The server generates and returns an arbitrary token, which is typically a hash or A few other fingerprint with the contents on the file. The browser isn't going to really need to know the way the fingerprint is generated; it only needs to send out it on the server on https://epictetusm541pbn4.blogvivi.com/profile