[{"data":1,"prerenderedAt":192},["ShallowReactive",2],{"nav-docs":3,"nav-api":60,"docs-receiving-files":89},[4],{"title":5,"path":6,"stem":7,"children":8},"Docs","\u002Fdocs","docs",[9,12,16,20,24,28,32,36,40,44,48,52,56],{"title":10,"path":6,"stem":11},"Installation","docs\u002Findex",{"title":13,"path":14,"stem":15},"Sending files","\u002Fdocs\u002Fsending-files","docs\u002F02.sending-files",{"title":17,"path":18,"stem":19},"Receiving files","\u002Fdocs\u002Freceiving-files","docs\u002F03.receiving-files",{"title":21,"path":22,"stem":23},"Passwords, galleries and backgrounds","\u002Fdocs\u002Fshare-options","docs\u002F04.share-options",{"title":25,"path":26,"stem":27},"Expiry and deletion","\u002Fdocs\u002Fexpiry","docs\u002F05.expiry",{"title":29,"path":30,"stem":31},"Users","\u002Fdocs\u002Fusers","docs\u002F06.users",{"title":33,"path":34,"stem":35},"Configuration","\u002Fdocs\u002Fconfiguration","docs\u002F07.configuration",{"title":37,"path":38,"stem":39},"Colours and branding","\u002Fdocs\u002Fcolors","docs\u002F08.colors",{"title":41,"path":42,"stem":43},"Docker","\u002Fdocs\u002Fdocker","docs\u002F09.docker",{"title":45,"path":46,"stem":47},"API keys","\u002Fdocs\u002Fapi-keys","docs\u002F10.api-keys",{"title":49,"path":50,"stem":51},"MCP server","\u002Fdocs\u002Fmcp-server","docs\u002F11.mcp-server",{"title":53,"path":54,"stem":55},"Troubleshooting","\u002Fdocs\u002Ftroubleshooting","docs\u002F12.troubleshooting",{"title":57,"path":58,"stem":59},"Contributing","\u002Fdocs\u002Fcontributing","docs\u002F13.contributing",[61],{"title":62,"path":63,"stem":64,"children":65},"Api","\u002Fapi","api",[66,69,73,77,81,85],{"title":67,"path":63,"stem":68},"REST API","api\u002Findex",{"title":70,"path":71,"stem":72},"Transfers","\u002Fapi\u002Ftransfers","api\u002F02.transfers",{"title":74,"path":75,"stem":76},"Uploading files","\u002Fapi\u002Fupload","api\u002F03.upload",{"title":78,"path":79,"stem":80},"Sending a transfer","\u002Fapi\u002Fsend","api\u002F04.send",{"title":82,"path":83,"stem":84},"Downloading","\u002Fapi\u002Fdownload","api\u002F05.download",{"title":86,"path":87,"stem":88},"Recipients","\u002Fapi\u002Frecipients","api\u002F06.recipients",{"id":90,"title":17,"body":91,"description":101,"extension":187,"meta":188,"navigation":189,"path":18,"seo":190,"stem":19,"__hash__":191},"docs\u002Fdocs\u002F03.receiving-files.md",{"type":92,"value":93,"toc":180},"minimark",[94,98,102,107,118,121,141,144,148,151,154,157,161,173],[95,96,17],"h1",{"id":97},"receiving-files",[99,100,101],"p",{},"This is the half an ordinary file host does not do, and the reason the app\nexists rather than a link to WeTransfer.",[103,104,106],"h2",{"id":105},"how-it-works","How it works",[99,108,109,110,113,114,117],{},"An administrator adds an outside contact under ",[111,112,29],"strong",{}," — an agency client, a\nphotographer, an accountant — as a ",[111,115,116],{},"guest",". A guest has no password and never\nsets one.",[99,119,120],{},"When they need to send you something:",[122,123,124,128,131,138],"ol",{},[125,126,127],"li",{},"They open your instance and enter their address.",[125,129,130],{},"If that address is on the list, they receive a one-time sign-in link.",[125,132,133,134,137],{},"The link opens an upload form where they choose ",[111,135,136],{},"which team member"," should\nreceive the files.",[125,139,140],{},"That person gets the transfer, with the guest's address as the reply-to.",[99,142,143],{},"No account for them to create, no password for them to forget, and nothing for\nyou to administer beyond adding the address once.",[103,145,147],{"id":146},"why-a-guest-can-only-address-your-team","Why a guest can only address your team",[99,149,150],{},"The recipient picker is filled from your member list, and the choice is resolved\nagainst the user table on the server. Addresses typed by the guest are refused.",[99,152,153],{},"Without that, anyone holding a magic link could use your server to mail an\narbitrary third party — a relay with your domain on it. A guest can pick who at\nyour company receives their files, and nothing else.",[99,155,156],{},"Guests also don't choose retention. They are dropping files off, not publishing,\nso the instance default applies rather than letting an outside contact pin\nsomething on your disk indefinitely.",[103,158,160],{"id":159},"magic-links","Magic links",[99,162,163,164,168,169,172],{},"The link is single-use and expires after ",[165,166,167],"code",{},"NUXT_MAGIC_LINK_MAX_AGE_MINUTES"," (30\nby default). Guest sessions are deliberately short — ",[165,170,171],{},"NUXT_GUEST_SESSION_MAX_AGE_HOURS",",\n12 by default — because a magic link is a one-off errand, not a standing login.",[99,174,175,176,179],{},"Requests are rate limited per IP, and the endpoint answers ",[111,177,178],{},"identically","\nwhether or not the address is known. That matters: an endpoint that says \"no\nsuch user\" is a way to test who your clients are.",{"title":181,"searchDepth":182,"depth":182,"links":183},"",2,[184,185,186],{"id":105,"depth":182,"text":106},{"id":146,"depth":182,"text":147},{"id":159,"depth":182,"text":160},"md",{},true,{"title":17,"description":101},"C2nioD8unw06V_gtQ7LwinMMWQfgs5yVMrq3vWGKVXM",1790104591922]