Technical Specification
Transfer Lifecycle & Workflow Specification
Detailed protocol execution sequence from user file selection to local download completion.
Phase 1: Session Initialization
When a user initiates a transfer by selecting a file on the host machine:
- File Metadata Extraction: The browser reads file properties (filename, size in bytes, MIME type) via the HTML5 File API. Filenames are sanitized locally to prevent path traversal or control character injection.
- Room Code Generation: A cryptographically pseudorandom 6-digit alphanumeric room code is generated from a 32-character alphabet (excluding ambiguous letters like 'l', '1', 'o', '0').
- Signaling Registration: The host registers the room state on the signaling relay with an initial status of
waitingand a 15-minute time-to-live (TTL). - QR Code Rendering: A vector SVG QR code encoding the room URL (
https://shareonline.net/room/[code]) is rendered on the host screen.
Phase 2: Signaling & Peer Pairing
When the receiving client joins:
- Room Lookup: The receiver requests room metadata via
POST /api/signalwith actionjoin-room. - SDP Offer/Answer: The host constructs a WebRTC SDP offer describing its transport capabilities. The receiver processes the offer and returns an SDP answer.
- ICE Gathering: Both peers query configured STUN servers (
stun:stun.l.google.com:19302) to discover public IP/port bindings and exchange candidates via signaling. - Direct Pathway Selection: WebRTC establishes the shortest direct network path (LAN or WAN UDP hole-punching).
Phase 3: Binary Stream Transmission
- DataChannel Ready: The host confirms the
RTCDataChannelstate isopen. - Slicing: The file is read in 32,768-byte (32 KB) chunks using
FileReader.readAsArrayBuffer(). - Backpressure Throttling: If
dataChannel.bufferedAmount > 524,288bytes, transmission halts untilbufferedamountlowfires. - Chunk Delivery: Chunks flow directly over SCTP/DTLS to the receiver without server storage.
Phase 4: Finalization & Teardown
- Completion Token: Upon reaching
offset >= file.size, the host transmits a{ type: 'complete' }signal. - Blob Compilation: The receiver packages accumulated
ArrayBuffer[]chunks into a unifiedBlobmatching the file MIME type. - Download Trigger: An object URL (
URL.createObjectURL(blob)) is attached to a temporary anchor element and clicked programmatically. - Session Purge: Both peers close connections, garbage-collect in-memory buffers, and trigger signaling cleanup.