Commit Graph

616 Commits

Author SHA1 Message Date
awaae 40f4f6546f fix(ftp): handle EOF and detect content type from read bytes (#3125) 2026-09-24 01:20:20 +08:00
Nostalgia 3a31b438a9 refactor(offline): centralize native tool setup (#3096)
- Keep storage-to-tool identity in the offline tool package.
- Share settings persistence, tool initialization, and storage admission across handlers.
- Preserve endpoint payloads and unsupported-storage diagnostics with focused tests.

Co-authored-by: nostalume <nostalucent@gmail.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-09-21 16:54:22 +08:00
Nostalgia 5447ecb072 fix(s3): encode multipart fixture paths (#3074)
test(s3): encode multipart fixture paths

- Serialize the Local storage addition instead of interpolating filesystem paths into JSON.
- Keep multipart fixture behavior portable across Windows and Linux.

Co-authored-by: nostalume <nostalucent@gmail.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-09-14 20:30:17 +08:00
Pikachu Ren 2d51c9ab4b feat!(init): add initialization wizard (#3041)
feat: add system initialization (setup wizard) support

Co-authored-by: PIKACHUIM <PIKACHUIM@users.noreply.github.com>
2026-09-07 14:14:22 +08:00
ShenLin d9d8aa24e6 fix(s3): default upload content types and return partial content (#3053)
- Default missing upload MIME types to application/octet-stream before passing streams to storage drivers.
- Return HTTP 206 for successful ranged GET responses while preserving error statuses.
- Add isolated response-status regression tests without database initialization.

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-09-07 12:01:15 +08:00
MadDogOwner 6247cf7be2 feat(server/s3): support multipart upload (#2813) 2026-09-05 15:56:40 +08:00
ShenLin 523af855ba fix(auth): secure SSO account binding
- Issue and verify short-lived SSO binding state and proof tokens
- Bind provider callbacks to an HttpOnly browser session cookie
- Reject invalid or already-associated SSO identities during profile updates

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
2026-09-01 18:45:40 +08:00
ShenLin bba3516693 fix(upload): authorize direct upload destinations
- Resolve and authorize the canonical destination from the request payload
- Reject upload capabilities that cross virtual storage mount boundaries
- Remove the unrelated File-Path middleware authorization check

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
2026-09-01 18:45:39 +08:00
ShenLin f244adf60e fix(meta): enforce case-insensitive access controls
- Add an invalidated metadata snapshot for case-insensitive fallback lookups
- Enforce segment-aware metadata coverage for passwords and download signatures
- Add regression tests while preserving case-sensitive write authorization

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
2026-09-01 18:45:39 +08:00
AmPlace c06656958c fix(offline): expose native 115 tools for ED2K downloads (#2920)
* fix(offline): allow ED2K downloads through 115 tools

- Treat 115 Cloud and 115 Open as ED2K-capable tools.
- Keep automatic fallback limited to Thunder tools.
- Add regression coverage for supported and unsupported tools.

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>

* fix(offline): route ED2K to native 115 tools

- Allow ED2K requests initially using SimpleHttp to enter tool routing.
- Prefer the matching 115 tool for 115 Cloud and 115 Open destinations.
- Add regression coverage for native storage tool selection.

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>

* fix(offline): expose native tools for destination storage

- Include the native destination tool in the path-aware tool list.
- Keep existing ready-tool filtering for external destinations.
- Add coverage for native storage to tool mapping.

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>

---------

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-08-29 01:22:29 +08:00
Nostalgia e0e4de5e82 fix(server/s3): paginate recursive object listings (#2968)
fix(s3): paginate recursive object listings

- stop recursive traversal after filling the requested S3 page
- preserve lexicographic marker ordering and request cancellation
- cover bounded traversal, continuation, prefixes, and cache safety

Co-authored-by: nostalume <nostalucent@gmail.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-08-29 01:18:42 +08:00
ThetaPilla. cca773f07b feat(fs): add pipelined multipart upload (#2723)
* feat(multipart): add chunk reassembly window

- Reassemble concurrently uploaded chunks into a sequential stream through a ring file, bounding disk usage to slots*chunkSize per session
- Park writers up to a deadline when their slot is busy instead of rejecting instantly, so flow control does not surface as connection errors in browsers
- Record a per-chunk CRC32 table for re-fill verification and keep it readable after close
- Propagate cancellation to blocked readers via CloseWithError so drivers treat aborts like canceled requests
- Cover ordering, backpressure, idempotent resends and close/abort wake-ups with race-enabled tests

* feat(multipart): add pipelined upload session manager

- Start the driver upload at session init over a sequential stream backed by the window, so client-to-server and server-to-storage transfers run concurrently
- Attach client-provided hashes to the stream so drivers can attempt rapid upload before any chunk arrives, and absorb chunks racing pipeline completion idempotently
- Keep only metadata and chunk CRCs after a failed attempt: re-sending chunk 0 re-fills a fresh window, and content changes between attempts are rejected
- Resume receiving sessions only when client hashes prove the same file; failed_retriable sessions resume unconditionally
- Reclaim sessions with a sliding-TTL GC and sweep orphaned ring files at startup
- Cover the state machine with race-enabled tests over a stubbed storage layer

* feat(setting): add multipart upload settings

- Add multipart_enabled and multipart_chunk_size (MB) as public traffic settings
- Validate the chunk size on save (integer within 1-90) via the setting item hook

* feat(server): add multipart upload API

- Add /api/fs/multipart init/chunk/complete/status/abort endpoints with headers aligned with /fs/put
- Gate init behind the FsUp permission checks and reuse the client upload rate limiter for chunk uploads
- Drain the request body before answering chunk requests on every path, so browsers do not see early responses as network errors
- Start the multipart session GC when the router is initialized to reclaim ring files orphaned by a previous run

* refactor(multipart): remove unused overwrite session field

- The overwrite flag was stored on the session but never read: the handler
  performs the pre-check and op.Put owns the overwrite semantics

* feat(setting): allow any positive multipart chunk size

- Validate the setting as a positive integer only; self-hosted admins decide
  the ceiling themselves instead of an arbitrary 90MB cap
- Keep clamping the client-suggested X-Chunk-Size to the admin value: the
  server buffers a window of 8 chunks per session, so an unbounded client
  suggestion would translate directly into server-side disk usage

* refactor(server): simplify multipart chunk size clamp

- Fold the two-step clamp into one branch: the ceiling is already floored,
  so a client suggestion just lowers the size with a 1MB floor
2026-08-06 14:14:35 +08:00
Pikachu Ren 6f80df2827 feat(drivers): add GuangYaPan driver with offline download support (#2882)
* feat(drivers): add GuangYaPan driver with offline download support

* fix(drivers): GuangYaPan driver multipartUploadToOSS
2026-08-04 11:34:56 +08:00
ILoveScratch cf931d4760 chore: fix typos (#2859) 2026-07-28 13:18:34 +08:00
ShenLin 84ecda35aa fix(search): apply access filtering before paginating results
* fix: replace strings.HasPrefix with utils.IsSubPath for path validation

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* fix: re-validate shared paths to ensure they remain within the creator's base path

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>

* fix(search): apply access filtering before paginating results

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-07-23 20:15:21 +08:00
ShenLin 28cea1fb2b fix(proxy): preserve proxied download filenames (#2824)
- Override transparent proxy Content-Disposition with the OpenList object name
- Add regression coverage for incorrect upstream download headers

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-07-23 16:10:45 +08:00
ShenLin 651da18da4 fix(handles): add src_name validation in FsBatchRename
- Validate source names with checkRelativePath before batch renames
- Reject invalid source paths with a forbidden response

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
2026-07-15 16:11:57 +08:00
ShenLin 59bd343140 fix(sharing): enforce base path boundaries
* fix: replace strings.HasPrefix with utils.IsSubPath for path validation

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* fix: re-validate shared paths to ensure they remain within the creator's base path

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
2026-07-10 12:24:40 +08:00
yunxuan d403f75da2 fix: prevent panic in unaligned 64-bit atomic (#2637)
* fix(net): prevent panic in unaligned 64-bit atomic on ARMv7

Convert int64 fields written and readingID to atomic.Int64
guarantees 8-byte alignment on 32-bit ARM architectures.

Unaligned 64-bit atomics fault with SIGILL on armv5/armv6
and armv7. Fixes file copy operations.

* fix(atomic): migrate more atomic useage

* fix(alias): improve link handling and add Clone method for Link struct

* fix warn

* fix(mem): simplify memory reservation handling in MemoryGrowCheck

* fix(link): simplify link handling by using Clone method

* fix bug

* fix(hash): typo

Signed-off-by: Yinan Qin <a.elysia@proton.me>

---------

Signed-off-by: Yinan Qin <a.elysia@proton.me>
Co-authored-by: Elysia <a.elysia@proton.me>
Co-authored-by: j2rong4cn <j2rong@qq.com>
2026-06-22 14:37:44 +08:00
ShenLin 3b017c2b5c feat(mcp): add mcp endpoint for whole openlist (#2485)
* feat(mcp): add initial MCP tools support

- 新增 MCP 路由与 session 初始化流程
- 接入 tools/list 与 tools/call,并开放 openlist.fs.list
- 补充 MCP 相关协议与路由测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* refactor(mcp): move MCP implementation into server/mcp

- 将 MCP 实现与测试迁移到 server/mcp 目录
- 保留 server/mcp.go 作为路由接入包装入口
- 对齐 webdav、s3、ftp、sftp 的目录组织风格

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): address endpoint review issues

- 收紧 Streamable HTTP Accept 头校验
- 为 MCP session 增加过期清理和数量上限
- 简化 fs.list 参数解析并修复分页边界
- 使用独立 Server 实例隔离 MCP 测试状态

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* feat(mcp): add fs get and link tools

- 新增 openlist.fs.get 和 openlist.fs.link 工具
- 复用文件详情、代理链接和权限校验逻辑
- 补充工具列表和参数解析测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): improve protocol negotiation and proxy handling

- Remove WebDAV proxy URL policy from MCP proxy link detection
- Return server protocol version during initialize negotiation
- Return JSON-RPC error body for invalid MCP Accept header
- Add tests for MCP proxy and HTTP negotiation behavior

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): set Allow header for GET requests

- 为 MCP GET 405 响应添加 Allow 头
- 补充 GET 405 响应头断言

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* refactor(mcp): use mutex for session store

- 将 MCP session 锁改为 Mutex
- 让锁类型匹配会更新 lastUsedAt 的访问路径

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): negotiate initialize protocol version

- 添加 MCP 协议版本协商函数
- 不支持客户端版本时返回服务端支持版本

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* revert(mcp): drop protocol version negotiation wrapper

- 撤回 MCP 协议版本协商包装函数
- 恢复 initialize 直接返回服务端协议版本

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): limit and reuse sessions

- 将 MCP 全局 session 上限调整为 128
- 添加单用户 16 个 session 上限
- initialize 复用同用户已有 session 标识
- 补充 session 复用和上限裁剪测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): require path for fs list

- 拒绝 openlist.fs.list 的空参数和 null 参数
- 校验 fs.list 缺失 path 时返回 -32602
- 添加 fs.list 参数解析测试覆盖错误文案

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): enforce protocol version header

- 校验非 initialize 请求的 MCP-Protocol-Version 头
- 拒绝缺失或不支持协议版本的后续 POST 请求
- 添加协议版本头缺失和不匹配测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* test(mcp): serialize setting cache mutation

- 为修改全局设置缓存的测试添加包级互斥锁
- 保留 ClearAll 清理逻辑,避免并发测试互相影响

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* feat(mcp): add config switch

- Add MCP config section with disabled default
- Register MCP routes only when enabled

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): handle missing session explicitly

- 区分缺失 MCP session 与未知 MCP session
- 为未知 session 返回 not found 错误
- 添加 MCP session 错误处理测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* feat(mcp): support latest protocol negotiation

- Upgrade default MCP protocol version to 2025-11-25
- Preserve 2025-06-18 compatibility through initialize negotiation
- Validate subsequent request protocol version against the negotiated session version
- Add tests for latest and older protocol negotiation paths

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(mcp): relax streamable http compatibility

- 允许缺失协议版本头时使用会话协商版本
- 放宽 Accept 头兼容 JSON、SSE 和通配类型
- 补充 MCP 初始化和协议版本兼容性测试

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

---------

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-06-19 00:32:00 +08:00
EzraRT dcfefce85d fix(webauthn): enable discoverable keys (#2451)
Set `WithResidentKeyRequirement` option during registration to enable discoverable keys.
Existing keys do not require migration. They won't appear without entering username, but work normally after username input, legacy flows remain unaffected.
2026-06-19 00:04:25 +08:00
ShenLin eadf03a4f8 fix(upload): respect overwrite for direct uploads (#2625)
* fix(upload): respect overwrite for direct uploads

- 将 Direct Upload 的 overwrite 参数传递到后端检查逻辑
- 覆盖上传时允许已存在目标继续生成直传信息
- 非覆盖上传时按完整目标路径返回 file exists

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(upload): validate direct upload target checks

- 校验直传文件名只能是单个路径段
- 在非覆盖直传检查中返回非 object not found 错误
- 在底层直传信息生成前保留真实探测错误

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

* fix(upload): preserve direct upload conflict status

- 将非覆盖直传的并发已存在错误返回为 403
- 保持直传存在性检查的前端错误文案不暴露路径

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>

---------

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-06-16 14:45:43 +08:00
ShenLin 7e55f11e4a fix(index/meilisearch): refresh progress after update (#2628)
fix(index): refresh progress after update

- 手动更新索引完成后刷新索引进度状态
- 保留现有对象计数避免引入计数差值风险
- 记录更新失败时的错误信息

Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
2026-06-16 13:43:43 +08:00
So d7c332ca13 fix(s3): only skip direct redirect for true sub-resource queries (#2604) 2026-06-12 17:46:51 +08:00
So 88d256de73 feat(s3): support direct transfer redirects (#2598)
Redirect S3 GET object requests to direct links when the underlying storage can provide one and proxying is not required.

Redirect eligible S3 PUT object requests to HttpDirect single PUT upload URLs with 307, while falling back to the existing gofakes3 stream path for unsupported uploads.

Allow OneDrive Sharelink direct upload info to use simple content PUT URLs for files within Microsoft's single-upload limit.

Co-authored-by: syscc <syscc@users.noreply.github.com>
Co-authored-by: Codex <codex@openai.com>
2026-06-12 08:59:34 +08:00
Suyunjing 4c77b9c7bf fix(fs): clear skipped names before copy and move tasks (#2520) 2026-05-27 13:26:16 +08:00
Pikachu Ren 1d071c0fd8 feat(func): support ed2k & magnet & torrent offline download (#2452)
Add end-to-end offline download support for torrent files, magnet links, and ed2k links, including torrent parse and generate APIs, CAS-based rapid upload for Cloud189, and protocol-aware tool routing with transfer flow improvements.

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: Suyunjing <suyunmeng@oplist.org.cn>
2026-05-25 14:34:21 +08:00
j2rong4cn 219564b56c refactor(func): replace GinWithValue with GinAppendValues (#2475) 2026-05-15 17:59:53 +08:00
j2rong4cn c7c0cfaeb7 fix(fsmanage): improve path validation (#2437)
* fix(fsmanage): improve path validation in FsMove, FsCopy, and FsRemove functions
2026-05-06 11:58:00 +08:00
j2rong4cn d3a6b06566 perf: replace strings.Split with strings.SplitSeq (#2441) 2026-05-04 13:05:07 +08:00
Miao Zhao 7e37c40516 feat(sharing): allow custom share IDs (#2353)
feat: allow custom share IDs

   - Change sharing ID column from char(12) to varchar(64)
   - Add new_id field to UpdateSharingReq for renaming share IDs
   - Add ID validation (max 64 chars, alphanumeric/CJK/hyphens/underscores)
   - Add conflict check when updating share ID
   - Add customize_share_id permission (bit 15)

   Closes OpenListTeam/OpenList#1806
2026-05-03 11:06:28 +08:00
MadDogOwner a5ba6a0e9d refactor(settings)!: move FilterReadMeScripts to frontend (#2346)
* refactor(settings)!: move FilterReadMeScripts to frontend

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* chore: run go mod tidy

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
2026-04-20 18:05:15 +08:00
Jealous d85f084acb feat(permissions): implement fine-grained permission control (#2145)
* refactor(permission): rename permission check functions for clarity

- User.CanWrite() → User.CanCreateFilesOrFolders()
- common.CanWrite() → common.CanWriteContentBypassUserPerms()
- common.IsApply() → common.MetaCoversPath()

Improves code readability by making function names more descriptive.
The new MetaCoversPath name clearly indicates it checks if a meta rule
covers a specific path. It better conveys that it's a query function
rather than an action, and the applyToSubFolder parameter is more
explicit than applySub.

Also adds comprehensive test coverage:
- 10 tests for MetaCoversPath core logic
- 6 tests for CanWriteContent
UserPerms
- 7 tests for getReadme
- 5 tests for getHeader
- 6 tests for isEncrypt
- 9 tests for whetherHide

Total: 43 test scenarios covering all path matching and permission
inheritance logic. Tests verify both normal behavior and bug fixes
for Readme/Header information leakage and write permission bypass.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>

* feat(permission): implement fine-grained user permissions for read/write operations

Add per-user read and write permission controls at the meta level to enable
more granular access control beyond the existing permission flags.

Key changes:
- Add ReadUsers/WriteUsers fields to Meta model with sub-directory inheritance flags
- Implement CanRead and CanWrite permission check functions in server/common
- Filter file list results based on user read permissions
- Add permission checks across all file operations (FTP, HTTP handlers, WebDAV)
- Simplify error handling pattern for MetaNotFound errors throughout codebase

This allows administrators to restrict specific users from accessing or modifying
certain paths, providing finer control over file system permissions.

Note: Batch and recursive operations (FsMove, FsCopy, FsRemove, FsRecursiveMove,
FsBatchRename, FsRegexRename) currently check parent directory permissions only.
Individual item permission checks are not performed for performance reasons.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>

* test(permission): add comprehensive tests for CanRead, CanWrite, and combined permission checks

Add TestCanRead, TestCanWrite, TestCanAccessWithReadPermissions, and
TestWritePermissionCombinations to validate the three-layer permission
system including nil user/meta, sub-path inheritance, user whitelists,
and root-level restrictions.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(webdav): use safe type assertion for MetaPassKey to prevent panic

Bearer-token and OPTIONS auth paths do not set MetaPassKey in context,
causing a panic when handlers perform a forced type assertion on nil.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(permission): treat nil user as system context in CanRead/CanWrite

Previously, CanRead/CanWrite returned false for nil user, causing
filterReadableObjs to return an empty list when fs.List is called from
internal contexts without a user (e.g. context.Background()). A nil user
represents an internal/system call and should bypass per-user restrictions,
consistent with how whetherHide already handles nil user.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(fsmanage): prevent path traversal in FsRemove

The previous check only skipped names that resolved to "/", but did not
prevent traversal to sibling directories (e.g. "../secret"), which could
bypass the CanWrite permission check that is only applied to req.Dir.

Replace with a post-join prefix check to ensure each resolved path stays
within reqPath.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(webdav): align MetaPassKey behavior with FTP auth logic

For guest users, the WebDAV password input serves as the meta folder
password (consistent with FTP anonymous/guest handling). For authenticated
users, MetaPassKey is set to empty string since their login password is
not the meta folder password.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(permission): require write auth for fs list refresh

* refactor(permission): use MetaCoversPath in CanRead/CanWrite for consistency

Replace inline `(Sub || meta.Path == path)` logic with MetaCoversPath,
consistent with CanWriteContentBypassUserPerms. Also fix a copy-paste
error in the CanWrite comment (read → write).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-03-26 14:42:35 +08:00
Jealous 9a2ba1dabe fix(server): add missing return after error responses (#2150)
In BeginAuthnRegistration (webauthn.go), missing return statements after
error responses caused the function to continue executing with a nil
authnInstance, potentially leading to a nil pointer panic.

In OIDCLoginCallback and SSOLoginCallback (ssologin.go), missing return
statements after GenerateToken/autoRegister errors caused the handler to
send a second response, resulting in a superfluous response write.

In SetThunderBrowser (offline_download.go), the default case of the
storage type switch sent an error response but did not return, causing
SaveSettingItems and tool initialization to continue executing even when
driver type validation failed.
2026-03-16 22:22:55 +08:00
MadDogOwner 82ae2d5890 chore(handles/auth): improve error response (#2148)
* chore(handles/auth): improve error response

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* Apply suggestion from @xrgzs

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
2026-02-19 17:15:40 +08:00
ShenLin 7b78fed106 Merge commit from fork
Co-authored-by: KirCute <951206789@qq.com>
2026-01-31 16:50:32 +08:00
Hu Yuantao d685bbfa9a fix(api/remove): add validation for empty items in delete file list (#1617)
* fix(FsRemove): add validation for empty items in delete file list

If Req.Names contains an empty string item, the whole directory will be removed. As a result we need add a simple guard to prevent such cases.

Signed-off-by: huyuantao <huyuantao@ultrarisc.com>

* fix(FsRemove): enhance validation to prevent unintended directory deletion

1. Use `utils.FixAndCleanPath` to correctly identify and block invalid names.
2. Change error handling from `return` to `continue`.

Signed-off-by: huyuantao <huyuantao@ultrarisc.com>

---------

Signed-off-by: huyuantao <huyuantao@ultrarisc.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
2026-01-29 21:48:16 +08:00
KirCute 85c69d853f fix(fs): panic when failed to get storage details (#1964) 2026-01-13 22:01:35 +08:00
mcxiedidi 642acf8bca feat(123pan): add offline download (#1911)
* feat(123网盘): 添加123网盘离线下载功能

- 新增123网盘离线下载实现
- 添加相关API接口和常量配置
- 在路由和工具集中集成123网盘支持

* refactor(offline_download): 重构123网盘离线下载状态处理和类型定义

- 将离线下载相关类型定义从util.go移至types.go
- 更新状态获取api

* 移除了备选方案(/offline_download/task/status)
2026-01-04 23:13:38 +08:00
我怎么就不是一只猫呢? c261ce78fb fix(s3): use current time as default modified time (#1860) 2025-12-29 23:52:35 +08:00
KirCute 2a99c97d52 feat(ldap): support webdav, ftp and sftp login (#1746)
* feat(ldap): support webdav, ftp and sftp login

* fix: apply suggestions of Copilot

* feat(ldap) support ftp, sftp and webdav auto-register
2025-12-15 16:53:38 +08:00
KirCute b2596fdc24 refactor(bootstrap): move booting logic to bootstrap package (#1773)
* refactor(bootstrap): move booting to bootstrap package

* chore(log): reduce level of some callings of `utils.Log.Fatal`

* fix(s3): no shutdown after SIGTERM received

* fix: add handle hook
2025-12-15 16:47:50 +08:00
j2rong4cn d31e1a333d feat(model): add object mask support and enhance cache/task handling (#1743) 2025-12-11 15:10:42 +08:00
j2rong4cn 96cd714385 refactor(op): remove automatic Path assignment (#1734)
* refactor: 移除 ObjResp 中的 Id 和 Path 字段

* 移除op.List的自动设置Path
Path和Id只在驱动内使用,不应由op.List设置Path

* cnb_releases:将 Addition 结构体中的 RootPath 字段为 RootID
当List方法加载二级目录时,若使用的是Id,应对使用driver.RootID

* doubao_share: 添加潜在bug注释

* 添加 GetRootPath 方法到多个驱动
2025-12-03 00:55:40 +08:00
KirCute 60a489eb68 feat(archive): support non-overwrite decompress (#1701) 2025-11-25 10:27:29 +08:00
varg1714 b22e211044 feat(fs): Add skipExisting option to move and copy, merge option to copy (#1556)
* fix(fs): Add skipExisting option to move and copy.

* feat(fs): Add merge option to copy.

* feat(fs): Code smell.

* feat(fs): Code smell.
2025-11-24 14:20:24 +08:00
KirCute 72e2ae1f14 feat(fs): support manually trigger objs update hook (#1620)
* feat(fs): support manually trigger objs update hook

* fix: support driver internal copy & move case

* fix

* fix: apply suggestions of Copilot
2025-11-21 12:18:20 +08:00
Copilot 9de7561154 feat(upload): add optional system file filtering for uploads (#1634) 2025-11-14 14:45:39 +08:00
KirCute 055696f576 feat(s3): support frontend direct upload (#1631)
* feat(s3): support frontend direct upload

* feat(s3): support custom direct upload host

* fix: apply suggestions of Copilot
2025-11-13 13:22:17 +08:00
ASLant 39dcf9bd19 feat(onedrive): support frontend direct upload (#1532)
* OneDrive添加直连上传

* refactor

* fix: duplicate root path join

---------

Co-authored-by: KirCute <951206789@qq.com>
2025-11-06 23:22:02 +08:00