Security and limits
The module treats share-sheet input as untrusted data supplied by another application.
Default limits
| Limit | Default |
|---|---|
| Text or URL representation | 256 KiB |
| Items in one share | 20 |
| One attachment | 100 MiB |
| All binary data in one share | 250 MiB |
| Pending receipts per platform | 20 |
| All module-managed attachments | 1 GiB |
| Acknowledged, unreleased files | Eligible for lazy cleanup after seven days from receipt |
File and item limits are configurable where exposed by the config plugin. Text, pending-receipt, and total managed-storage caps are package safety boundaries.
releaseSharedFilesAsync deletes acknowledged receipt directories immediately. The seven-day value is only a cleanup eligibility threshold for acknowledged files that were not explicitly released. Cleanup runs on later queue operations; it is not a background timer or a guaranteed maximum retention period.
Android URI validation
The module accepts only content:// streams that:
- belong to the current intent;
- arrive with
FLAG_GRANT_READ_URI_PERMISSION; - pass an explicit URI permission check.
It rejects file:// input and does not treat ambient already-held access as a valid share grant.
Safe copies and filenames
Attachments are streamed with byte limits. Generated filenames discard source paths and unsafe characters. JavaScript receives a local module-managed URI instead of depending on provider access remaining valid.
Atomic persistence
- Android queue updates use an atomic file and synchronized processing.
- iOS commits one atomic JSON queue record under a cross-process lock.
- Hosts never intentionally read partially written records.
Privacy
The package does not upload payloads, attachments, or logs. All intake and queue processing happens on device. Your application is responsible for any network or analytics behavior after receiving a payload.
Application responsibilities
- Treat text and file metadata as untrusted input.
- Make business processing idempotent.
- Copy long-lived attachments into application-owned storage.
- Acknowledge only after durable processing.
- Release module-managed files when no longer needed.
- Avoid logging payload contents in production.