Shop Update: Contact Sellers & Secure Digital Downloads
September 10, 2026
Today we’re shipping two major shop features that have been highly requested by our community: a way for buyers to ask sellers questions before purchasing, and secure digital file delivery for downloadable products.
Contact Seller — Ask Before You Buy
Ever wanted to ask a shop owner a question about a product before making a purchase? Now you can.
Every product card in the shop now has a “Contact Seller” button. Click it, type your question (up to 1024 characters), and send. The shop owner receives an instant real-time notification via Server-Sent Events (SSE) — no page refresh needed. They can reply directly from their Shop Owner Dashboard, and you’ll get a notification when they do.
How it works
- Buyer clicks “Contact Seller” on any product
- Types a question (max 1024 characters)
- Seller gets an instant SSE toast notification with a preview of the message
- Seller opens the Inquiries section in their dashboard and replies
- Buyer receives an SSE notification that the seller replied
Rate limiting
To prevent spam, each buyer can have at most 5 open inquiries per product per 24 hours. This keeps the system manageable for sellers while giving buyers plenty of room to ask follow-up questions.
Available in 23 languages
All UI text for the contact feature is translated into all 23 supported languages: Arabic, Bengali, German, English, Spanish, Farsi, French, Hindi, Indonesian, Italian, Japanese, Korean, Polish, Portuguese, Russian, Swahili, Thai, Tagalog, Turkish, Urdu, Vietnamese, Chinese (Simplified), and Chinese (Traditional).
Secure Digital Downloads — Virus-Scanned File Delivery
Shop owners can now upload downloadable files (PDFs, images, audio, video, EPUBs) to their digital products. After a buyer pays, the files appear in their “My Downloads” section in the shop.
Multi-layer security (defense in depth)
Security was our top priority when building this feature. We implemented nine layers of protection to ensure no malware can reach our players:
| # | Layer | What it does |
|---|---|---|
| 1 | File type allowlist | Only safe document/media types are accepted: PDF, PNG, JPG, GIF, WebP, TXT, Markdown, MP3, MP4, WebM, OGG, EPUB. No executables, scripts, or archives that can contain scripts. |
| 2 | Magic-byte validation | The file’s actual content must match its extension. A file named photo.png must actually start with PNG magic bytes. Renaming malware.exe to malware.pdf won’t work. |
| 3 | 50 MB size limit | Hard cap on upload size prevents denial-of-service via large files. |
| 4 | ClamAV virus scanning | Every file is scanned by ClamAV (running as a Docker sidecar) using the INSTREAM protocol. If ClamAV detects a threat, the upload is rejected. If ClamAV is unreachable in production, uploads are also rejected — we never store unscanned files. |
| 5 | SHA-256 hashing | Every stored file is hashed and the hash is recorded in the database. This provides integrity verification and auditability. |
| 6 | Double-extension blocking | Files like document.pdf.exe are rejected. Only single extensions are allowed. |
| 7 | No direct web access | Download files are stored outside the web root. There is no nginx path that serves them directly. The only way to access a file is through the authenticated download handler. |
| 8 | Authenticated download handler | The download endpoint verifies that the requesting user owns the order, the order is paid, and the download file belongs to a product in that order. No order, no access. |
| 9 | Download counting | Each file can be downloaded a maximum of 10 times per order. This prevents abuse if a download link is somehow leaked. |
How it works for shop owners
- Mark your product as “digital” when creating or editing it
- Click the new “Downloads” button on the product
- Upload a file (max 50 MB, allowed types only)
- The file is automatically scanned by ClamAV
- You’ll see a green “scanned” badge when the file passes the scan
- The SHA-256 hash is displayed for verification
How it works for buyers
- Purchase a digital product and complete payment
- The “My Downloads” section appears in your shop sidebar
- Click Download — the file is served as a secure blob download
- Your download counter shows how many downloads remain (10 per file)
What about the existing fragment/CTTC delivery?
The existing automatic delivery of Fragment Pieces and CTTC Pieces continues to work exactly as before. The new download system is an additional delivery mechanism for any other digital files a shop owner wants to attach to their products.
Technical details
- Backend: Go game-service with PostgreSQL. New database tables handle buyer-seller messages and file metadata/access grants.
- ClamAV: Runs as a Docker sidecar container alongside the game-service. Communication via TCP using the INSTREAM protocol.
- SSE: Real-time notifications use the existing Server-Sent Events infrastructure. New events notify the seller on incoming inquiries and the buyer on replies.
- Frontend: Vanilla JavaScript with i18n. 28 new translation keys across 25 language files.
- Storage: Download files are stored outside the web root, accessible only through the authenticated API.
What’s next?
These features are currently rolling out to our MAAS staging server for testing. Once validated, they’ll be deployed to all production regions.
If you’re a shop owner, start thinking about what digital products you’d like to sell — whether it’s PDFs, artwork, music, or videos, the shop now supports secure delivery with enterprise-grade malware protection.
Have feedback? Use the new Contact Seller feature to reach out to our team shop!