* feat(driver): support 123 official app api
* fix(123_open): migrate api refresh to token.go
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/123_open): trigger proactive refresh with client credentials
* fix(drivers/123_open): use client-credential token endpoint for local refresh
Keep renewapi parsing for expires_in and map it to internal expiry time handling.
* fix(drivers/123_open): limit proactive refresh to client credentials
* fix(drivers/123_open): allow renewapi refresh token proactive init
* fix(drivers/123_open): update API address to use renewapi endpoint
* fix(drivers/123_open): simplify token refresh parsing
* fix(drivers/123_open): unify token expiration to expiredAt
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: Suyunmeng <Susus0175@proton.me>
Co-authored-by: Suyunjing <suyunmeng@oplist.org.cn>
- Switch default SQLite path to github.com/glebarez/sqlite to reduce CGO dependency pressure.
- Introduce a unified openSQLite entry in bootstrap and split driver selection by build tags.
- Add sqlite_cgo_compat fallback for linux mips, mips64, loong64 and mipsle to keep legacy target builds working.
- Update build.sh musl build flow to apply compatibility tag for mips-family targets.
- Update beta_release workflow to pass compatibility tag cleanly and avoid conflicting flag composition.
* refactor(permission): rename permission check functions for clarity
- User.CanWrite() → User.CanCreateFilesOrFolders()
- common.CanWrite() → common.CanWriteContentBypassUserPerms()
- common.IsApply() → common.MetaCoversPath()
Improves code readability by making function names more descriptive.
The new MetaCoversPath name clearly indicates it checks if a meta rule
covers a specific path. It better conveys that it's a query function
rather than an action, and the applyToSubFolder parameter is more
explicit than applySub.
Also adds comprehensive test coverage:
- 10 tests for MetaCoversPath core logic
- 6 tests for CanWriteContent
UserPerms
- 7 tests for getReadme
- 5 tests for getHeader
- 6 tests for isEncrypt
- 9 tests for whetherHide
Total: 43 test scenarios covering all path matching and permission
inheritance logic. Tests verify both normal behavior and bug fixes
for Readme/Header information leakage and write permission bypass.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* feat(permission): implement fine-grained user permissions for read/write operations
Add per-user read and write permission controls at the meta level to enable
more granular access control beyond the existing permission flags.
Key changes:
- Add ReadUsers/WriteUsers fields to Meta model with sub-directory inheritance flags
- Implement CanRead and CanWrite permission check functions in server/common
- Filter file list results based on user read permissions
- Add permission checks across all file operations (FTP, HTTP handlers, WebDAV)
- Simplify error handling pattern for MetaNotFound errors throughout codebase
This allows administrators to restrict specific users from accessing or modifying
certain paths, providing finer control over file system permissions.
Note: Batch and recursive operations (FsMove, FsCopy, FsRemove, FsRecursiveMove,
FsBatchRename, FsRegexRename) currently check parent directory permissions only.
Individual item permission checks are not performed for performance reasons.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* test(permission): add comprehensive tests for CanRead, CanWrite, and combined permission checks
Add TestCanRead, TestCanWrite, TestCanAccessWithReadPermissions, and
TestWritePermissionCombinations to validate the three-layer permission
system including nil user/meta, sub-path inheritance, user whitelists,
and root-level restrictions.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(webdav): use safe type assertion for MetaPassKey to prevent panic
Bearer-token and OPTIONS auth paths do not set MetaPassKey in context,
causing a panic when handlers perform a forced type assertion on nil.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(permission): treat nil user as system context in CanRead/CanWrite
Previously, CanRead/CanWrite returned false for nil user, causing
filterReadableObjs to return an empty list when fs.List is called from
internal contexts without a user (e.g. context.Background()). A nil user
represents an internal/system call and should bypass per-user restrictions,
consistent with how whetherHide already handles nil user.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(fsmanage): prevent path traversal in FsRemove
The previous check only skipped names that resolved to "/", but did not
prevent traversal to sibling directories (e.g. "../secret"), which could
bypass the CanWrite permission check that is only applied to req.Dir.
Replace with a post-join prefix check to ensure each resolved path stays
within reqPath.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(webdav): align MetaPassKey behavior with FTP auth logic
For guest users, the WebDAV password input serves as the meta folder
password (consistent with FTP anonymous/guest handling). For authenticated
users, MetaPassKey is set to empty string since their login password is
not the meta folder password.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(permission): require write auth for fs list refresh
* refactor(permission): use MetaCoversPath in CanRead/CanWrite for consistency
Replace inline `(Sub || meta.Path == path)` logic with MetaCoversPath,
consistent with CanWriteContentBypassUserPerms. Also fix a copy-paste
error in the CanWrite comment (read → write).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
In BeginAuthnRegistration (webauthn.go), missing return statements after
error responses caused the function to continue executing with a nil
authnInstance, potentially leading to a nil pointer panic.
In OIDCLoginCallback and SSOLoginCallback (ssologin.go), missing return
statements after GenerateToken/autoRegister errors caused the handler to
send a second response, resulting in a superfluous response write.
In SetThunderBrowser (offline_download.go), the default case of the
storage type switch sent an error response but did not return, causing
SaveSettingItems and tool initialization to continue executing even when
driver type validation failed.
* fix(115_share): add user agent support and update driver dependency
* fix(115): fix download error
* feat: add thumbnail support for 115 driver and 115 share
- Add Thumb() method to FileObj in 115 driver to return thumbnail URL
- Add ThumbURL field to FileObj struct in 115 share utility
- Update 115driver dependency from v1.2.2 to v1.2.3 to support thumbnail functionality
- Implement Thumb() method for 115 share FileObj to return thumbnail URL
* fix(FsRemove): add validation for empty items in delete file list
If Req.Names contains an empty string item, the whole directory will be removed. As a result we need add a simple guard to prevent such cases.
Signed-off-by: huyuantao <huyuantao@ultrarisc.com>
* fix(FsRemove): enhance validation to prevent unintended directory deletion
1. Use `utils.FixAndCleanPath` to correctly identify and block invalid names.
2. Change error handling from `return` to `continue`.
Signed-off-by: huyuantao <huyuantao@ultrarisc.com>
---------
Signed-off-by: huyuantao <huyuantao@ultrarisc.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
* fix(driver/seafile): object not found when RootFolderPath != "/"
* refactor(seafile): restructure Seafile driver for improved library handling and error management
* add IsDir method to LibraryInfo type
* improve initialization
* add repoID to RepoItemResp and update List method to set repoID
---------
Co-authored-by: Khoray <hhkorm@gmail.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
* fix(FileTransferTask): skip copying if destination directory does not exist
* pass only object not found error
---------
Co-authored-by: cyk <dr_arc@163.com>
Co-authored-by: KirCute <951206789@qq.com>
* Remove the `OnlyProxy` restriction and obtain the redirected link to support 302
* Add `driver.Config` `PreferProxy` to recommend user to enable the proxy by default
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* feat(drivers): support getting disk usage of some drivers
* feat(drivers/degoo): implement GetDetails
* fix(fs/storage-details): fill used space rather than free space
* fix mega
* fix bsize type
* feat(driver): add wps drive support
* feat(driver): add wps drive support
* fix(wps): update personal mode string to English
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): remove trailing slash from drive origin URL
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): correct order of options in mode selection
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): enable local sort and upload overwrite
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): resolve put bugs, fix file op problems and optimize list logic
- Fix uploading bugs. Support all uploading methods based on 8825.85d3c864.js
- Fix issues in delete/copy/move while opearting big folders.
- Use cache to optimize performance of list, especially in a deep path.
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
* refactor(bootstrap): move booting to bootstrap package
* chore(log): reduce level of some callings of `utils.Log.Fatal`
* fix(s3): no shutdown after SIGTERM received
* fix: add handle hook
* feat(fs): Support customizing the cache time for a specific path
* feat(fs): Get the cache rule for driver information.
* feat(fs): Support globbing.
* feat(fs): Add log.
---------
Signed-off-by: ShenLin <773933146@qq.com>
Co-authored-by: ShenLin <773933146@qq.com>
refactor!(userAgent): merge all userAgent into base
1. change var to const
2. remove duplicated ua definetion after original Resty R
3. upgrade Chrome and OS versions
* fix(mediafire): enable automatic session token acquisition and fix gzip parsing
- Fix Init() method to allow automatic session token retrieval from cookie
- Change SessionToken from required to optional in configuration
- Add proper gzip decompression support for API responses
- Improve error handling for session token acquisition failures
- Update help text to clarify authentication requirements
Resolves initialization failure and JSON parsing errors when session token
can be automatically obtained from browser cookie.
* fix(mediafire): ensure driver files end with newline
* chore: gofmt drivers/mediafire/*.go
* Add task queue for Meilisearch to prevent race conditions
- Implement TaskQueueManager for async index operations
- Queue update tasks and process them in batches every 30 seconds
- Check pending task status before executing new operations
- Optimize batch indexing and deletion logic
- Fix type assertion bug in buildSearchDocumentFromResults
* fix(search): re-enqueue skipped tasks to prevent task loss
When tasks are skipped due to pending dependencies, they are now
re-enqueued if not already in queue. This prevents task loss while
avoiding overwriting newer snapshots for the same parent.
* fix(copilot-comment): Invoke Stop() & err of SliceConvert
---------
Co-authored-by: ImoutoHeaven <noreply@imoutoheaven.org>
Co-authored-by: jyxjjj <773933146@qq.com>
* fix(driver/123): initialization the Platform field
Signed-off-by: MoYan <1561515308@qq.com>
* Fix formatting of Platform field in Pan123
Signed-off-by: MoYan <1561515308@qq.com>
---------
Signed-off-by: MoYan <1561515308@qq.com>
* fix(strm): non-specified type generates strm
* fix(strm): only insert to strmTrie if SaveStrmToLocal is enabled
* fix(strm): update suffix handling in convert2strmObjs function
* fix(strm): refactor generateStrm to use range reader
---------
Co-authored-by: j2rong4cn <j2rong@qq.com>
* refactor(stream): simplify Close method and update SeekableStream to use RangeReader interface
* refactor(stream): improve RangeRead comments for clarity
* fix(baidu_netdisk): improve upload experience
* fix(typo): URL should be uppercase, apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: ShenLin <773933146@qq.com>
* fix(typo): URL should be uppercase, apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: ShenLin <773933146@qq.com>
* fix(baidu_netdisk): use "UploadAPI" as a fallback when using dynamic upload api
* fix(baidu_netdisk): all uploads share the same upload url cache
* fix(drivers/baidu_netdisk): defer uploadUrlMu unlock
* update driver.go to main
---------
Signed-off-by: ShenLin <773933146@qq.com>
Signed-off-by: jenfonro <799170122@qq.com>
Co-authored-by: ShenLin <773933146@qq.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: jenfonro <799170122@qq.com>
* perf(stream): optimize CacheFullAndWriter for better memory management
* fix(stream): ensure proper seek handling in CacheFullAndWriter for improved data integrity
* support proxy
* debug
* debug2
* del debug
* add proxy configuration with env var fallback
* comments to en
* refactor(env): fallback env
---------
Co-authored-by: jyxjjj <773933146@qq.com>
* feat(drivers/123): Allow modification of the platform field
* feat(drivers/123): Set login platfrom as web
* fix(drivers/123): update platform field help value
2025-11-03 10:02:52 +08:00
339 changed files with 15599 additions and 7026 deletions
You must check all the following, otherwise your issue may be closed directly.
You must read, check, confirm, and agree to all the following, otherwise your issue will definitely be closed directly.
Or you can go to the [discussions](https://github.com/OpenListTeam/OpenList/discussions).
options:
- label:|
@@ -34,7 +34,8 @@ body:
I believe this issue must be handled by `OpenList` and not by a third party.
- label:|
I confirm this issue is not fixed in the latest version.
- label:|
I have not read these checkboxes and therefore I just ticked them all, Please close this issue.
- type:input
id:version
attributes:
@@ -59,6 +60,14 @@ body:
label:Bug Description (required)
validations:
required:true
- type:textarea
id:logs
attributes:
label:Logs (required)
description:|
Please copy and paste any relevant log output or screenshots. (You may mask sensitive fields) [Guide](https://doc.oplist.org/faq/howto#how-to-quickly-locate-bugs)
validations:
required:true
- type:textarea
id:config
attributes:
@@ -67,12 +76,6 @@ body:
Please provide your `OpenList` application's configuration file and a screenshot of the relevant storage configuration. (You may mask sensitive fields)
validations:
required:true
- type:textarea
id:logs
attributes:
label:Logs (optional)
description:|
Please copy and paste any relevant log output or screenshots. (You may mask sensitive fields) [Guide](https://doc.oplist.org/faq/howto#how-to-quickly-locate-bugs)
Provide a general summary of your changes in the Title above.
The PR title must start with `feat(): `, `docs(): `, `fix(): `, `style(): `, or `refactor(): `, `chore(): `. For example: `feat(component): add new feature`.
If it spans multiple components, use the main component as the prefix and enumerate in the title, describe in the body.
For breaking changes, add `!` after the type, e.g., `feat(component)!: breaking change`.
comment += "⚠️ Please modify the title to better describe your issue or request, and remove the example prompt. This issue will be automatically closed. If you wish to proceed, please create a new issue.\n";
comment += "⚠️ Your issue does not comply with the submission rules. Please read the guidelines before submitting again. This issue will be automatically closed. If you wish to proceed, please confirm that you have reviewed the rules before reopening or creating a new issue.\n";
await github.rest.issues.createComment({
...context.repo,
issue_number: context.issue.number,
body: comment
});
await github.rest.issues.update({
...context.repo,
issue_number: context.issue.number,
state: 'closed',
state_reason: 'not_planned',
labels: ['invalid']
});
return;
}
if (confirmHasRead) {
comment = "感谢您联系OpenList。我们会尽快回复您。\n";
comment += "Thanks for contacting OpenList. We will reply to you as soon as possible.\n\n";
comment += "⚠️ The PR title must start with `feat(): `, `docs(): `, `fix(): `, `style(): `, or `refactor(): `, `chore(): `. For example: `feat(component): add new feature`.\n\n";
@@ -122,12 +122,17 @@ Thank you for your support and understanding of the OpenList project.
## Demo
N/A (to be rebuilt)
- 🌎 [Global Demo](https://demo.oplist.org)
- 🇨🇳 [CN Demo](https://demo.oplist.org.cn)
## Discussion
Please refer to [*Discussions*](https://github.com/OpenListTeam/OpenList/discussions) for raising general questions, ***Issues* is for bug reports and feature requests only.**
## Sponsor
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## License
The `OpenList` is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
@@ -122,12 +122,17 @@ Dank u voor uw ondersteuning en begrip
## Demo
N.v.t. (wordt opnieuw opgebouwd)
- 🌎 [Global Demo](https://demo.oplist.org)
- 🇨🇳 [CN Demo](https://demo.oplist.org.cn)
## Discussie
Stel algemene vragen in [*Discussions*](https://github.com/OpenListTeam/OpenList/discussions), ***Issues* zijn alleen voor bugmeldingen en feature requests.**
## Sponsoren
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## Licentie
`OpenList` is open-source software onder de [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) licentie.
File diff suppressed because it is too large
Load Diff
Some files were not shown because too many files have changed in this diff
Show More
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.