Architecture
Cloud Recording Exporter is a multi-tenant, server-side OAuth and webhook integration. Zoom and Google OAuth credentials remain on the server. Internal recording operations require a separate server-side API key and are not exposed through the public website interface.
OAuth protection
- Zoom and Google authorization use random, short-lived, single-use state bound to the initiating Nimbus user.
- Google authorization additionally uses PKCE, and authorization codes are exchanged server-side.
- Access tokens are refreshed before expiry and rotated refresh tokens replace older values.
- Raw tokens are not returned in browser callbacks or application logs.
Encryption and secrets
Zoom and Google token sets are encrypted at rest using AES-256-GCM with a deployment-specific key. Private runtime files use owner-only 0600 permissions and are stored outside the public web root. Client secrets, webhook secrets, OAuth tokens, destination credentials, and internal API keys must not be committed to source control.
Webhook verification
Cloud Recording Exporter calculates the Zoom HMAC over the raw request body, verifies x-zm-signature using timing-safe comparison, and rejects timestamps outside a short replay window. URL validation is answered with the required HMAC proof. Accepted events are deduplicated and logged without recording download URLs.
Recording data
The workflow requests only the recording and transcript information required for the configured export. Recording content is intended for transfer to the user-selected destination rather than retention as a separate Nimbus Whale archive. Operational logs contain limited metadata such as event time, meeting identifier, file type, file size, and processing status.
Deletion safeguards
Export does not trigger deletion by default. Supported deletion requests prefer Zoom trash. Permanent recording deletion requires additional confirmation, and destination verification should complete before any source deletion is accepted.
Deauthorization
Zoom deauthorization notifications must carry a valid signature and recent timestamp. A verified app_deauthorized notification deletes the associated Zoom token record and prevents future Zoom API access. Disconnecting Google Drive revokes the Google grant and removes its encrypted local token and folder configuration. Files already exported remain in the user-controlled destination.
Tenant isolation
Users, workspaces, provider installations, storage destinations, transfer jobs, webhook idempotency records, and audit events are stored in PostgreSQL and scoped to their owning user or workspace. OAuth callback state is atomically consumed and linked to the Nimbus user who initiated it, so provider account email addresses do not need to match the Nimbus account email.
Report a security issue
Email [email protected]. Do not include credentials, tokens, recording data, or exploit details in the first email.