Commit Graph

689 Commits

Author SHA1 Message Date
Nostalgia 3a31b438a9 refactor(offline): centralize native tool setup (#3096)
- Keep storage-to-tool identity in the offline tool package.
- Share settings persistence, tool initialization, and storage admission across handlers.
- Preserve endpoint payloads and unsupported-storage diagnostics with focused tests.

Co-authored-by: nostalume <nostalucent@gmail.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-09-21 16:54:22 +08:00
Nostalgia 56064d1981 fix(op): enforce link cache lifecycle policy (#3101)
- Share one admitted lifecycle policy between regular and archive links.
- Reject and release links that combine TTL caching with owned resources.
- Keep wrapper clones independent from the source cache expiration.
- Cover reuse, reference, invalidation, conflict, and clone behavior.

Co-authored-by: nostalume <nostalucent@gmail.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-09-21 16:54:12 +08:00
fryeggs d6109a7940 feat(task): persist task timestamps across restarts (#2914)
Co-authored-by: OpenAI Codex <noreply@openai.com>
2026-09-10 19:20:11 +08:00
Pikachu Ren 2d51c9ab4b feat!(init): add initialization wizard (#3041)
feat: add system initialization (setup wizard) support

Co-authored-by: PIKACHUIM <PIKACHUIM@users.noreply.github.com>
2026-09-07 14:14:22 +08:00
MadDogOwner 6247cf7be2 feat(server/s3): support multipart upload (#2813) 2026-09-05 15:56:40 +08:00
ShenLin bba3516693 fix(upload): authorize direct upload destinations
- Resolve and authorize the canonical destination from the request payload
- Reject upload capabilities that cross virtual storage mount boundaries
- Remove the unrelated File-Path middleware authorization check

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
2026-09-01 18:45:39 +08:00
ShenLin f244adf60e fix(meta): enforce case-insensitive access controls
- Add an invalidated metadata snapshot for case-insensitive fallback lookups
- Enforce segment-aware metadata coverage for passwords and download signatures
- Add regression tests while preserving case-sensitive write authorization

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
2026-09-01 18:45:39 +08:00
qbisicwate d220b8b005 fix(drivers/189pc)!: normalize escaped apostrophes in names (#2792)
fix(189pc): normalize escaped apostrophes in names

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-08-29 01:32:57 +08:00
AmPlace c06656958c fix(offline): expose native 115 tools for ED2K downloads (#2920)
* fix(offline): allow ED2K downloads through 115 tools

- Treat 115 Cloud and 115 Open as ED2K-capable tools.
- Keep automatic fallback limited to Thunder tools.
- Add regression coverage for supported and unsupported tools.

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>

* fix(offline): route ED2K to native 115 tools

- Allow ED2K requests initially using SimpleHttp to enter tool routing.
- Prefer the matching 115 tool for 115 Cloud and 115 Open destinations.
- Add regression coverage for native storage tool selection.

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>

* fix(offline): expose native tools for destination storage

- Include the native destination tool in the path-aware tool list.
- Keep existing ready-tool filtering for external destinations.
- Add coverage for native storage to tool mapping.

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>

---------

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-08-29 01:22:29 +08:00
UVJkiNTQ 89077c35a7 feat(setting): add move transfer threads option (#2907) 2026-08-08 19:05:49 +08:00
Ovear 7e9082f90e fix(stream): allow seeking beyond file size per Go convention (#2667)
Remove `offset > size` guard from RangeReadReadAtSeeker.Seek and
DynamicReadAtSeeker.Seek. Go's io.Seeker convention allows seeking
past EOF.

Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-08-07 22:53:49 +08:00
ThetaPilla. cca773f07b feat(fs): add pipelined multipart upload (#2723)
* feat(multipart): add chunk reassembly window

- Reassemble concurrently uploaded chunks into a sequential stream through a ring file, bounding disk usage to slots*chunkSize per session
- Park writers up to a deadline when their slot is busy instead of rejecting instantly, so flow control does not surface as connection errors in browsers
- Record a per-chunk CRC32 table for re-fill verification and keep it readable after close
- Propagate cancellation to blocked readers via CloseWithError so drivers treat aborts like canceled requests
- Cover ordering, backpressure, idempotent resends and close/abort wake-ups with race-enabled tests

* feat(multipart): add pipelined upload session manager

- Start the driver upload at session init over a sequential stream backed by the window, so client-to-server and server-to-storage transfers run concurrently
- Attach client-provided hashes to the stream so drivers can attempt rapid upload before any chunk arrives, and absorb chunks racing pipeline completion idempotently
- Keep only metadata and chunk CRCs after a failed attempt: re-sending chunk 0 re-fills a fresh window, and content changes between attempts are rejected
- Resume receiving sessions only when client hashes prove the same file; failed_retriable sessions resume unconditionally
- Reclaim sessions with a sliding-TTL GC and sweep orphaned ring files at startup
- Cover the state machine with race-enabled tests over a stubbed storage layer

* feat(setting): add multipart upload settings

- Add multipart_enabled and multipart_chunk_size (MB) as public traffic settings
- Validate the chunk size on save (integer within 1-90) via the setting item hook

* feat(server): add multipart upload API

- Add /api/fs/multipart init/chunk/complete/status/abort endpoints with headers aligned with /fs/put
- Gate init behind the FsUp permission checks and reuse the client upload rate limiter for chunk uploads
- Drain the request body before answering chunk requests on every path, so browsers do not see early responses as network errors
- Start the multipart session GC when the router is initialized to reclaim ring files orphaned by a previous run

* refactor(multipart): remove unused overwrite session field

- The overwrite flag was stored on the session but never read: the handler
  performs the pre-check and op.Put owns the overwrite semantics

* feat(setting): allow any positive multipart chunk size

- Validate the setting as a positive integer only; self-hosted admins decide
  the ceiling themselves instead of an arbitrary 90MB cap
- Keep clamping the client-suggested X-Chunk-Size to the admin value: the
  server buffers a window of 8 chunks per session, so an unbounded client
  suggestion would translate directly into server-side disk usage

* refactor(server): simplify multipart chunk size clamp

- Fold the two-step clamp into one branch: the ceiling is already floored,
  so a client suggestion just lowers the size with a 1MB floor
2026-08-06 14:14:35 +08:00
Pikachu Ren 6f80df2827 feat(drivers): add GuangYaPan driver with offline download support (#2882)
* feat(drivers): add GuangYaPan driver with offline download support

* fix(drivers): GuangYaPan driver multipartUploadToOSS
2026-08-04 11:34:56 +08:00
Liangbin Lian 78f2f0b25d chore(deps): remove unimplemented FUSE mount functionality and dependencies (#2854)
FUSE was introduced years ago but never implemented,
let's remove it to reduce dependencies.

Signed-off-by: Liangbin Lian <jjm2473@gmail.com>
2026-07-28 01:50:22 +08:00
ShenLin 84ecda35aa fix(search): apply access filtering before paginating results
* fix: replace strings.HasPrefix with utils.IsSubPath for path validation

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* fix: re-validate shared paths to ensure they remain within the creator's base path

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>

* fix(search): apply access filtering before paginating results

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-07-23 20:15:21 +08:00
ShenLin 8495470e63 fix(search): serialize index updates by parent (#2827)
- Prevent concurrent updates from inserting duplicate index entries
- Preserve parallel indexing across different parent paths
- Add serialization, concurrency, and lock cleanup tests

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-07-23 19:33:25 +08:00
ShenLin 59bd343140 fix(sharing): enforce base path boundaries
* fix: replace strings.HasPrefix with utils.IsSubPath for path validation

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* fix: re-validate shared paths to ensure they remain within the creator's base path

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
2026-07-10 12:24:40 +08:00
风月同天 6eedff851c feat(drivers): add Cloudflare Image Bed support (#2427)
* feat(driver): add Cloudflare Image Bed support

* fix: restore accidentally deleted file and name

* refactor: rename driver to cloudflare_imgbed and fix module structure

- Rename driver identifier and directory to 'cloudflare_imgbed' for consistency.
- Remove invalid 'replace' directive in go.mod.
- Restore accidentally modified/deleted files in public/dist.
- Update driver registration in drivers/all.go.

Co-authored-by: Copilot <copilot@github.com>

* fix: use base.NewRestyClient() and use e.g

Co-authored-by: Copilot <copilot@github.com>

* fix:go fmt

* feat(driver/cloudflare-imgbed): enhance cloudflare_imgbed API integration with improved error handling and pagination

* refactor

* feat(cloudflare_imgbed): implement upload functionality and optimize performance

- Added support for standard multipart form upload with zero-copy streaming.
- Implemented HuggingFace LFS direct upload for large files (>20MB).
- Integrated with OpenList global rate limiter and progress tracking.
- Optimized memory usage using io.MultiReader for request body construction.
- Added configurable upload threads for chunked HF uploads.
- Support auto mkdir dir when in upload

* refactor: simplify path handling logic

* refactor(cloudflare_imgbed): streamline API endpoint constants and improve initialization logic

* refactor(cloudflare_imgbed): clean up upload logic and remove unused functions

* docs: update help descriptions to English in cloudflare_imgbed

* feat(cloudflare_imgbed): add virtual directory support

* refactor(weak_cache): iImprove weak pointer cleanup handling

Store a cleanup handle alongside weak pointers and stop previous cleanups when overwriting entries to avoid stale removals and leaked cleanup handlers.

Ensure Delete signals success and stops associated cleanup. Add Clear to stop all active cleanups. Use entry identity in the cleanup callback to avoid removing newly inserted values.

* fix bug

* Apply suggestions from code review

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>

* Adds uploadFolder param and streams base64 sample

Adds an uploadFolder query parameter to forward the destination path to the backend. Replaces the fixed-size sample read with a streaming base64 encoder to avoid truncation and reduce allocations

Co-authored-by: Copilot <copilot@github.com>

* refactor: add context parameter to doRequest and related calls

* fix: update List method to check args.Refresh before virtual directory mask

* refactor: optimize List method and improve error handling in doRequest

* feat: add public URL support and multi-channel chunked upload

- Support multi-channel chunk size configurations (e.g., Telegram, CFR2, S3, Discord).
- Fix 401 unauthorized error when merging chunks in HuggingFace channel.

---------

Signed-off-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: Copilot <copilot@github.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-06-30 16:26:35 +08:00
yunxuan d403f75da2 fix: prevent panic in unaligned 64-bit atomic (#2637)
* fix(net): prevent panic in unaligned 64-bit atomic on ARMv7

Convert int64 fields written and readingID to atomic.Int64
guarantees 8-byte alignment on 32-bit ARM architectures.

Unaligned 64-bit atomics fault with SIGILL on armv5/armv6
and armv7. Fixes file copy operations.

* fix(atomic): migrate more atomic useage

* fix(alias): improve link handling and add Clone method for Link struct

* fix warn

* fix(mem): simplify memory reservation handling in MemoryGrowCheck

* fix(link): simplify link handling by using Clone method

* fix bug

* fix(hash): typo

Signed-off-by: Yinan Qin <a.elysia@proton.me>

---------

Signed-off-by: Yinan Qin <a.elysia@proton.me>
Co-authored-by: Elysia <a.elysia@proton.me>
Co-authored-by: j2rong4cn <j2rong@qq.com>
2026-06-22 14:37:44 +08:00
ShenLin 3b017c2b5c feat(mcp): add mcp endpoint for whole openlist (#2485)
* feat(mcp): add initial MCP tools support

- 新增 MCP 路由与 session 初始化流程
- 接入 tools/list 与 tools/call,并开放 openlist.fs.list
- 补充 MCP 相关协议与路由测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* refactor(mcp): move MCP implementation into server/mcp

- 将 MCP 实现与测试迁移到 server/mcp 目录
- 保留 server/mcp.go 作为路由接入包装入口
- 对齐 webdav、s3、ftp、sftp 的目录组织风格

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): address endpoint review issues

- 收紧 Streamable HTTP Accept 头校验
- 为 MCP session 增加过期清理和数量上限
- 简化 fs.list 参数解析并修复分页边界
- 使用独立 Server 实例隔离 MCP 测试状态

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* feat(mcp): add fs get and link tools

- 新增 openlist.fs.get 和 openlist.fs.link 工具
- 复用文件详情、代理链接和权限校验逻辑
- 补充工具列表和参数解析测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): improve protocol negotiation and proxy handling

- Remove WebDAV proxy URL policy from MCP proxy link detection
- Return server protocol version during initialize negotiation
- Return JSON-RPC error body for invalid MCP Accept header
- Add tests for MCP proxy and HTTP negotiation behavior

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): set Allow header for GET requests

- 为 MCP GET 405 响应添加 Allow 头
- 补充 GET 405 响应头断言

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* refactor(mcp): use mutex for session store

- 将 MCP session 锁改为 Mutex
- 让锁类型匹配会更新 lastUsedAt 的访问路径

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): negotiate initialize protocol version

- 添加 MCP 协议版本协商函数
- 不支持客户端版本时返回服务端支持版本

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* revert(mcp): drop protocol version negotiation wrapper

- 撤回 MCP 协议版本协商包装函数
- 恢复 initialize 直接返回服务端协议版本

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): limit and reuse sessions

- 将 MCP 全局 session 上限调整为 128
- 添加单用户 16 个 session 上限
- initialize 复用同用户已有 session 标识
- 补充 session 复用和上限裁剪测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): require path for fs list

- 拒绝 openlist.fs.list 的空参数和 null 参数
- 校验 fs.list 缺失 path 时返回 -32602
- 添加 fs.list 参数解析测试覆盖错误文案

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): enforce protocol version header

- 校验非 initialize 请求的 MCP-Protocol-Version 头
- 拒绝缺失或不支持协议版本的后续 POST 请求
- 添加协议版本头缺失和不匹配测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* test(mcp): serialize setting cache mutation

- 为修改全局设置缓存的测试添加包级互斥锁
- 保留 ClearAll 清理逻辑,避免并发测试互相影响

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* feat(mcp): add config switch

- Add MCP config section with disabled default
- Register MCP routes only when enabled

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): handle missing session explicitly

- 区分缺失 MCP session 与未知 MCP session
- 为未知 session 返回 not found 错误
- 添加 MCP session 错误处理测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* feat(mcp): support latest protocol negotiation

- Upgrade default MCP protocol version to 2025-11-25
- Preserve 2025-06-18 compatibility through initialize negotiation
- Validate subsequent request protocol version against the negotiated session version
- Add tests for latest and older protocol negotiation paths

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): relax streamable http compatibility

- 允许缺失协议版本头时使用会话协商版本
- 放宽 Accept 头兼容 JSON、SSE 和通配类型
- 补充 MCP 初始化和协议版本兼容性测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

---------

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-06-19 00:32:00 +08:00
ShenLin ace7482bc2 fix(offline-download): block cloud metadata endpoints (#2487) 2026-06-18 23:16:16 +08:00
ShenLin eadf03a4f8 fix(upload): respect overwrite for direct uploads (#2625)
* fix(upload): respect overwrite for direct uploads

- 将 Direct Upload 的 overwrite 参数传递到后端检查逻辑
- 覆盖上传时允许已存在目标继续生成直传信息
- 非覆盖上传时按完整目标路径返回 file exists

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(upload): validate direct upload target checks

- 校验直传文件名只能是单个路径段
- 在非覆盖直传检查中返回非 object not found 错误
- 在底层直传信息生成前保留真实探测错误

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(upload): preserve direct upload conflict status

- 将非覆盖直传的并发已存在错误返回为 403
- 保持直传存在性检查的前端错误文案不暴露路径

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

---------

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-06-16 14:45:43 +08:00
ShenLin b05a51a062 feat(archive): support livp as zip archive (#2624)
fix(archive): support livp as zip archive

- 将 .livp 注册为 ZIP 压缩包识别格式
- 复用现有 ZIP 解析逻辑支持 LIVP 预览和解压
- 补充 .livp 扩展名注册测试

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-06-16 13:46:17 +08:00
j2rong4cn 054db9f5eb fix(op): use oldName variable for cache updates in Rename function (#2570) 2026-06-03 19:56:55 +08:00
Jealous 9b587ee165 fix(archive): prefer utf-8 for non-EFS zip names (#2557) 2026-06-01 01:50:47 +08:00
j2rong4cn 9282e8ef09 fix(cache,mem): replace finalizers with runtime.AddCleanup (#2535) 2026-06-01 01:50:20 +08:00
Suyunjing 9cc5dd969b fix(offline_download): block SimpleHttp temp file path traversal via strict filename sanitization
* fix(offline_download): prevent path traversal

* fix(SimpleHttp): improve filename validation

* fix(offline_download): harden SimpleHttp filename and temp path checks

* simplify filename validation

---------

Co-authored-by: ILoveScratch2 <ilovescratch@foxmail.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
2026-05-27 17:18:31 +08:00
Suyunjing 3b1760e959 fix(offline_download): restore SimpleHttp fallback for http links (#2516)
- Fixed a regression where SimpleHttp returned the same unsupported scheme error for normal HTTP and HTTPS links.
2026-05-26 13:11:21 +08:00
Pikachu Ren 1d071c0fd8 feat(func): support ed2k & magnet & torrent offline download (#2452)
Add end-to-end offline download support for torrent files, magnet links, and ed2k links, including torrent parse and generate APIs, CAS-based rapid upload for Cloud189, and protocol-aware tool routing with transfer flow improvements.

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: Suyunjing <suyunmeng@oplist.org.cn>
2026-05-25 14:34:21 +08:00
j2rong4cn 9eae62581a refactor(cache)!: extract hybrid_cache package (#2477)
* refactor(HybridCache)!: extract hybrid_cache package and rename cache_threshold to auto_memory_limit

* split HybridCache and stores into internal/hybrid_cache package
* introduce BackingStore abstraction with BufferStore and FileStore
* rename CacheThreshold to AutoMemoryLimit in config/env/bootstrap
* update stream/request integration and related tests

* rename singleFileCache and MultiFileCache to singleFileStore and MultiFileStore

* refactor(HybridCache): improve memory management strategies in NewHybridCache

* rename

* alias hybrid_cache to hcache

* omments
2026-05-18 15:11:39 +08:00
j2rong4cn ea19bed247 fix(setting): handle delete of setting item with empty key (#2131) 2026-05-14 23:23:44 +08:00
j2rong4cn b6db83ed5e refactor: unify stream caching via HybridCache (#2460)
* add LinearMemory

* replace mmap with LinearMemory

* remove unused code

* add GuardedMemory; add `min_free_memoryMB` conf

* add HybridCache and StreamBuffer

* log

* rename SizedReadWriterAt to Section

* 重构 FileStream,改用 HybridCache

* 重构 HybridCache,更新方法名并添加回滚功能;优化请求和流处理逻辑

* 重构 StreamSectionReader 接口,使用HybridCache

* 在 NewGuardedMemory 函数中添加了对 LinearMemory 的最终化处理,以确保内存释放

* .

* 优化检查逻辑

* 重命名

* 改进、重命名

* 修复

* 添加测试

* 移除HybridCacheReader并引入DynamicReadAtSeeker

* 重构缓存读取逻辑,简化代码并引入ReadFromN方法

* 优化缓存配置注释并修复下载器部分大小限制逻辑

* 优化中断逻辑

* 优化下载器代码

* 修复bug

* HybridCache添加多文件缓存模式

* 优化下载器并发,添加测试

* 修复bug

* 重命名+注释

* .

* fix(net): always cleanup downloader on interrupt

* fix(net): guard chunk enqueue with context cancel

* fix(net): update interrupt logic and add download interrupt test

* fix(test): update concurrency limit in high concurrency test

* refactor(buffer): simplify ReadAt logic

* refactor(config): update memory configuration logic

* .

---------

Co-authored-by: Suyunmeng <Susus0175@proton.me>
2026-05-14 22:14:54 +08:00
j2rong4cn d3a6b06566 perf: replace strings.Split with strings.SplitSeq (#2441) 2026-05-04 13:05:07 +08:00
mkitsdts e87e028a49 fix(internal/fs): add ObjectAlreadyExists error check (#2019)
* fix(webdav/drivers):add errors check

* chore(pkg/error):add errs.IsObjectAlreadyExists function

* chore(pkg/error):rollback error change

* chore(op/makedir):add IsObjectAlreadyExists check

* fix(driver/quark_uc):add makedir response checking

* fix(op/put):add makedir error checking

* chore(op/put):fix logic error

* fix(driver/uc):fix error resp check

* chore(op/makedir):add parentPath check

* fix(op/makedir):fix some errors

* fix(op/makedir):fix logic error

* fix(drivers/cloudreve_v4): add object existence error

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
2026-05-03 19:10:31 +08:00
Miao Zhao 7e37c40516 feat(sharing): allow custom share IDs (#2353)
feat: allow custom share IDs

   - Change sharing ID column from char(12) to varchar(64)
   - Add new_id field to UpdateSharingReq for renaming share IDs
   - Add ID validation (max 64 chars, alphanumeric/CJK/hyphens/underscores)
   - Add conflict check when updating share ID
   - Add customize_share_id permission (bit 15)

   Closes OpenListTeam/OpenList#1806
2026-05-03 11:06:28 +08:00
MadDogOwner a5ba6a0e9d refactor(settings)!: move FilterReadMeScripts to frontend (#2346)
* refactor(settings)!: move FilterReadMeScripts to frontend

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* chore: run go mod tidy

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
2026-04-20 18:05:15 +08:00
Jealous da26e72bee fix(op): invalidate new path cache on meta path update (#2322) 2026-04-09 09:32:18 +08:00
sdvcrx 12c9bdbd56 fix(offline_download): prevent infinite retry on status update failure (#2294) 2026-04-03 15:47:40 +08:00
Suyunjing 7bea29c18e refactor(db): migrate sqlite to pure-go and add mips compatibility switch (#2296)
- Switch default SQLite path to github.com/glebarez/sqlite to reduce CGO dependency pressure.
- Introduce a unified openSQLite entry in bootstrap and split driver selection by build tags.
- Add sqlite_cgo_compat fallback for linux mips, mips64, loong64 and mipsle to keep legacy target builds working.
- Update build.sh musl build flow to apply compatibility tag for mips-family targets.
- Update beta_release workflow to pass compatibility tag cleanly and avoid conflicting flag composition.
2026-04-03 01:27:02 +08:00
ShenLin 29447a41a3 revert(db)!: replace SQLite Driver with glebarez/sqlite to avoid CGO (#2269)
Revert "refactor(db)!: replace SQLite Driver with glebarez/sqlite to avoid CG…"

This reverts commit d598ef7569.
2026-03-26 21:01:48 +08:00
Jealous d85f084acb feat(permissions): implement fine-grained permission control (#2145)
* refactor(permission): rename permission check functions for clarity

- User.CanWrite() → User.CanCreateFilesOrFolders()
- common.CanWrite() → common.CanWriteContentBypassUserPerms()
- common.IsApply() → common.MetaCoversPath()

Improves code readability by making function names more descriptive.
The new MetaCoversPath name clearly indicates it checks if a meta rule
covers a specific path. It better conveys that it's a query function
rather than an action, and the applyToSubFolder parameter is more
explicit than applySub.

Also adds comprehensive test coverage:
- 10 tests for MetaCoversPath core logic
- 6 tests for CanWriteContent
UserPerms
- 7 tests for getReadme
- 5 tests for getHeader
- 6 tests for isEncrypt
- 9 tests for whetherHide

Total: 43 test scenarios covering all path matching and permission
inheritance logic. Tests verify both normal behavior and bug fixes
for Readme/Header information leakage and write permission bypass.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>

* feat(permission): implement fine-grained user permissions for read/write operations

Add per-user read and write permission controls at the meta level to enable
more granular access control beyond the existing permission flags.

Key changes:
- Add ReadUsers/WriteUsers fields to Meta model with sub-directory inheritance flags
- Implement CanRead and CanWrite permission check functions in server/common
- Filter file list results based on user read permissions
- Add permission checks across all file operations (FTP, HTTP handlers, WebDAV)
- Simplify error handling pattern for MetaNotFound errors throughout codebase

This allows administrators to restrict specific users from accessing or modifying
certain paths, providing finer control over file system permissions.

Note: Batch and recursive operations (FsMove, FsCopy, FsRemove, FsRecursiveMove,
FsBatchRename, FsRegexRename) currently check parent directory permissions only.
Individual item permission checks are not performed for performance reasons.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>

* test(permission): add comprehensive tests for CanRead, CanWrite, and combined permission checks

Add TestCanRead, TestCanWrite, TestCanAccessWithReadPermissions, and
TestWritePermissionCombinations to validate the three-layer permission
system including nil user/meta, sub-path inheritance, user whitelists,
and root-level restrictions.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(webdav): use safe type assertion for MetaPassKey to prevent panic

Bearer-token and OPTIONS auth paths do not set MetaPassKey in context,
causing a panic when handlers perform a forced type assertion on nil.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(permission): treat nil user as system context in CanRead/CanWrite

Previously, CanRead/CanWrite returned false for nil user, causing
filterReadableObjs to return an empty list when fs.List is called from
internal contexts without a user (e.g. context.Background()). A nil user
represents an internal/system call and should bypass per-user restrictions,
consistent with how whetherHide already handles nil user.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(fsmanage): prevent path traversal in FsRemove

The previous check only skipped names that resolved to "/", but did not
prevent traversal to sibling directories (e.g. "../secret"), which could
bypass the CanWrite permission check that is only applied to req.Dir.

Replace with a post-join prefix check to ensure each resolved path stays
within reqPath.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(webdav): align MetaPassKey behavior with FTP auth logic

For guest users, the WebDAV password input serves as the meta folder
password (consistent with FTP anonymous/guest handling). For authenticated
users, MetaPassKey is set to empty string since their login password is
not the meta folder password.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(permission): require write auth for fs list refresh

* refactor(permission): use MetaCoversPath in CanRead/CanWrite for consistency

Replace inline `(Sub || meta.Path == path)` logic with MetaCoversPath,
consistent with CanWriteContentBypassUserPerms. Also fix a copy-paste
error in the CanWrite comment (read → write).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-03-26 14:42:35 +08:00
Pikachu Ren d598ef7569 refactor(db)!: replace SQLite Driver with glebarez/sqlite to avoid CGO (#2211)
* mod(db): driver/sqlite ->glebarez/sqlite

* mod(db): driver/sqlite ->glebarez/sqlite

* [WIP] Refactor SQLite Driver with glebarez/sqlite to avoid CGO (#2213)

* Initial plan

* fix: address review comments - fix import order, update test, remove CGO sqlite deps

Co-authored-by: PIKACHUIM <40362270+PIKACHUIM@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: PIKACHUIM <40362270+PIKACHUIM@users.noreply.github.com>

---------

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
2026-03-25 17:45:37 +08:00
Copilot f3428e65bc fix(net): honor proxy settings when uploading to 115/115 Open/PikPak OSS (#2222)
* Initial plan

* fix: honor HTTPS proxy for OSS uploads

Co-authored-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* Honor HTTPS proxy settings for 115/115 Open/PikPak OSS uploads

Co-authored-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* revert

* chore

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: jyxjjj <773933146@qq.com>
2026-03-16 22:15:00 +08:00
MadDogOwner 82ae2d5890 chore(handles/auth): improve error response (#2148)
* chore(handles/auth): improve error response

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* Apply suggestion from @xrgzs

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
2026-02-19 17:15:40 +08:00
ShenLin e3c664f81d Merge commit from fork
Co-authored-by: KirCute <951206789@qq.com>
2026-01-31 16:52:20 +08:00
mkitsdts d8417e050c fix(webdav/move): fix source file still exist after moving file by webdav (#1979) 2026-01-21 17:27:19 +08:00
Tron a79d8347bd fix(fs): handle non-existent destination directory in file transfer (#1898)
* fix(FileTransferTask): skip copying if destination directory does not exist

* pass only object not found error

---------

Co-authored-by: cyk <dr_arc@163.com>
Co-authored-by: KirCute <951206789@qq.com>
2026-01-17 20:12:31 +08:00
KirCute 85c69d853f fix(fs): panic when failed to get storage details (#1964) 2026-01-13 22:01:35 +08:00
MadDogOwner c6bd437242 feat(drivers/webdav): add support for 302 redirects (#1952)
* Remove the `OnlyProxy` restriction and obtain the redirected link to support 302

* Add `driver.Config` `PreferProxy` to recommend user to enable the proxy by default

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
2026-01-11 15:15:42 +08:00
KirCute 744dbd5e26 feat(drivers): support getting disk usage of some drivers (#1905)
* feat(drivers): support getting disk usage of some drivers

* feat(drivers/degoo): implement GetDetails

* fix(fs/storage-details): fill used space rather than free space

* fix mega

* fix bsize type
2026-01-08 10:47:22 +08:00