· 4 min read · Go · Networking · Product
xposed: Sharing a File Shouldn’t Need an Upload
Right-click any file and get a public HTTPS link and a QR code. Nothing uploads: it streams from your disk, and the link expires after 24 hours. How it works, and what shipping 13 releases in 7 days taught me.
Sending someone a file still takes too many steps. Pick a service, upload the file, wait, copy a link, and remember to delete it later. If the file is big, you wait twice: once while it uploads, and again while they download it. The file was already sitting on my disk. Why does it need to travel anywhere first?
xposed is my answer. Right-click any file on a Mac, Windows or Linux machine, pick Share with xposed, and you get a public HTTPS link and a QR code. There’s no upload step. When someone opens the link, the file streams straight from your disk, through the xposed relay, to their browser. Nothing keeps a copy, and closing the share kills the link for everyone at once.
What it does
- Right-click to share, from GNOME Files, a Finder Quick Action or File Explorer. Or
xposed share <file…>from a terminal. - A link and a QR code for every share, on a control panel that opens in your browser.
- An optional 6-digit PIN, with a lockout after five wrong tries, and an optional cap on how many people can download.
- A download log with the file, time, browser and bytes sent, exportable as CSV. It stays on your machine.
- Links expire after 24 hours, downloaded or not. xposed is for quick sharing, not hosting.
- Resumable downloads via HTTP Range, because the file never moved.
How it works
There are two binaries and one relay.
-
xposeddis a small daemon. It runs one HTTP server on loopback and one connection to the relay at*.getxposed.link, using frp’s client as a Go library, so there’s no second executable. Each share is a row in a SQLite registry, addressed by an unguessable token in the path (/s/<token>), so a new share costs nothing extra. -
xposedis a thin CLI. It talks to the daemon over a Unix socket and starts it on demand, so there’s no service to install. - Every computer you sign in on gets its own stable subdomain on the relay, so links survive a daemon restart.
My favourite small detail is the dashboard address. Browsers resolve every name under
.localhost to your own machine without any setup, so the dashboard just lives at
http://xposed.localhost. Nothing to register, no port to remember. It also answers only you: requests
that come in through the relay, or from another user account on the same computer, are refused.
$ xposed share --pin --max-downloads 3 ~/Clients/wedding-selects.zip
Public URL: https://k3x9.getxposed.link/s/4kQ9TzA2mXc1
Expires: in 24 hours
PIN: 419027
$ xposed close 4kQ9TzA2mXc1
closed: 4kQ9TzA2mXc1 The honest limits
- Your computer serves the file, so it has to stay on and online while the share is open.
- Anyone with the link (and the PIN, if set) can download. Treat the link like the file.
- The PIN is friction, not a vault: six digits and a short lockout, against casual guessing.
- Files up to 10 GB.
- The relay terminates TLS at its edge. There’s no end-to-end encryption on top.
I’d rather say these plainly than have someone find them out the hard way. xposed is built for the everyday case: sending a client a folder, getting a build onto a phone, handing a friend a video, without making a copy of it on someone else’s server.
13 releases in 7 days
v0.1.0 went out on 27 September as a Linux-only tool for GNOME Files. A week later, v0.8.0 ran on Windows 10 and 11 with a proper installer, on macOS (Intel and Apple Silicon) with a Finder Quick Action, and sign-up was open to everyone instead of invite-only. That was 13 tagged releases in 7 days.
Most of those releases were small, and most of the work in them wasn’t the clever part. Moving the relay client inside the daemon so there’s one binary, updating in place on Windows, installing on macOS without sudo, printing the right URL when port 80 is taken: none of that shows up in a demo, and all of it shows up the first time someone else runs your install script. A product’s real surface area is the install, the first run and the failure messages. That’s also why the project leans on end-to-end checks in Docker (a real relay, a real share, the PIN gate, the download limit) over a large unit-test suite.
One more thing: the film
I made the 20-second launch film too, rendered from code, with real QR codes in every frame. The site is a single page told as one roll of film, with GSAP motion, hand-written WebGL2 and procedural audio. Building the whole thing, from the daemon to the frame the film ends on, is the part of this work I enjoy most.
Try it
curl -fsSL https://getxposed.link/install.sh | sh That works on Linux and macOS; Windows has an installer on getxposed.link. Sign in once with GitHub or Google, then right-click something.