We're currently working on a website to explore collections in the wearables archive, it looks like this:
Wanted to ask / get consent first about exposing a direct link that can download the 3D files for any of the wearables. These files have always been exposed from the NFT metadata, but it was always a couple extra steps to go to the NFT metadata and grab the URL vs just clicking something.
There's already a layer of protection: the attribution information of each wearable is encoded inside every 3D file - not just the NFT. So even if someone gets the file, the same metadata from the NFT is merged with the 3D file. If the file is ever altered, then the hash will be different and thus verifiable as a bootleg copy. For more info about these measures check out this post: https://mirror.xyz/m3org.eth/4NPYOzRtcuYHrRI7iZK1yADswgOv9To2ErQ8KrqLPX0
Question: Are you okay with a download button for the 3D files?
If no, remember that the download links will still be in the NFT metadata, but just not exposed on the frontend.