | text | Optional numeric PIN for the collection |

**download\_history**

| Column | Type | Notes |
| - | - | - |
| file\_id | uuid | Foreign key to uploaded\_files |
| ip\_address | inet | Anonymous downloader IP |
| user\_agent | text | Browser / client identifier |
| downloaded\_at | timestamp | Exact time of download |

**audit\_logs**

| Column | Type | Notes |
| - | - | - |
| admin\_id | uuid | Acting administrator |
| action | text | Performed action name |
| target\_user\_id | uuid | Affected user, if any |
| target\_file\_id | uuid | Affected file, if any |
| details | jsonb | Structured context for the action |

## Next Steps

* [Upload and Organize Files](/file-transfer/uploading-files)
* [Share Files with Secure Links and QR Codes](/file-transfer/sharing-files)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.