Function
The content key, already joined from the catch-all segments
The routing store for this request
A 302 to the asset, a 400 for an unsafe key, or a 404 for a missing one
Never streams bytes. Proxying would put the whole media corpus through the
Node process and force this route to reimplement Range handling for video
seeking; a redirect lets the browser fetch and seek directly against the
bucket, which is what buckets and CDNs are for. The browser follows the
redirect once per asset, then talks to the store for every range after.
A private store's key is answered with a freshly-signed URL. A public one is redirected to its permanent URL rather than 404ing, so a link minted while a store was private keeps working after it is opened up.
Answers a content request with a redirect to wherever the asset actually lives.