QR code scans were authorized on the phone but the storage stayed stuck on
the QR page, and token-only setups failed with "params is null".
The driver used appId 8025431004 while the official PC client uses
9317140619. Tokens, sessions and QR sessions are all scoped to an appId, so
the mismatch meant the QR poll never saw status:0 and an accessToken could
not be exchanged for a sessionSecret.
- Use appId 9317140619 and version 7.2.4.0. QR state polling uses
clientType=1; password login keeps 10020.
- Send the QR poll parameters the official client sends (cb_SaveName,
isOauth2, state, user-finger header, logbox Referer) and poll locally
instead of only checking once per save.
- Parse lt/reqId from the logbox redirect and paramId from appConf.do. The
new login page no longer embeds them as inline variables; the old inline
format is still supported.
- Implement the -133 second device verification via
sendSmsCodeForSecondAuth/submitForSecondAuth. That endpoint has no
dedicated SMS field: the code goes into epd, encrypted with the same
public key used for the password. Persist the DEVICEID cookie so the
verification only happens once.
- Detect refreshToken.do failures. It reports them as HTTP 200 with a
result field, so SetError never fired and a failed refresh was treated as
success, surfacing later as a misleading "params is null".
- username/password are no longer required, so token-only storages save
without placeholders. clientSn/jgOpenId are optional and only sent when
configured; user-finger is generated once per storage.
- Return named errors instead of panicking when the login page changes shape.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Lanzou recently changed the file share page: download params moved
into an iframe (/fn?<token>) inner page, and the download API is now
an absolute URL (https://apifile.woozooo.com/ajaxfile.php?file=N)
with new sign params (wp_sign/ajaxdata, action=downprocess).
The old findFileIDReg ('/ajaxm.php?file=N' relative path) no longer
matches, causing 'failed link: failed get link: not find file id'.
Fall back to parsing the new /fn page structure when the legacy
regex does not match. Legacy flow is kept untouched.
Signed-off-by: rzsgsfm <rzsgsfm@users.noreply.github.com>
Co-authored-by: rzsgsfm <rzsgsfm@users.noreply.github.com>
Co-authored-by: GLM (ZCode CLI) <noreply@z.ai>
* fix(aliyundrive): limit callback concurrency
- Share proxy callback admission by Aliyun user identity and hold permits for complete response-body lifetimes.
- Retry only verified callback-capacity rejections while preserving direct redirects and server download limiting.
- Map exhausted temporary capacity to S3 SlowDown through the merged OpenListTeam gofakes3 module.
- Cover shared limits, lifecycle release, cancellation, retry classification, and the S3 HTTP response.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
# Conflicts:
# go.mod
# go.sum
# server/s3/pager.go
* fix(op): separate redirect and proxy link cache entries
- Include redirect mode in the link cache key for all drivers.
- Cover both redirect-to-proxy and proxy-to-redirect cache reuse.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(proxy): close range bodies before opening next
- make ServeHTTP own each range body and preserve cleanup failures
- remove the aggregate range closer and pass range readers directly
- replace the obsolete callback transport test with focused lifecycle coverage
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
---------
Co-authored-by: nostalume <nostalucent@gmail.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
- Refresh OSS credentials and retry the rejected multipart operation
- Preserve upload IDs, completed parts, callbacks, and outer part retries
- Rewind parts before resending and pass the upload context to OSS requests
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(alist_v3): set child paths so nested directories resolve
- Set `Path` on every object returned by `List`, matching the OpenList
driver. `op.Get` hands a child object straight back to `List`, so a
child without a path made the driver request `""` from the upstream
server, which answered with its own root: every directory below the
mount point served the same listing back, endlessly.
- Add tests covering the child paths and a three-level descent.
Co-authored-by: Claude <81847+claude@users.noreply.github.com>
* test(alist_v3): trim the child-path test to a single case
Collapse the two tests into one two-level descent, drop the recorder
type and the helper funcs, and inline the driver setup. 173 -> 65 lines.
Co-authored-by: Claude <81847+claude@users.noreply.github.com>
---------
Co-authored-by: Fighting <3899648+Elity@users.noreply.github.com>
Co-authored-by: Claude <81847+claude@users.noreply.github.com>
test(s3): encode multipart fixture paths
- Serialize the Local storage addition instead of interpolating filesystem paths into JSON.
- Keep multipart fixture behavior portable across Windows and Linux.
Co-authored-by: nostalume <nostalucent@gmail.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
- add an opt-in Local driver setting for PDF thumbnails
- render PDF first pages with macOS Quick Look
- preserve unsupported-platform behavior and cover the renderer with tests
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Co-authored-by: ILoveScratch <ilovescratch@foxmail.com>
ci(github): enforce AI disclosures and lock invalid issues
- Require exactly one AI disclosure option and a model name when AI is used
- Comment, close, lock, and label issues invalid for missing or malformed AI disclosures or missing model names
- Lock issues closed for unchanged placeholder titles
- Lock issues closed for selecting the unread checklist option
- Exclude AI disclosure options from unchecked task detection
- Skip automatic checks for announcement titles
- Update bilingual closure replies to mention locking and request a new issue
- Split issue replies and PR title checks into separate workflows without changing PR title rules
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(drivers/139): improve mail login credential renewal
* fix(drivers/139): guard mail login client initialization
Fall back to base.NewRestyClient() when base.RestyClient has not been initialized, while preserving cloned global-client behavior and the login/SMS retry and redirect policies.
- Decode JSON time strings before normalizing Unicode spaces in both 189 drivers
- Exercise escaped spaces and existing date formats through JSON unmarshalling
- Cover invalid JSON input and XML time parsing
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
- Resolve and authorize the canonical destination from the request payload
- Reject upload capabilities that cross virtual storage mount boundaries
- Remove the unrelated File-Path middleware authorization check
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
* fix(cmd/start): use absolute executable path for child process
* fix(cmd/start): detect force-bin-dir flag variants
---------
Co-authored-by: Zoe Lee <zoelee@gmail.com>
multipartUploadToOSS passed the UpdateProgress callback into
stream.NewStreamSectionReader, which ignores the up argument, so the
callback was never invoked while uploading parts. As a result,
cross-storage copy tasks targeting GuangYaPan stayed at 0% and showed no
progress bar or speed in the task list.
Fix by tracking the uploaded byte count and invoking up after every
part is uploaded, keeping consistent with other drivers' upload flow.
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
The 115 and pikpak multipart uploaders checked for cancellation with a
`case <-ctx.Done()` inside a select, and a break there only leaves the
select, not the enclosing `for retry := 0; retry < 3; retry++` loop.
Cancelling an upload therefore ran all three attempts for every
remaining chunk, each allocating a chunk-sized buffer and reading it
off disk before firing a request that could not succeed, and reported
a transport error instead of the cancellation.
Move the check ahead of the select and use utils.IsCanceled, matching
the pattern the other drivers already use. Assigning ctx.Err() to err
is load-bearing: without it a cancelled chunk takes the success branch,
counts toward progress, and appends a zero-value UploadPart.
Found with staticcheck (SA4011).
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
* feat(strm): add local save permission mode
- add private and shared permission modes for local STRM files
- repair shared-mode directory and file permissions during generation
- add permission handling tests
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(strm): respect deployment umask for local directories
- remove application-level permission modes and chmod operations
- create local STRM directories with umask-controlled permissions
- preserve existing permissions and test the behavior
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
---------
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* feat(ilanzou): modernize console API session and copy
Use an isolated cookie-backed API session and preserve raw appToken syntax required by current iLanzou endpoints.
Resolve CDN download responses more robustly, align upload metadata with the console protocol, and delegate copies to OpenList background tasks instead of blocking requests.
* fix(ilanzou): escape appToken query values
Escape opaque appToken values while preserving the literal colon required by iLanzou endpoints. Ignore CDN HEAD response lengths unless the response status is successful.
* fix(ilanzou): address driver review feedback
Use the ilanzou package name consistently, document upload result polling, and bound CDN size probes. Keep the appToken and CDN challenge handling covered by focused tests and comments.
* fix(ilanzou): use context timeout for HEAD probe
* feat(strm): add file size filtering for STRM generation
- add ParseSize helper function in pkg/utils to parse human-readable byte sizes
- add minFileSize setting field to STRM driver Addition struct
- filter out files below minFileSize threshold during STRM generation
* refactor(strm): use MB as default unit for minFileSize instead of ParseSize
Replace string-based ParseSize auto-conversion with a simple int64 number
field defaulting to MB, consistent with other drivers (Google Drive,
Teldrive). Remove the now-unused ParseSize function and its tests.
* feat(multipart): add chunk reassembly window
- Reassemble concurrently uploaded chunks into a sequential stream through a ring file, bounding disk usage to slots*chunkSize per session
- Park writers up to a deadline when their slot is busy instead of rejecting instantly, so flow control does not surface as connection errors in browsers
- Record a per-chunk CRC32 table for re-fill verification and keep it readable after close
- Propagate cancellation to blocked readers via CloseWithError so drivers treat aborts like canceled requests
- Cover ordering, backpressure, idempotent resends and close/abort wake-ups with race-enabled tests
* feat(multipart): add pipelined upload session manager
- Start the driver upload at session init over a sequential stream backed by the window, so client-to-server and server-to-storage transfers run concurrently
- Attach client-provided hashes to the stream so drivers can attempt rapid upload before any chunk arrives, and absorb chunks racing pipeline completion idempotently
- Keep only metadata and chunk CRCs after a failed attempt: re-sending chunk 0 re-fills a fresh window, and content changes between attempts are rejected
- Resume receiving sessions only when client hashes prove the same file; failed_retriable sessions resume unconditionally
- Reclaim sessions with a sliding-TTL GC and sweep orphaned ring files at startup
- Cover the state machine with race-enabled tests over a stubbed storage layer
* feat(setting): add multipart upload settings
- Add multipart_enabled and multipart_chunk_size (MB) as public traffic settings
- Validate the chunk size on save (integer within 1-90) via the setting item hook
* feat(server): add multipart upload API
- Add /api/fs/multipart init/chunk/complete/status/abort endpoints with headers aligned with /fs/put
- Gate init behind the FsUp permission checks and reuse the client upload rate limiter for chunk uploads
- Drain the request body before answering chunk requests on every path, so browsers do not see early responses as network errors
- Start the multipart session GC when the router is initialized to reclaim ring files orphaned by a previous run
* refactor(multipart): remove unused overwrite session field
- The overwrite flag was stored on the session but never read: the handler
performs the pre-check and op.Put owns the overwrite semantics
* feat(setting): allow any positive multipart chunk size
- Validate the setting as a positive integer only; self-hosted admins decide
the ceiling themselves instead of an arbitrary 90MB cap
- Keep clamping the client-suggested X-Chunk-Size to the admin value: the
server buffers a window of 8 chunks per session, so an unbounded client
suggestion would translate directly into server-side disk usage
* refactor(server): simplify multipart chunk size clamp
- Fold the two-step clamp into one branch: the ceiling is already floored,
so a client suggestion just lowers the size with a 1MB floor
The Login endpoint may return an acw_sc__v2 validation page when accessed,
which previously caused login failures. This change adds the same retry
logic and cookie handling already used in request() to automatically solve
the challenge, ensuring login success even when the anti-bot mechanism is
triggered.
* fix(drivers/139): update path handling for family
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* perf(drivers/139): add retry go for family upload
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* feat(drivers/139): add FamilyCloudHost and GroupCloudHost handling
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* perf(drivers/139): add retry go for personalnew upload
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): use new batchpartinfos for remaining parts
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(driver/139): do not use path in id
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(driver/139): refactor RootPath handling
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(driver/139): remove root path stripping in Init method
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(drivers/139): reduce upload retry attempts to 3
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): add rate limiting for MetaPersonalNew upload
- Wrap stream with LimitedUploadStream before creating StreamSectionReader
- Aligns with the same pattern used in the MetaPersonal/MetaGroup/MetaFamily path
Co-authored-by: GitHub Copilot <copilot@github.com>
* fix(drivers/139): fix section reader leak and seek check in retry block
- Check rd.Seek() return value and free the section reader on error
- Call ss.FreeSectionReader(rd) on all error paths within retry.Do closure
- Prevents buffer.Block leak when retrying failed upload chunks
Co-authored-by: GitHub Copilot <copilot@github.com>
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): move GetSectionReader outside retry loop
- Move ss.GetSectionReader() before retry.Do() so the sequential
stream section reader is only called once per chunk
- Remove redundant ss.FreeSectionReader() calls from inside the
retry closure since the reader is now owned by the outer scope
- Fixes 'stream not cached' errors when retrying failed chunk
uploads during cross-storage WebDAV COPY operations
Co-authored-by: GitHub Copilot <copilot@github.com>
* feat(drivers/139): add UseOldStreamUpload option
- Add UseOldStreamUpload option
- Implement newRequest, newPost
- Support rapid upload for PersonalNew and Group/Family
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): add more param for group/family put
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): correct group params for new put
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): update personalPost to use getPersonalCloudHost
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(drivers/139): correct typo
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): pass full partInfos slice for batched upload
- Pass the global partInfos slice instead of the batch subset to
uploadPersonalParts, so that PartNumber-1 indexing does not go
out of bounds when a file has more than 100 parts.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(drivers/139): avoid double-counting progress on upload retries
- Save p.Done before each part and reset it inside the retry function
so that bytes from failed attempts are not counted toward progress.
- Each part is counted exactly once, on the successful attempt.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(drivers/139): gate route-host checks by cloud type
- Only validate GroupCloudHost and FamilyCloudHost for MetaGroup
and MetaFamily storage types, so that personal-only accounts do
not fail initialization when the route policy omits group/family.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(drivers/139): add ProviderRoot back for groupgetfiles
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): set path to 0 when group old upload
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): improve error handling for family root path retrieval
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* refactor(drivers/139): update condition checks for CloudHost initialization
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: GitHub Copilot <copilot@github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Recover temporarily missing or incomplete 115 Open path metadata from parent
and ancestor directory listings. Use 115-sdk-go v0.2.6 to normalize missing
object errors, while preserving valid zero-byte files and ensuring recursive
parent resolution progresses correctly.
Co-authored-by: Claude <noreply@anthropic.com>
* refactor(github_releases): remove internal caching, use global cache instead
- Remove Release/Releases/OtherFile cache fields from MountPoint struct
- Convert instance methods to pure functions (releaseToFiles, releasesToVersionDirs, etc.)
- Make List() fetch fresh data from GitHub API on every call
- Add githubGet helper to centralize GitHub API requests
- Remove unused GetRequest method and IsAncestorDir function
Co-authored-by: GitHub Copilot <copilot@github.com>
* feat(github_releases): add pagination and max page limit for all versions
- Add PerPage config to control releases per page (default 30, max 100)
- Add MaxPage config to limit max pages fetched (0 = unlimited)
- Rewrite getAllReleases to support automatic pagination
Co-authored-by: GitHub Copilot <copilot@github.com>
* chore(github_releases): move utils from driver.go to util.go
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(github_releases): revert changes to GetRequest
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(github_releases): use more common format for github proxy url
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(github_releases): show_readme in empty releases case
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(github_releases): preserve README and LICENSE name variants
Co-authored-by: Copilot <copilot@github.com>
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: GitHub Copilot <copilot@github.com>
* feat(driver): add Cloudflare Image Bed support
* fix: restore accidentally deleted file and name
* refactor: rename driver to cloudflare_imgbed and fix module structure
- Rename driver identifier and directory to 'cloudflare_imgbed' for consistency.
- Remove invalid 'replace' directive in go.mod.
- Restore accidentally modified/deleted files in public/dist.
- Update driver registration in drivers/all.go.
Co-authored-by: Copilot <copilot@github.com>
* fix: use base.NewRestyClient() and use e.g
Co-authored-by: Copilot <copilot@github.com>
* fix:go fmt
* feat(driver/cloudflare-imgbed): enhance cloudflare_imgbed API integration with improved error handling and pagination
* refactor
* feat(cloudflare_imgbed): implement upload functionality and optimize performance
- Added support for standard multipart form upload with zero-copy streaming.
- Implemented HuggingFace LFS direct upload for large files (>20MB).
- Integrated with OpenList global rate limiter and progress tracking.
- Optimized memory usage using io.MultiReader for request body construction.
- Added configurable upload threads for chunked HF uploads.
- Support auto mkdir dir when in upload
* refactor: simplify path handling logic
* refactor(cloudflare_imgbed): streamline API endpoint constants and improve initialization logic
* refactor(cloudflare_imgbed): clean up upload logic and remove unused functions
* docs: update help descriptions to English in cloudflare_imgbed
* feat(cloudflare_imgbed): add virtual directory support
* refactor(weak_cache): iImprove weak pointer cleanup handling
Store a cleanup handle alongside weak pointers and stop previous cleanups when overwriting entries to avoid stale removals and leaked cleanup handlers.
Ensure Delete signals success and stops associated cleanup. Add Clear to stop all active cleanups. Use entry identity in the cleanup callback to avoid removing newly inserted values.
* fix bug
* Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
* Adds uploadFolder param and streams base64 sample
Adds an uploadFolder query parameter to forward the destination path to the backend. Replaces the fixed-size sample read with a streaming base64 encoder to avoid truncation and reduce allocations
Co-authored-by: Copilot <copilot@github.com>
* refactor: add context parameter to doRequest and related calls
* fix: update List method to check args.Refresh before virtual directory mask
* refactor: optimize List method and improve error handling in doRequest
* feat: add public URL support and multi-channel chunked upload
- Support multi-channel chunk size configurations (e.g., Telegram, CFR2, S3, Discord).
- Fix 401 unauthorized error when merging chunks in HuggingFace channel.
---------
Signed-off-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: Copilot <copilot@github.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
Rename function passed RenameResp by value instead of pointer, causing
the API response to be discarded and producing a zero-value file entry
with empty name, zero size, and zero timestamps after rename.
1. Add `cwd_list` option to switch LIST command logic
Use CWD + LIST "" instead of LIST <path> to fix garbled non-UTF8 paths on legacy Chinese FTP servers, eliminate fake duplicate folders.
2. Filter entries with "/" in filename
Skip cdir marker entries carrying full path names, compliant with FTP filename specification.
Co-authored-by: Claude <81847+claude@users.noreply.github.com>
* fix(drivers/github_releases): skip broken repos instead of returning 500
When multiple repos are configured and one fails (404, rate limit, etc.),
the driver now logs a warning and skips that repo instead of panicking
with a nil pointer dereference that caused a 500 error for the entire
storage. Added proper error propagation from GetRequest through
RequestRelease/RequestReleases/GetOtherFile, and nil checks on all
Release/Releases dereferences.
Instead of hiding broken repos entirely, still display them as directory
entries in parent listings. Return an error only when the user navigates
into a broken repo.
Co-authored-by: Claude Code <noreply@anthropic.com>
Co-authored-by: Mimo <208276378+mimo@users.noreply.github.com>
* fix(drivers/github_releases): apply patches
Co-authored-by: GitHub Copilot <copilot@github.com>
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: Claude Code <noreply@anthropic.com>
Co-authored-by: Mimo <208276378+mimo@users.noreply.github.com>
Co-authored-by: GitHub Copilot <copilot@github.com>
Normalize WebDAV 404 responses from `Stat` to `errs.ObjectNotFound`.
This fixes the mkdir pre-check path: when the target folder does not exist, `op.MakeDir` can now treat the lookup as a normal missing object and continue to issue `MKCOL` through the WebDAV driver.
Co-authored-by: ChatGPT <noreply@openai.com>
Set `WithResidentKeyRequirement` option during registration to enable discoverable keys.
Existing keys do not require migration. They won't appear without entering username, but work normally after username input, legacy flows remain unaffected.
Redirect S3 GET object requests to direct links when the underlying storage can provide one and proxying is not required.
Redirect eligible S3 PUT object requests to HttpDirect single PUT upload URLs with 307, while falling back to the existing gofakes3 stream path for unsupported uploads.
Allow OneDrive Sharelink direct upload info to use simple content PUT URLs for files within Microsoft's single-upload limit.
Co-authored-by: syscc <syscc@users.noreply.github.com>
Co-authored-by: Codex <codex@openai.com>
- Fix#2343: update 115driver to v1.3.3 to handle float size values
- Fix#2349, #2356, #2502: use base.UserAgent as fallback when User-Agent header is empty
The 115 CDN returns 403 "no cookie value" when the User-Agent header
is empty or doesn't match the cookie. This fix ensures a consistent
browser User-Agent is used for download link generation.
Add end-to-end offline download support for torrent files, magnet links, and ed2k links, including torrent parse and generate APIs, CAS-based rapid upload for Cloud189, and protocol-aware tool routing with transfer flow improvements.
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: Suyunjing <suyunmeng@oplist.org.cn>
* Squashed commit of the following:
commit f029df88e4ebc36e0886662193dc99f8276959ce
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 14:00:36 2025 +0800
Add Terms of Use and Privacy Policy links to READMEs
Added links to the Terms of Use and Privacy Policy in the English, Chinese, Japanese, and Dutch README files to provide users with easy access to legal information.
commit 00f825d9e2
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:53:29 2025 +0800
Update documentation links in README files
Replaced plain documentation URLs with labeled links and icons in English, Chinese, Japanese, and Dutch README files for improved clarity and user experience.
commit 732dcfa5b1
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:40:52 2025 +0800
fix format
commit e2ad8eabb8
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:38:28 2025 +0800
Revert "test large name"
This reverts commit affedc845b.
commit affedc845b
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:37:43 2025 +0800
test large name
commit 382cd6425f
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:34:42 2025 +0800
Add Dutch README and update language links
Added a new Dutch translation (README_nl.md) and updated language navigation links in the English, Chinese, and Japanese README files to include Dutch.
commit e880acb71d
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:29:51 2025 +0800
Add AGPL-3.0 license links to README files
Updated the English, Chinese, and Japanese README files to include direct links to the AGPL-3.0 license text and the LICENSE file for clarity and easier access.
commit a0d1eadf3e
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:25:52 2025 +0800
Move language and links sections below logo in READMEs
Repositioned the language selection and related links sections to appear after the logo and separator in README.md, README_cn.md, and README_ja.md for improved layout consistency.
commit 70a0a32b7b
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 13:23:36 2025 +0800
Revise and unify README files across languages
Updated README.md, README_cn.md, and README_ja.md to improve structure, add navigation links, clarify project purpose, and unify feature lists. Enhanced formatting, added acknowledgments to original authors, and improved legal/disclaimer sections for consistency across English, Chinese, and Japanese documentation.
commit 2f32120908
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:56:26 2025 +0800
Update Go Report Card badge URL in README
Changed the Go Report Card badge to reference v3 instead of v4. This ensures the badge displays the correct status for the intended version.
commit 0fdfa2b365
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:53:43 2025 +0800
Update README.md
commit 82713611c0
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:53:22 2025 +0800
Update Go Report Card badge URL in README
Changed the Go Report Card badge link to remove the '/v3' suffix, ensuring it points to the correct repository path.
commit 41acb3e865
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:52:46 2025 +0800
Update project description in README
Revised the introductory paragraph to emphasize OpenList's resilience and community-driven nature as a fork of AList, highlighting its commitment to defending open source against trust-based attacks.
commit 77aca6609a
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:50:45 2025 +0800
Update README.md
commit 63a597f802
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:49:57 2025 +0800
Improve README badge formatting and alignment
Reformatted the badge section in the README for better readability and visual alignment. Updated the div to use 'align="center"' and placed each badge on its own line with proper indentation.
commit fcf7530dd8
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:46:38 2025 +0800
Update logo size and remove migration note in README
Set explicit width and height for the logo image and removed the note about migration progress, reflecting project updates.
commit 5f0645ded8
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:45:04 2025 +0800
Revert README header to HTML
Replaces markdown-based center alignment and badge/image syntax with HTML tags for better visual formatting and consistency in the README header.
commit 0f7ba9599d
Author: jyxjjj <773933146@qq.com>
Date: Tue Jul 1 12:42:59 2025 +0800
Revise README formatting and update project info
Refactored the README to use markdown badge/link syntax, improved formatting, and clarified the disclaimer section. Updated Docker Deploy status, added a Contact Us section, and reordered the Contributors section for better project transparency and communication.
* chore(readme): fix sites
* chore(readme): fix sites
* refactor(HybridCache)!: extract hybrid_cache package and rename cache_threshold to auto_memory_limit
* split HybridCache and stores into internal/hybrid_cache package
* introduce BackingStore abstraction with BufferStore and FileStore
* rename CacheThreshold to AutoMemoryLimit in config/env/bootstrap
* update stream/request integration and related tests
* rename singleFileCache and MultiFileCache to singleFileStore and MultiFileStore
* refactor(HybridCache): improve memory management strategies in NewHybridCache
* rename
* alias hybrid_cache to hcache
* omments
* fix(driver): fix 189 & 189pc fastcopy form local storage
* fix(driver): fix 189 & 189pc fastcopy form local storage
* fix(driver): fix 189 & 189pc fastcopy form local storage
* feat(driver): support 123 official app api
* fix(123_open): migrate api refresh to token.go
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/123_open): trigger proactive refresh with client credentials
* fix(drivers/123_open): use client-credential token endpoint for local refresh
Keep renewapi parsing for expires_in and map it to internal expiry time handling.
* fix(drivers/123_open): limit proactive refresh to client credentials
* fix(drivers/123_open): allow renewapi refresh token proactive init
* fix(drivers/123_open): update API address to use renewapi endpoint
* fix(drivers/123_open): simplify token refresh parsing
* fix(drivers/123_open): unify token expiration to expiredAt
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: Suyunmeng <Susus0175@proton.me>
Co-authored-by: Suyunjing <suyunmeng@oplist.org.cn>
- Switch default SQLite path to github.com/glebarez/sqlite to reduce CGO dependency pressure.
- Introduce a unified openSQLite entry in bootstrap and split driver selection by build tags.
- Add sqlite_cgo_compat fallback for linux mips, mips64, loong64 and mipsle to keep legacy target builds working.
- Update build.sh musl build flow to apply compatibility tag for mips-family targets.
- Update beta_release workflow to pass compatibility tag cleanly and avoid conflicting flag composition.
* refactor(permission): rename permission check functions for clarity
- User.CanWrite() → User.CanCreateFilesOrFolders()
- common.CanWrite() → common.CanWriteContentBypassUserPerms()
- common.IsApply() → common.MetaCoversPath()
Improves code readability by making function names more descriptive.
The new MetaCoversPath name clearly indicates it checks if a meta rule
covers a specific path. It better conveys that it's a query function
rather than an action, and the applyToSubFolder parameter is more
explicit than applySub.
Also adds comprehensive test coverage:
- 10 tests for MetaCoversPath core logic
- 6 tests for CanWriteContent
UserPerms
- 7 tests for getReadme
- 5 tests for getHeader
- 6 tests for isEncrypt
- 9 tests for whetherHide
Total: 43 test scenarios covering all path matching and permission
inheritance logic. Tests verify both normal behavior and bug fixes
for Readme/Header information leakage and write permission bypass.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* feat(permission): implement fine-grained user permissions for read/write operations
Add per-user read and write permission controls at the meta level to enable
more granular access control beyond the existing permission flags.
Key changes:
- Add ReadUsers/WriteUsers fields to Meta model with sub-directory inheritance flags
- Implement CanRead and CanWrite permission check functions in server/common
- Filter file list results based on user read permissions
- Add permission checks across all file operations (FTP, HTTP handlers, WebDAV)
- Simplify error handling pattern for MetaNotFound errors throughout codebase
This allows administrators to restrict specific users from accessing or modifying
certain paths, providing finer control over file system permissions.
Note: Batch and recursive operations (FsMove, FsCopy, FsRemove, FsRecursiveMove,
FsBatchRename, FsRegexRename) currently check parent directory permissions only.
Individual item permission checks are not performed for performance reasons.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* test(permission): add comprehensive tests for CanRead, CanWrite, and combined permission checks
Add TestCanRead, TestCanWrite, TestCanAccessWithReadPermissions, and
TestWritePermissionCombinations to validate the three-layer permission
system including nil user/meta, sub-path inheritance, user whitelists,
and root-level restrictions.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(webdav): use safe type assertion for MetaPassKey to prevent panic
Bearer-token and OPTIONS auth paths do not set MetaPassKey in context,
causing a panic when handlers perform a forced type assertion on nil.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(permission): treat nil user as system context in CanRead/CanWrite
Previously, CanRead/CanWrite returned false for nil user, causing
filterReadableObjs to return an empty list when fs.List is called from
internal contexts without a user (e.g. context.Background()). A nil user
represents an internal/system call and should bypass per-user restrictions,
consistent with how whetherHide already handles nil user.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(fsmanage): prevent path traversal in FsRemove
The previous check only skipped names that resolved to "/", but did not
prevent traversal to sibling directories (e.g. "../secret"), which could
bypass the CanWrite permission check that is only applied to req.Dir.
Replace with a post-join prefix check to ensure each resolved path stays
within reqPath.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(webdav): align MetaPassKey behavior with FTP auth logic
For guest users, the WebDAV password input serves as the meta folder
password (consistent with FTP anonymous/guest handling). For authenticated
users, MetaPassKey is set to empty string since their login password is
not the meta folder password.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(permission): require write auth for fs list refresh
* refactor(permission): use MetaCoversPath in CanRead/CanWrite for consistency
Replace inline `(Sub || meta.Path == path)` logic with MetaCoversPath,
consistent with CanWriteContentBypassUserPerms. Also fix a copy-paste
error in the CanWrite comment (read → write).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
In BeginAuthnRegistration (webauthn.go), missing return statements after
error responses caused the function to continue executing with a nil
authnInstance, potentially leading to a nil pointer panic.
In OIDCLoginCallback and SSOLoginCallback (ssologin.go), missing return
statements after GenerateToken/autoRegister errors caused the handler to
send a second response, resulting in a superfluous response write.
In SetThunderBrowser (offline_download.go), the default case of the
storage type switch sent an error response but did not return, causing
SaveSettingItems and tool initialization to continue executing even when
driver type validation failed.
* fix(115_share): add user agent support and update driver dependency
* fix(115): fix download error
* feat: add thumbnail support for 115 driver and 115 share
- Add Thumb() method to FileObj in 115 driver to return thumbnail URL
- Add ThumbURL field to FileObj struct in 115 share utility
- Update 115driver dependency from v1.2.2 to v1.2.3 to support thumbnail functionality
- Implement Thumb() method for 115 share FileObj to return thumbnail URL
* fix(FsRemove): add validation for empty items in delete file list
If Req.Names contains an empty string item, the whole directory will be removed. As a result we need add a simple guard to prevent such cases.
Signed-off-by: huyuantao <huyuantao@ultrarisc.com>
* fix(FsRemove): enhance validation to prevent unintended directory deletion
1. Use `utils.FixAndCleanPath` to correctly identify and block invalid names.
2. Change error handling from `return` to `continue`.
Signed-off-by: huyuantao <huyuantao@ultrarisc.com>
---------
Signed-off-by: huyuantao <huyuantao@ultrarisc.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
* fix(driver/seafile): object not found when RootFolderPath != "/"
* refactor(seafile): restructure Seafile driver for improved library handling and error management
* add IsDir method to LibraryInfo type
* improve initialization
* add repoID to RepoItemResp and update List method to set repoID
---------
Co-authored-by: Khoray <hhkorm@gmail.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
* fix(FileTransferTask): skip copying if destination directory does not exist
* pass only object not found error
---------
Co-authored-by: cyk <dr_arc@163.com>
Co-authored-by: KirCute <951206789@qq.com>
* Remove the `OnlyProxy` restriction and obtain the redirected link to support 302
* Add `driver.Config` `PreferProxy` to recommend user to enable the proxy by default
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* feat(drivers): support getting disk usage of some drivers
* feat(drivers/degoo): implement GetDetails
* fix(fs/storage-details): fill used space rather than free space
* fix mega
* fix bsize type
* feat(driver): add wps drive support
* feat(driver): add wps drive support
* fix(wps): update personal mode string to English
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): remove trailing slash from drive origin URL
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): correct order of options in mode selection
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): enable local sort and upload overwrite
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(wps): resolve put bugs, fix file op problems and optimize list logic
- Fix uploading bugs. Support all uploading methods based on 8825.85d3c864.js
- Fix issues in delete/copy/move while opearting big folders.
- Use cache to optimize performance of list, especially in a deep path.
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
* refactor(bootstrap): move booting to bootstrap package
* chore(log): reduce level of some callings of `utils.Log.Fatal`
* fix(s3): no shutdown after SIGTERM received
* fix: add handle hook
* feat(fs): Support customizing the cache time for a specific path
* feat(fs): Get the cache rule for driver information.
* feat(fs): Support globbing.
* feat(fs): Add log.
---------
Signed-off-by: ShenLin <773933146@qq.com>
Co-authored-by: ShenLin <773933146@qq.com>
refactor!(userAgent): merge all userAgent into base
1. change var to const
2. remove duplicated ua definetion after original Resty R
3. upgrade Chrome and OS versions
* fix(mediafire): enable automatic session token acquisition and fix gzip parsing
- Fix Init() method to allow automatic session token retrieval from cookie
- Change SessionToken from required to optional in configuration
- Add proper gzip decompression support for API responses
- Improve error handling for session token acquisition failures
- Update help text to clarify authentication requirements
Resolves initialization failure and JSON parsing errors when session token
can be automatically obtained from browser cookie.
* fix(mediafire): ensure driver files end with newline
* chore: gofmt drivers/mediafire/*.go
* Add task queue for Meilisearch to prevent race conditions
- Implement TaskQueueManager for async index operations
- Queue update tasks and process them in batches every 30 seconds
- Check pending task status before executing new operations
- Optimize batch indexing and deletion logic
- Fix type assertion bug in buildSearchDocumentFromResults
* fix(search): re-enqueue skipped tasks to prevent task loss
When tasks are skipped due to pending dependencies, they are now
re-enqueued if not already in queue. This prevents task loss while
avoiding overwriting newer snapshots for the same parent.
* fix(copilot-comment): Invoke Stop() & err of SliceConvert
---------
Co-authored-by: ImoutoHeaven <noreply@imoutoheaven.org>
Co-authored-by: jyxjjj <773933146@qq.com>
* fix(driver/123): initialization the Platform field
Signed-off-by: MoYan <1561515308@qq.com>
* Fix formatting of Platform field in Pan123
Signed-off-by: MoYan <1561515308@qq.com>
---------
Signed-off-by: MoYan <1561515308@qq.com>
* fix(strm): non-specified type generates strm
* fix(strm): only insert to strmTrie if SaveStrmToLocal is enabled
* fix(strm): update suffix handling in convert2strmObjs function
* fix(strm): refactor generateStrm to use range reader
---------
Co-authored-by: j2rong4cn <j2rong@qq.com>
* refactor(stream): simplify Close method and update SeekableStream to use RangeReader interface
* refactor(stream): improve RangeRead comments for clarity
* fix(baidu_netdisk): improve upload experience
* fix(typo): URL should be uppercase, apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: ShenLin <773933146@qq.com>
* fix(typo): URL should be uppercase, apply suggestion from @Copilot
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: ShenLin <773933146@qq.com>
* fix(baidu_netdisk): use "UploadAPI" as a fallback when using dynamic upload api
* fix(baidu_netdisk): all uploads share the same upload url cache
* fix(drivers/baidu_netdisk): defer uploadUrlMu unlock
* update driver.go to main
---------
Signed-off-by: ShenLin <773933146@qq.com>
Signed-off-by: jenfonro <799170122@qq.com>
Co-authored-by: ShenLin <773933146@qq.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: jenfonro <799170122@qq.com>
* perf(stream): optimize CacheFullAndWriter for better memory management
* fix(stream): ensure proper seek handling in CacheFullAndWriter for improved data integrity
* support proxy
* debug
* debug2
* del debug
* add proxy configuration with env var fallback
* comments to en
* refactor(env): fallback env
---------
Co-authored-by: jyxjjj <773933146@qq.com>
* feat(drivers/123): Allow modification of the platform field
* feat(drivers/123): Set login platfrom as web
* fix(drivers/123): update platform field help value
* feat(drivers): add ProtonDrive driver
- Implement complete ProtonDrive storage driver with end-to-end encryption support
- Add authentication via username/password with credential caching and reusable login
- Support all core operations: List, Link, Put, Copy, Move, Remove, Rename, MakeDir
- Include encrypted file operations with PGP key management and node passphrase handling
- Add temporary HTTP server for secure file downloads with range request support
- Support media streaming using temp server range requests
- Implement progress tracking for uploads and downloads
- Support directory operations with circular move detection
- Add proper error handling and panic recovery for external library integration
- Support buffered upload for specific sequential and encrypted, but optimized transmission.
* Update drivers/proton_drive/util.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: D@' 3z K!7 <99719341+Da3zKi7@users.noreply.github.com>
* chore
* feat(drivers): enhance ProtonDrive temp server
- Implement separate listen and public port configuration for complex network deployments
- Add intelligent port detection with 8080 as preferred default, fallback to auto-assignment
- Support Container/NAT/VM environments through configurable external host and port mapping
- Add port availability validation with graceful fallback to listen port
- Enable users to specify external domain/IP for client connections (e.g., 192.168.1.5)
- Follow FTP server configuration patterns for network flexibility
- Maintain localhost development simplicity while supporting production deployments
* feat(proton_drive): refactor directory handling and improve link retrieval
* fix(proton_drive): add NoLinkURL configuration option
* fix(proton_drive): update file size retrieval and enforce TwoFACode requirement
* feat(proton_drive): add expiration to link response
* fix(proton_drive): handle empty RootFolderID in Init method
* fix(proton_drive): update credential handling to use email and reusable login
* fix(proton_drive): update credential handling to use reusableCredential variable
* fix(proton_drive): update DirectRename to use GetLink for source object retrieval
* fix(proton_drive): refactor uploadFile to return model.Obj and handle errors correctly
* fix(proton_drive): refactor DirectMove to use getLink for source retrieval and simplify destination handling
* fix(proton_drive): simplify Copy method by removing temporary file creation and directly using FileStream
* refactor(proton_drive): remove unused temporary server and related code
* chore
* fix(proton_drive): fix driver
- Handle fresh login if ProtonDrive rejects AccessToken or RefreshToken
- Update stored credentials
* fix(proton_drive): simplify reusable login handling in Init method
* fix(proton_drive): fix driver
- Update stored credentials, now is failing
* feat(proton_drive): improve authentication handling and remove unused variables
* fix(proton_drive): fix driver
- Update stored credentials, now is failing
* fix(proton_drive): improve authentication handling
* refactor(proton_drive): move client initialization to initClient method
* feat(proton_drive): move addrs and addrKRs
* feat(proton_drive): optimize upload threads
- Change ConcurrentBlockUploadCount to user configured upload threads number
- Comment ConcurrentFileCryptoCount, default is runtime.GOMAXPROCS(0)
---------
Signed-off-by: D@' 3z K!7 <99719341+Da3zKi7@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: KirCute <951206789@qq.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: KirCute <kircute@foxmail.com>
* 新增清真云Open驱动,支持最新的轻量SDK
* Change Go version in go.mod
Downgrade Go version from 1.24.2 to 1.23.4
Signed-off-by: zzzhr1990 <zzzhr@hotmail.com>
* Apply suggestions from code review
* Removed unnecessary comments
* Downgraded the Go version to 1.23.4.
* Not sure whether FileStream supports concurrent read and write operations, so currently using single-threaded upload to ensure safety.
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: zzzhr1990 <zzzhr@hotmail.com>
* feat(halalcloud_open): support disk usage
* Set useSingleUpload to true for upload safety
Not sure whether FileStream supports concurrent read and write operations, so currently using single-threaded upload to ensure safety.
Signed-off-by: zzzhr1990 <zzzhr@hotmail.com>
* Update meta.go
Change required for RefreshToken, If using a personal API approach, the RefreshToken is not required.
Signed-off-by: zzzhr1990 <zzzhr@hotmail.com>
* remove debug logs
* bump halalcloud SDK version
* fix unnecessary params
* Update drivers/halalcloud_open/driver_init.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: zzzhr1990 <zzzhr@hotmail.com>
* Fixed spelling errors; changed hardcoded retry parameters to constants.
* remove pointer in get link function in utils.go
---------
Signed-off-by: zzzhr1990 <zzzhr@hotmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: KirCute <951206789@qq.com>
* feat(http3|quic): add http3|quic support
* revert(ai): fix ai error
* fix(shutdown): shutdown was using close
* feat(http3|quic): add config if needs h3
* feat(http3|quic): add Alt-Svc to expose h3
* feat(pikpak): support disk usage
* fix(alias): cannot list with details
* refactor: rename `NewDiskUsageFromUsedAndTotal`
* fix(disk-usage): get details of storages that is not initialized
* fix(ftp-server): cannot get obj in uploading state inconsistency window
* fix
* fix: duplicate obj when upload completed but client access does not
* fix
* feat: support stat remove and move
* chore(announcement): change default announcement text for better clarity
- Improve site announcement style for a more polished look
- Adjust default value to avoid unclear meaning with only repo or single link
* feat(style): add driver icons and disk usage
* feat(driver): add disk usage for 115_open, 123_open, aliyundrive_open and baidu_netdisk
* feat(driver): add disk usage for crypt, sftp and smb
* chore: clean unused variable
* feat(driver): add disk usage for cloudreve_v4
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(local): disk label check when getting disk usage
* feat(style): return details when accessing the manage page
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
### Key Changes
- **189PC**: Add QR code login and refresh token support
- **189TV**: Add session refresh mechanism and fix TempUuid persistence issue
- **Both**: Implement session keep-alive with cron jobs (5min interval)
### Features
- QR code authentication for 189PC as alternative to password login
- Automatic token refresh to avoid frequent re-authentication
- Session keep-alive to maintain long-term connections
- Retry logic with max attempts to prevent infinite loops
### Fixes
- Fixed 189TV TempUuid causing storage corruption on QR code reload
- Enhanced error handling for token expiration scenarios
* feat(drivers): add cnb_releases
* feat(cnb_release): implement reference
* refactor(cnb_releases): get release info by ID instead of tag name
* feat(cnb_releases): add option to use tag name instead of release name
* fix(cnb_releases): set default root and improve release info retrieval
* feat(cnb_releases): implement Put
* perf(cnb_release): use io.Pipe to stream file upload
* perf(cnb_releases): add context timeout for file upload request
* feat(cnb_releases): implement Remove
* feat(cnb_releases): implement MakeDir
* feat(cnb_releases): implement Rename
* feat(cnb_releases): require repo and token in Addition
* chore(cnb_releases): remove unused code
* Revert 'perf(cnb_release): use io.Pipe to stream file upload'
* perf(cnb_releases): optimize upload with MultiReader
* feat(cnb_releases): add DefaultBranch
---------
Co-authored-by: ILoveScratch <ilovescratch@foxmail.com>
* fix(123open): correct query parameter name from 'fileId' to 'fileID' in getDirectLink function
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(123open): change SpaceTempExpr type from 'string' to 'int64' in UserInfoResp struct
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(123open): comment out unused fields in UserInfoResp struct
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(123open): add getUID method and cache UID
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(189tv): use rate-limited upload stream in OldUpload function
* fix(189tv): wrap tempFile with io.NopCloser to prevent premature closure in OldUpload function
* .
https://github.com/tgdrive/teldrivehttps://teldrive-docs.pages.dev/docs/api
实现:
* copy
* move
* link (302 share and local proxy)
* chunked uploads
* rename
未实现:
- openlist扫码登陆
- refresh token
https://github.com/OpenListTeam/OpenList-Docs/pull/155
* feat(Teldrive): Add driver Teldrive
* fix(teldrive): force webproxy and memory optimized
* chore(teldrive): go fmt
* chore(teldrive): remove TODO
* chore(teldrive): organize code
* feat(teldrive): add UseShareLink option and support 302
* fix(teldrive): standardize API path construction
* fix(teldrive): trim trailing slash from Address in Init method
* chore(teldrive): update help text for UseShareLink field in Addition struct
* fix(teldrive): set 10 MiB as default chunk size
---------
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: ILoveScratch <ilovescratch@foxmail.com>
* Fix incorrect path error during upload on Dropbox
* Add RootNamespaceId to the config for direct modification
* Refactor Dropbox header logic: extract JSON marshaling into helper method
* Fix Dropbox: replace marshalToJSONString with utils.Json.MarshalToString
* feat(config): Add PWA manifest.json endpoint for web app installation
* fix: Update comment to English in manifest handler
* fix: fix EOL
* fix: Remove unused fmt import from manifest handler
* feat: use site settings for manifest name and icon
* fix(manifest): Move manifest.json route to static handler for proper CDN handling
* feat: move manifest.json handler to static package and improve path handling
* feat: Add custom static file handler to prevent manifest.json conflicts
* fix: Integrate manifest.json handling into static file serving routes
* fix: Simplify PWA manifest scope handling and static file serving
- Remove CDN-specific logic for PWA manifest scope and start_url
- Always use base path for PWA scope regardless of CDN configuration
- Replace manual file serving logic with http.FileServer for static assets
* fix: Ensure consistent base path handling in site configuration and manifest path construction
* fix: Refactor trailing slash handling in site configuration
* feat(static): update manifest path handling and add route for manifest.json
* feat(driver_strm): Also shown some files with strm
Allow user set some file types that need to shown with strm, usually subtitles
Most of code was copy and managed from drivers/alias
* 优化
* 优化
* 。
* 添加注释
---------
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
* feat(search): enhanced `meilisearch` search experience
- upgrade `meilisearch` dependency
- support subdirectory search
- optimize searchDocument fields for subdirectory search
- specify full index uid instead of index prefix
* fix(search): more fixes to `meilisearch`
- make use of context where context was not used
- remove code of waiting task in deletion process, as tasks are queued and will be executed orderly (if tasks were submitted to the queue successfully), which can improve `AutoUpdate` performance
- In doubao/types.go:
- Change LastUpdateTime from int to int64
- Change UserCreateTime from int to int64
- In doubao_share/types.go:
- Change CreateTime and UpdateTime from int to int64 in ShareInfo and FilePath
- In quark_uc/types.go:
- Change UpdateTime from int to int64 in TranscodingResp
These changes ensure consistent and accurate representation of timestamp data across the project.
* feat(setting): add site version information
* feat(conf): update conf.WebVersion to rolling
* fix(static): update condition to check conf.Version instead of conf.WebVersion
* fix(build.sh): use rolling release for web frontend in dev and beta builds
* chore(build.sh): update GitAuthor to The OpenList Projects Contributors
* fix(static): update condition to check conf.WebVersion
* feat:Add Windows 7 and LoongArch old world build support (#30)
* feat:Add Windows 7 and Loongson old world build support
- Add BuildWin7() function with patched Go compiler for Windows 7 compatibility
- Add BuildLoongOldWorld() function for linux-loong64-abi1.0 target
- Create Zig-based wrapper scripts for Windows 7 cross-compilation
- Integrate new build functions into existing release workflows
* fix(win7):Add MinGW-w64 toolchain and improve LoongArch ABI isolation
- Install MinGW-w64 cross-compilation toolchain for Win7 compatibility
- Replace Zig compiler wrappers with MinGW-w64 for Windows 7 builds
- Add Go build cache cleaning to prevent LoongArch ABI1.0/ABI2.0 cross-contamination
- Force clean rebuilds (-a flag) for LoongArch builds to ensure ABI compatibility
* feat: add Windows 7 build support to beta release workflow
* feat: add LoongArch ABI2.0 support alongside existing ABI1.0 build (#31)
- Add BuildWin7() function with patched Go compiler for Windows 7 compatibility
- Add BuildLoongOldWorld() function for linux-loong64-abi1.0 target
- Create Zig-based wrapper scripts for Windows 7 cross-compilation
- Integrate new build functions into existing release workflows
- Install MinGW-w64 cross-compilation toolchain for Win7 compatibility
- Replace Zig compiler wrappers with MinGW-w64 for Windows 7 builds
- Add Go build cache cleaning to prevent LoongArch ABI1.0/ABI2.0 cross-contamination
- Force clean rebuilds (-a flag) for LoongArch builds to ensure ABI compatibility
* [skip ci]refactor:Refactor LoongArch builds to separate glibc from musl compilation
* fix(go-cache):Improve error handling for Go module cache cleaning in LoongArch builds
* feat(build): Enhance LoongArch build process with improved toolchain setup and cache management
* fix(build): Update Windows 7 target naming in build scripts and workflows
* refactor(build): Replace MinGW-w64 with Zig for Windows 7 toolchain in build scripts
* chore(cgo): remove cgo-actions subproject
* feat(log):Add configurable log filtering middleware for HTTP requests
Implement a comprehensive log filtering system that allows selective suppression of HTTP request logs based on paths, methods, and prefixes. The system includes environment variable configuration support and filters health checks, WebDAV requests, and HEAD requests by default to reduce log noise.
* fix(log):Replace gin.DefaultLogFormatter with custom implementation
* Remove filtered logger test file
* fix(log):Refactor log filtering to use centralized configuration and add server-specific filtering
* fix(log):Add documentation comments for log filtering configuration
* feat(log):Add configurable log filtering middleware for HTTP requests
Implement a comprehensive log filtering system that allows selective suppression of HTTP request logs based on paths, methods, and prefixes. The system includes environment variable configuration support and filters health checks, WebDAV requests, and HEAD requests by default to reduce log noise.
* refactor(static): simplify folder iteration in Static function
* feat(static): disable local static when `cdn` is set
* feat(static): fetch index.html from cdn for beta
* refactor(static): use RestyClient for better retrying
* fix(static): add Accept header when fetching index.html from CDN
* refactor(static): optimize HTML replacement
* chore(static): add logging to static file system initialization
* feat(static): ensure static file redirected to CDN
* fix(fs): ensure accurate content-length in http2 requests
Chrome browsers were unable to preview thumbnails, reporting an
'ERR_HTTP_2_PROTOCOL_ERROR'. This was caused by an incorrect
content-length header in the server's response for thumbnail images.
This commit corrects the content-length calculation, allowing
Chrome and other compliant clients to render thumbnails correctly.
* fix(net): ensure accurate content-length in response
* 补缺
* .
---------
Co-authored-by: zhiqiang.huang <zhiqiang.tech@gmail.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Update PR title validation and feedback messages
Improves the PR title regex to be non-greedy and adds 'chore' to the allowed prefixes. Enhances feedback comments with clearer instructions in both Chinese and English, including guidance for PRs spanning multiple components.
style: Remove the line break of the img tag in readme to avoid GitHub's incorrect rendering of the blue underline
Co-authored-by: ShenLin <773933146@qq.com>
* add lite version
* fixed lite ci
* test
* fixed lite version
* fixed release build md5 and tar
* fixed lite
* fixed release ci
* fixed ci secrets
* fixed ci
* fixed ci
* fixed docker ci
* fixed docker ci
* fixed ci
* fixed docker ci
* fixed docker ci
* fixed docker ci
* ci:delete lite in beta version
* feat(ci):Add Lite Version Build
* Fixed Beta version Docker
* Fixed Web Lite
* fixed EOL
* fixed EOL
---------
Co-authored-by: Sumengjing <146963948+suyunjing-su@users.noreply.github.com>
* chore(issue): Update issue templates with improved descriptions and links
Enhanced bug and feature request templates with bilingual descriptions, default titles, and updated documentation links. Added new contact options in config.yml, including a Telegram chat link. Improved clarity and localization for user instructions.
* split
* zh
* test preview
* en
* fix temp preview error
* one line and multiple reproduction links
* fix en
* Revert "fix en"
This reverts commit b3cb48afb4.
* Revert "one line and multiple reproduction links"
This reverts commit cd09ef0d15.
* split fr
* fix temp preview error
* consistency
* fr
* reorder
* split
* fix dup
* consistency
* again due to ai: fix temp preview error
* summary
Enhanced bug and feature request templates with bilingual descriptions, default titles, and updated documentation links. Added new contact options in config.yml, including a Telegram chat link. Improved clarity and localization for user instructions.
- Change PDF.js viewer URL from protocol-relative to HTTPS and updates parameter from "url" to "file" for proper document loading
- Also standardize EPUB.js viewer to use HTTPS protocol for consistency
* Add Official API Refresh Interface(Baiduyun)
* add UseOnlineAPI & APIAddress
add _refreshToken using APIAddress
* fix return
* Modify the frontend display using the default API refresh method
* Fixed display and operation related issues
* fixed aliyundrive_open old refresh
---------
Co-authored-by: Suyunmeng <sumengjing@outlook.com>
Mega supports duplicate names but alist does not support.
In `List()` method, driver will return multiple files with same name.
That makes alist to use oldest version file for listing/downloading.
So it is necessary to filter old same name files in a folder.
After fixes, all CRUD work normally.
Refs #8344
* feat(local): support percent for video thumbnail
The percentage determines the point in the video (as a percentage of the total duration) at which the thumbnail will be generated.
* feat(local): support both time and percent for video thumbnail
* refactor(local): avoid duplicate parsing of VideoThumbPos
* feat(lanzou): add RemoveJSComment function to clean JavaScript comments from HTML
* feat(lanzou): remove comments from share page data in getFilesByShareUrl function
* fix(lanzou): optimize RemoveJSComment function to improve comment removal logic
* fix(aliyundrive_open): resolve file duplication issues and improve path handling
1. Fix file duplication by implementing a new removeDuplicateFiles method that cleans up duplicate files after operations
2. Change Move operation to use "ignore" for check_name_mode instead of "refuse" to allow moves when destination has same filename
3. Set Copy operation to handle duplicates by removing them after successful copy
4. Improve path handling for all file operations (Move, Rename, Put, MakeDir) by properly maintaining the full path of objects
5. Implement GetRoot interface for proper root object initialization with correct path
6. Add proper path management in List operation to ensure objects have correct paths
7. Fix path handling in error cases and improve logging of failures
* refactor(aliyundrive_open): change error logging to warnings for duplicate file removal
Updated the Move, Rename, and Copy methods to log warnings instead of errors when duplicate file removal fails, as the primary operations have already completed successfully. This improves the clarity of logs without affecting the functionality.
* Update drivers/aliyundrive_open/util.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix: potential XSS vulnerabilities
* feat: support filter and render for readme.md
* chore: set ReadMeAutoRender to true
* fix attachFileName undefined
---------
Co-authored-by: Andy Hsu <i@nn.ci>
* refactor(cmd): use std `runtime` package to get go version info
- Remove the `GoVersion` variable.
- Remove overriding `GoVersion` by ldflags in `build.sh`.
- Get go version, OS and arch from the constants in the std `runtime` package instead of compile time.
* chore(ci): remove `GoVersion` flag from workflows
Remove GoVersion flag from beta_release.yml and build.yml workflows.
> Reduce compile-time dependencies.
* fix(driver): additionally implement canceling and updating progress for putting for some drivers
* refactor: add driver archive api into template
* fix(123): use built-in MD5 to avoid caching full
* .
* fix build failed
* fix(archive): unrecognition zip
* feat(archive): add tree for zip meta
* fix bug
* refactor(archive): meta cache time use Link Expiration first
* feat(archive): return sort policy in meta (#2)
* refactor
* perf(archive): reduce new network requests
---------
Co-authored-by: KirCute_ECT <951206789@qq.com>
* Feat(offline-download): allow using thunder offline download tool in any storage
* Feat(offline-download): allow using 115 offline download tool in any storage
* Feat(offline-download): allow using pikpak offline download tool in any storage
* style(offline-download): unify offline download tool names
* feat(offline-download): show available offline download tools only
* Fix(offline-download): update unmodified tool names.
---------
Co-authored-by: Andy Hsu <i@nn.ci>
* feat(github): add github api driver
* fix: filter submodule operation
* feat: rename, copy and move, but with bugs
* fix: move and copy returns 422
* fix: change TargetPath in rename msg from parent path to new self path
* fix: add non-commit mutex
* pref(github): use net/http to put blob
* chore: add a help message to `ref` addition
* feat(local): support percent for video thumbnail
The percentage determines the point in the video (as a percentage of the total duration) at which the thumbnail will be generated.
* feat(local): support both time and percent for video thumbnail
* build: add argument INSTALL_ARIA2 to dockerfile
* feat: run aria2 in main entrypoint
* feat(ci): environment matrix for docker release
* improve(ci): allow overwrite artifacts in docker release
* fix(ci): permission of alist binary in docker; entrypoint logic
* improve(aria2): move aria2 data to /opt/aria2; fix permission issues
References:
https://github.com/AlistGo/with_aria2/pull/13
Co-authored-by: GoodbyeNJN <cc@fuckwall.cc>
* fix(ci): aio image is not taking effect
* fix(build): tar command in aria2 installation process
(cherry picked from commit 647285408354807bae64df6a20fefb696ff787de)
---------
Co-authored-by: GoodbyeNJN <cc@fuckwall.cc>
* feat(patch): upgrade patch module
* chore(patch): add docs
* fix(patch): skip and rewrite invalid last launched version
* fix(patch): turn two functions into patches
* fix(ftp-server): client timeout to wait a large file upload to netdisk
* fix(ftp-server): driver alist v3 upload failed and temp files do not be deleted
* fix(139): update family cloud API
* fix(139): update API of familyGetLink
* feat(139): support group (close#7603)
* docs: add `139 group` to Readme
* feat(139): support multipart upload (close: #7444)
* feat(139): add custom upload part size option
* fix: missing right big quote
---------
Co-authored-by: Andy Hsu <i@nn.ci>
- Add support for remote and OneDrive storage types
- Implement new upload methods for different storage types
- Update driver to handle various storage policies
- Add error handling and session cleanup for failed uploads
* feat: support general users view and cancel own tasks
Add a creator attribute to the upload, copy and offline download
tasks, so that a GENERAL task creator can view and cancel them.
BREAKING CHANGE:
1. A new internal package `task` including the struct `TaskWithCreator`
which embeds `tache.Base` is created, and the past dependence on
`tache.Task` will all be transferred to dependence on this package.
2. The API `/admin/task` can now also be accessed via `/task`, and the
old endpoint is retained to ensure compatibility with legacy
automation scripts.
Closes#7398
* fix(deps): update github.com/xhofe/tache to v0.1.3
* add my_build.sh
* Fix OOM of thumbnail generation of LoaclDrive by using a task queue to control thread count
* remove my_build.sh
* chore(local): allow ThumbConcurrency set to zero
* revert(local): changes to thumbnail generating functions
* feat(local): implement static token bucket
* feat(local): use static token bucket to limit thumbnails generating concurrent
---------
Co-authored-by: KKJas <75424880+Muione@users.noreply.github.com>
- eliminating fixed 200 ms delay in getFiles to prevent thread starvation
- allowing cancellation via context to mitigate potential DoS attacks by immediately cancelling excessive requests
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: David Hao <akang943578@gmail.com>
Co-authored-by: Ke Wang <me@ke.wang>
* Fix: when S3 PutObject with objectName contains /, aliyundriveopen failed due to KeyNotFound, make dir to fix this.
(cherry picked from commit eb24f45771d29a3659e75813734b290d6306cfcf)
* Upgrade gofakes3 to v0.0.5, support AWS Signature V2
(cherry picked from commit 3218d7cf2c4e1a8c51fd2414595547fd109a89ac)
---------
Co-authored-by: David Hao <akang943578@gmail.com>
* add pikpak offline download function
* 完善PikPak离线下载功能
* 删除多余的代码
* add task cache to avoid too many requests about API
* 优化Status函数
* 完善所有功能,目前测试无BUG
* 减少缓存时间,优化添加离线任务的参数
* fix(drivers/iLanZou): resolve resource access issue on iLanZou driver mount
The driver failed to mount due to incorrect URL parameter ordering which the backend did not accept
This commit reorders the parameters to meet the backend's expectations
and ensures successful mounting of the iLanZou driver.
Closes#6271, Closes#6415
* fix(drivers/iLanZou): Fixed the error ID number returned when creating a folder
Closes#6610, Closes#6333
---------
Co-authored-by: maye174 <96584640+maye174@users.noreply.github.com>
* feat(mega): add support for two-factor authentication in Mega driver #6226
* feat(mega): remove debug print statement in Mega driver Init function
* feat(mega): add help message for new field
* fix(115): Support 115 302 redirect while getting link under (nested) alist_v3 remote
* chore: simplify logic
* chore: simplify logic
* use internal UA
* add option to set if the user want their ua be passed to upstream
In TestGetStorageVirtualFilesByPath() and TestGetBalancedStorage(), setupStorages() was being called twice, leading to a "UNIQUE constraint failed" error.
* fix(search): the problem of not returning in time when index does not support auto update.
* fix(search): the problem of duplicate indexing of folders.
* fix(quqi): error returned when uploading a file that existed
* fix empty download link for no vip user
* fix cannot parse request result
---------
Co-authored-by: Andy Hsu <i@nn.ci>
* feat: add `quqi` driver
* change signature of request function
* specific header for every storage
* todo: real upload
* fix upload method
* fix incorrect parameters for some request function calls
* refine some form parameters to avoid potential problems
* fix file extension duplication in rename function
* improve the error message in login function
---------
Co-authored-by: Andy Hsu <i@nn.ci>
* feat: add `quqi` driver
* change signature of request function
* specific header for every storage
* todo: real upload
* fix upload method
* fix incorrect parameters for some request function calls
---------
Co-authored-by: Andy Hsu <i@nn.ci>
* fix(chaoxing):fix JSON parsing error in `content` field
* fix(chaoxing): optimizing `UnmarshalJSON` implementation
* fix(chaoxing): use `objectID` when is empty
* build: improve multistage docker build
* build: add dockerfile for ci
* build: add BuildDockerMultiplatform function in build.sh for ci
* ci: change build method
* build: add missing mod download command to the Dockerfile
* build: revert changes made ffmpeg installed
* build: use musl build for docker release
* ci: apply to dev version
* fix: don't login on pr
* fix: don't build_docker_with_aria2 on pr
---------
Co-authored-by: Andy Hsu <i@nn.ci>
* Add support for client-side discoverable in begin login
Use `(*webauthn.WebAuthn).BeginDiscoverableLogin()` to handle client-side discoverable login.
* Upgrade github.com/go-webauthn/webauthn to v0.10.0
Upgrade [go-webauthn/webauthn](github.com/go-webauthn/webauthn) library to latest.
The convenient finish login function (as FinishDiscoverableLogin) for discoverable functions has been added in the v0.9.0. [^1]
---
[^1]: https://github.com/go-webauthn/webauthn/releases/tag/v0.9.0
* Add support for client-side discoverable in validating login
Use `(*webauthn.WebAuthn).FinishDiscoverableLogin()` to handle client-side discoverable login.
> **NOTE**:
- The first param `rawID` in this callback function is unnecessary to check, it's handled by the third-party webauthn library later.
- `userHandle` param is equal to the ID returned by (User).WebAuthnID() function.
* fix:123 driver connect error
* feat: calculate sign with pure go
---------
Co-authored-by: tangminghao <tangminghao@hxzn.com>
Co-authored-by: Andy Hsu <i@nn.ci>
* fix(aliyundrive_open):Mitigation measures for AliOpen's 15-minute limit.
I conducted small-scale tests, which seem to have no significant negative impact. If the 15-minute issue still occurs, further measures will be needed. Methods like local proxy can be attempted.
* chore(aliyundrive_open): change cache of the link to 1 minute
---------
Co-authored-by: Andy Hsu <i@nn.ci>
This update introduces the ability to mount 115 share links.
Currently, only listing and downloading are supported. Note that login and share link are required for this feature to work.
Close#5384
general: add createTime/updateTime support in webdav and some drivers
general: add hash support in some drivers
general: cross-storage rapid-upload support
general: enhance upload to avoid local temp file if possible
general: replace readseekcloser with File interface to speed upstream operations
feat(aliyun_open): same as above
feat(crypt): add hack for 139cloud
Close#4934Close#4819
baidu_netdisk needs to improve the upload code to support rapid-upload
* feat: support webauthn login
* manually merge
* fix: clear user cache after updating authn
* decrease db size of Authn
* change authn type to text
* simplify code structure
---------
Co-authored-by: Andy Hsu <i@nn.ci>
general: enhance multi-thread downloader with cancelable context, immediately stop all stream processes when canceled;
feat(crypt): improve stream closing;
general: fix the bug of downloading files becomes previewing stream on modern browsers;
Co-authored-by: Sean He <866155+seanhe26@users.noreply.github.com>
Co-authored-by: Andy Hsu <i@nn.ci>
this PR has several enhancements, fixes, and features:
- [x] Crypt: a transparent encryption driver. Anyone can easily, and safely store encrypted data on the remote storage provider. Consider your data is safely stored in the safe, and the storage provider can only see the safe, but not your data.
- [x] Optional: compatible with [Rclone Crypt](https://rclone.org/crypt/). More ways to manipulate the encrypted data.
- [x] directory and filename encryption
- [x] server-side encryption mode (server encrypts & decrypts all data, all data flows thru the server)
- [x] obfuscate sensitive information internally
- [x] introduced a server memory-cached multi-thread downloader.
- [x] Driver: **Quark** enabled this feature, faster load in any single thread scenario. e.g. media player directly playing from the link, now it's faster.
- [x] general improvement on HTTP/WebDAV stream processing & header handling & response handling
- [x] Driver: **Mega** driver support ranged http header
- [x] Driver: **Quark** fix bug of not closing HTTP request to Quark server while user end has closed connection to alist
## Crypt, a transparent Encrypt/Decrypt Driver. (Rclone Crypt compatible)
e.g.
Crypt mount path -> /vault
Crypt remote path -> /ali/encrypted
Aliyun mount paht -> /ali
when the user uploads a.jpg to /vault, the data will be encrypted and saved to /ali/encrypted/xxxxx. And when the user wants to access a.jpg, it's automatically decrypted, and the user can do anything with it.
Since it's Rclone Crypt compatible, users can download /ali/encrypted/xxxxx and decrypt it with rclone crypt tool. Or the user can mount this folder using rclone, then mount the decrypted folder in Linux...
NB. Some breaking changes is made to make it follow global standard, e.g. processing the HTTP header properly.
close#4679close#4827
Co-authored-by: Sean He <866155+seanhe26@users.noreply.github.com>
Co-authored-by: Andy Hsu <i@nn.ci>
title:"[BUG] Please modify the title to describe the issue you are facing"
labels:[bug]
body:
- type:markdown
attributes:
value:|
Thank you for taking the time to fill out this bug report.
Please **make sure** your issue is not a duplicate and is not caused by your own operation, network, or third-party software.
- type:checkboxes
attributes:
label:Please confirm the following
description:|
You must read, check, confirm, and agree to all the following, otherwise your issue will definitely be closed directly.
Or you can go to the [discussions](https://github.com/OpenListTeam/OpenList/discussions).
options:
- label:|
I have read and agree to [AGPL-3.0 Section 15](https://www.gnu.org/licenses/agpl-3.0.txt#:~:text=15.%20Disclaimer%20of%20Warranty.) .
The program is provided "as is" without any warranties; you bear all risks of using it.
- label:|
I have read and agree to [AGPL-3.0 Section 16](https://www.gnu.org/licenses/agpl-3.0.txt#:~:text=16.%20Limitation%20of%20Liability.) .
The copyright holders and distributors are not liable for any damages resulting from the use or inability to use the program.
- label:|
I confirm my description is clear, polite, helps developers quickly locate the issue, and complies with community rules.
- label:|
I have read the [OpenList documentation](https://doc.oplist.org).
- label:|
I confirm there are no duplicate issues or discussions.
- label:|
I confirm this is an `OpenList` issue, not caused by other reasons (such as [network](https://doc.oplist.org/faq/howto#tls-handshake-timeout-read-connection-reset-by-peer-dns-lookup-failed-connect-connection-refused-client-timeout-exceeded-while-awaiting-headers-no-such-host-1), dependencies, or operation).
- label:|
I believe this issue must be handled by `OpenList` and not by a third party.
- label:|
I confirm this issue is not fixed in the latest version.
- label:|
I have not read these checkboxes and therefore I just ticked them all, Please close this issue.
- type:input
id:version
attributes:
label:OpenList Version (required)
description:|
What version of the software are you using? Please do not use `latest` or `master` as the answer.
placeholder:v4.xx.xx
validations:
required:true
- type:input
id:driver
attributes:
label:Storage Driver Used (required)
description:|
Which storage driver are you using?
placeholder:"e.g. OneDrive"
validations:
required:true
- type:textarea
id:bug-description
attributes:
label:Bug Description (required)
validations:
required:true
- type:textarea
id:logs
attributes:
label:Logs (required)
description:|
Please copy and paste any relevant log output or screenshots. (You may mask sensitive fields) [Guide](https://doc.oplist.org/faq/howto#how-to-quickly-locate-bugs)
validations:
required:true
- type:textarea
id:config
attributes:
label:Configuration File Content (required)
description:|
Please provide your `OpenList` application's configuration file and a screenshot of the relevant storage configuration. (You may mask sensitive fields)
validations:
required:true
- type:textarea
id:reproduction
attributes:
label:Reproduction Link (optional)
description:|
Please provide a link to a repo or page that can reproduce this issue.
- type:checkboxes
id:aigenerated
attributes:
label:AI Generated Content
description:Select exactly one option. Do not delete or modify the disclosure text.
options:
- label:I used AI tools to generate this content
- label:I did not use AI tools to generate this content
- type:input
id:ai-model
attributes:
label:AI model used
description:If you used AI tools, enter the model name; otherwise leave this blank.
Thanks for taking the time to fill out this bug report, please **confirm that your issue is not a duplicate issue and not because of your operation or version issues**
感谢您花时间填写此错误报告,请**务必确认您的issue不是重复的且不是因为您的操作或版本问题**
- type:checkboxes
attributes:
label:Please make sure of the following things
description:You may select more than one, even select all.
options:
- label:I have read the [documentation](https://alist.nn.ci).
- label:I'm sure there are no duplicate issues or discussions.
- label:I'm sure it's due to `alist` and not something else(such as `Dependencies` or `Operational`).
- label:I'm sure I'm using the latest version
- type:input
id:version
attributes:
label:Alist Version / Alist 版本
description:What version of our software are you running?
placeholder:v2.0.0
validations:
required:true
- type:input
id:driver
attributes:
label:Driver used / 使用的存储驱动
description:What storage driver are you using?
placeholder:"for example: Onedrive"
validations:
required:true
- type:textarea
id:bug-description
attributes:
label:Describe the bug / 问题描述
validations:
required:true
- type:textarea
id:reproduction
attributes:
label:Reproduction / 复现链接
description:|
Please provide a link to a repo that can reproduce the problem you ran into. Please be aware that your issue may be closed directly if you don't provide it.
Hello @${{ github.event.issue.user.login }}, this issue was closed due to inactive more than 52 days. You can reopen or recreate it if you think it should continue. Thank you for your contributions again.
⚠️ Please modify the title to better describe your issue or request, and remove the example prompt. This issue will be automatically closed and locked. If you wish to proceed, please create a new issue.
`;
} else if (confirmNotRead || !validAiDisclosure || missingAiModel) {
⚠️ Your issue does not comply with the submission rules. Please read the guidelines before submitting again. This issue will be automatically closed and locked. If you wish to proceed, please confirm that you have reviewed the rules before creating a new issue.
`;
} else if (/- \[ \] (?!我没有阅读这个清单|I have not read these checkboxes)/.test(issueBody.replace(aiSection[0], ''))) {
comment = `感谢您联系OpenList。我们会尽快回复您。
Thanks for contacting OpenList. We will reply to you as soon as possible.
Hello @${{ github.event.issue.user.login }}, please input issue by template and add detail. Issues labeled by `question` will be closed if no activities in 3 days.
⚠️ The PR title must start with \`feat(): \`, \`docs(): \`, \`fix(): \`, \`style(): \`, or \`refactor(): \`, \`chore(): \`. For example: \`feat(component): add new feature\`.
如果跨多个组件,请使用主要组件作为前缀,并在标题中枚举、描述中说明。
If it spans multiple components, use the main component as the prefix and enumerate in the title, describe in the body.
Before creating an issue, review the available issue templates in the `.github` directory.
When drafting the issue:
- Use the most appropriate template.
- Follow the template structure.
- Fill in all required sections.
- Remove sections that the template explicitly marks as optional or not applicable.
- Do not invent reproduction steps, logs, screenshots, or expected behavior.
## Pull Requests
Before creating a pull request, read `.github/PULL_REQUEST_TEMPLATE.md`.
When drafting the pull request:
- Follow the template structure.
- Use the title format required by the template.
- Fill in or remove each section according to the template guidance.
- Include testing details, or explain why testing was not run.
- Do not invent testing results.
- Do not claim validation, verification, or review steps that were not actually performed.
## Automated Contributions
Fully automated contributions are not considered equivalent to normal community participation.
A contribution may be considered fully automated if it is submitted through an automated agent, or if the submitting account participates in project discussions through an automated agent, without meaningful human review or intervention.
When making this determination, maintainers may consider the overall behavior of the account, including but not limited to disclosed agent usage, interaction patterns, response characteristics, and other available evidence. No single factor is determinative.
Maintainers reserve the right to accept, reject, modify, or reimplement any contribution independently of any action taken against the submitting account. Acceptance of a contribution does not imply acceptance of the submitting account or its contribution method. If an account is determined to be primarily operated through automated processes, we may need to restrict its future participation in contributions until that determination is rescinded.
## Git Commits
When creating commits, follow the repository `git-commit` skill rules:
- Use Conventional Commits title format: `type(scope): subject`.
You can use `*` when the change affects more than a single scope.
### Subject
The subject contains succinct description of the change:
* use the imperative, present tense: "change" not "changed" nor "changes"
* don't capitalize first letter
* no dot (.) at the end
### Body
Just as in the **subject**, use the imperative, present tense: "change" not "changed" nor "changes".
The body should include the motivation for the change and contrast this with previous behavior.
### Footer
The footer should contain any information about **Breaking Changes** and is also the place to
[reference GitHub issues that this commit closes](https://help.github.com/articles/closing-issues-via-commit-messages/).
**Breaking Changes** should start with the word `BREAKING CHANGE:` with a space or two newlines.
The rest of the commit message is then used for this.
It's suggested to sign your commits. See: [How to sign commits](https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits)
## Submit a pull request
Push your branch to your `alist`fork and open a pull request against the
`main` branch.
Please make sure your code has been formatted with `go fmt` or [prettier](https://prettier.io/) before submitting.
Push your branch to your `openlist` fork and open a pull request against the `main` branch.
## Merge your pull request
Your pull request will be merged after review. Please wait for the maintainer to merge your pull request after review.
At least 1 approving review is required by reviewers with write access. You can also request a review from maintainers.
## Delete your branch
(Optional) After your pull request is merged, you can delete your branch.
## AI Disclosure
If your pull request includes substantial AI-assisted content, disclose it in the PR description.
The pull request description must follow the repository's pull request template.
Fully automated contributions are not considered equivalent to normal community participation.
A contribution may be considered fully automated if it is submitted through an automated agent, or if the submitting account participates in project discussions through an automated agent, without meaningful human review or intervention.
When making this determination, maintainers may consider the overall behavior of the account, including but not limited to disclosed agent usage, interaction patterns, response characteristics, and other available evidence. No single factor is determinative.
Maintainers reserve the right to accept, reject, modify, or reimplement any contribution independently of any action taken against the submitting account. Acceptance of a contribution does not imply acceptance of the submitting account or its contribution method. If an account is determined to be primarily operated through automated processes, we may need to restrict its future participation in contributions until that determination is rescinded.
Please include:
- Tools used, such as ChatGPT, GitHub Copilot, Claude, Cursor, or other AI tools.
- Usage scope, such as code generation, refactoring, documentation, tests, translation, or review assistance.
- Confirmation that you have reviewed and validated all AI-assisted content before submission.
- Confirmation that the submitted content complies with this repository's license and contribution policies.
Minor AI assistance, such as typo fixes, autocomplete, formatting suggestions, or wording polish, does not need to be disclosed.
---
Thank you for your contribution! Let's make OpenList better together!
### Default image is base. You can add other support by modifying BASE_IMAGE_TAG. The following parameters are supported: base (default), aria2, ffmpeg, aio
ARGBASE_IMAGE_TAG=base
FROMalpine:edgeASbuilder
LABELstage=go-builder
WORKDIR/app/
RUN apk add --no-cache bash curl jq gcc git go musl-dev
COPY go.mod go.sum ./
RUN go mod download
COPY ./ ./
RUNapk add --no-cache bash curl gcc git go musl-dev;\
bash build.sh release docker
RUNbash build.sh release docker
FROMalpine:3.18
LABELMAINTAINER="i@nn.ci"
VOLUME/opt/alist/data/
WORKDIR/opt/alist/
COPY --from=builder /app/bin/alist ./
COPY entrypoint.sh /entrypoint.sh
RUN apk add --no-cache bash ca-certificates su-exec tzdata;\
<p><em>OpenList is a resilient, long-term governance, community-driven fork of AList — built to defend open source against trust-based attacks.</em></p>
OpenList is an open-source project independently maintained by the OpenList Team, following the AGPL-3.0 license and committed to maintaining complete code openness and modification transparency.
We have noticed the emergence of some third-party projects in the community with names similar to this project, such as OpenListApp/OpenListApp, as well as some paid proprietary software using the same or similar naming. To avoid user confusion, we hereby declare:
- OpenList has no official association with any third-party derivative projects.
- All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.
- Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments, and the use of existing features does not involve any costs.
We respect the community's rights to free use and derivative development, but we also strongly urge downstream projects:
- Should not use the "OpenList" name for impersonation promotion or commercial gain;
- Must not distribute OpenList-based code in a closed-source manner or violate AGPL license terms.
To better maintain healthy ecosystem development, we recommend:
- Clearly indicate the project source and choose appropriate open-source licenses in accordance with the open-source spirit;
- If involving commercial use, please avoid using "OpenList" or any confusing naming as the project name;
- If you need to use materials located under OpenListTeam/Logo, you may modify and use them under compliance with the agreement.
Thank you for your support and understanding of the OpenList project.
Please go to our [discussion forum](https://github.com/Xhofe/alist/discussions) for general questions, **issues are for bug reports and feature request only.**
Please refer to [*Discussions*](https://github.com/OpenListTeam/OpenList/discussions) for raising general questions, ***Issues* is for bug reports and feature requests only.**
## Sponsor
AList is an open-source software, if you happen to like this project and want me to keep going, please consider sponsoring me or providing a single donation! Thanks for all the love and support:
https://alist.nn.ci/guide/sponsor.html
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
### Special sponsors
## Donors
- [亚洲云 - 高防服务器|服务器租用|福州高防|广东电信|香港服务器|美国服务器|海外服务器 - 国内靠谱的企业级云计算服务提供商](https://www.asiayun.com/aff/QQCOOQKZ) (sponsored Chinese API server)
The `AList` is open-source software licensed under the AGPL-3.0 license.
The `OpenList` is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
## Disclaimer
- This program is a free and open source project. It is designed to share files on the network disk, which is convenient for downloading and learning golang. Please abide by relevant laws and regulations when using it, and do not abuse it;
- This program is implemented by calling the official sdk/interface, without destroying the official interface behavior;
- This program only does 302 redirect/traffic forwarding, and does not intercept, store, or tamper with any user data;
- Before using this program, you should understand and bear the corresponding risks, including but not limited to account ban, download speed limit, etc., which is none of this program's business;
- If there is any infringement, please contact me by [email](mailto:i@nn.ci), and it will be dealt with in time.
---
- This project is a free and open-source software designed to facilitate file sharing via net disks, primarily intended to support the downloading and learning of the Go programming language.
- Please comply with all applicable laws and regulations when using this software. Any form of misuse is strictly prohibited.
- The software is based on official SDKs or APIs without any modification, disruption, or interference with their behavior.
- It only performs HTTP 302 redirects or traffic forwarding, and does not intercept, store, or tamper with any user data.
- This project is not affiliated with any official platform or service provider.
- The software is provided "as is", without any warranties of any kind, either express or implied, including but not limited to warranties of merchantability or fitness for a particular purpose.
- The maintainers are not liable for any direct or indirect damages arising from the use of, or inability to use, this software.
- You are solely responsible for any risks associated with using this software, including but not limited to account bans or download speed limitations.
- This project is licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) License. Please see the [LICENSE](./LICENSE) file for details.
We sincerely thank the author [Xhofe](https://github.com/Xhofe) of the original project [AlistGo/alist](https://github.com/AlistGo/alist) and all other contributors.
<p><em>OpenList هو تفرّع من AList يتميز بالمرونة والحوكمة طويلة الأمد ويقوده المجتمع، وقد بُني للدفاع عن البرمجيات مفتوحة المصدر ضد الهجمات القائمة على الثقة.</em></p>
OpenList is an open-source project independently maintained by the OpenList Team under the AGPL-3.0 license, with a commitment to code openness and modification transparency.
OpenList has no official association with third-party derivative projects that use similar names, including OpenListApp/OpenListApp or paid proprietary software using the same or similar names.
- All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.
- Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments.
- Downstream projects should not use the "OpenList" name for impersonation or commercial confusion, and must not distribute OpenList-based code as closed source in violation of the AGPL license.
- This software is provided "as is" without warranties. Please comply with applicable laws and regulations when using it.
## الميزات
- [x] Multiple storages
- [x] Local storage
- [x] [Aliyundrive](https://www.alipan.com)
- [x] OneDrive / Sharepoint ([Global](https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage), [CN](https://portal.partner.microsoftonline.cn), DE, US)
Please refer to [Discussions](https://github.com/OpenListTeam/OpenList/discussions) for general questions; Issues are for bug reports and feature requests only.
## الراعي
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## المتبرعون
Thanks to the following donors for their generous support:
- [HisAtri](https://github.com/HisAtri)
- 爱发电用户_7jTh
- suka
## الترخيص
OpenList is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
We sincerely thank [Xhofe](https://github.com/Xhofe), author of the original project [AlistGo/alist](https://github.com/AlistGo/alist), and all other contributors.
<p><em>OpenList ist ein widerstandsfähiger, langfristig verwalteter und Community-getriebener Fork von AList, entwickelt zum Schutz von Open Source vor vertrauensbasierten Angriffen.</em></p>
OpenList is an open-source project independently maintained by the OpenList Team under the AGPL-3.0 license, with a commitment to code openness and modification transparency.
OpenList has no official association with third-party derivative projects that use similar names, including OpenListApp/OpenListApp or paid proprietary software using the same or similar names.
- All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.
- Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments.
- Downstream projects should not use the "OpenList" name for impersonation or commercial confusion, and must not distribute OpenList-based code as closed source in violation of the AGPL license.
- This software is provided "as is" without warranties. Please comply with applicable laws and regulations when using it.
## Funktionen
- [x] Multiple storages
- [x] Local storage
- [x] [Aliyundrive](https://www.alipan.com)
- [x] OneDrive / Sharepoint ([Global](https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage), [CN](https://portal.partner.microsoftonline.cn), DE, US)
Please refer to [Discussions](https://github.com/OpenListTeam/OpenList/discussions) for general questions; Issues are for bug reports and feature requests only.
## Sponsor
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## Spender
Thanks to the following donors for their generous support:
- [HisAtri](https://github.com/HisAtri)
- 爱发电用户_7jTh
- suka
## Lizenz
OpenList is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
We sincerely thank [Xhofe](https://github.com/Xhofe), author of the original project [AlistGo/alist](https://github.com/AlistGo/alist), and all other contributors.
<p><em>OpenList es un fork de AList resiliente, con gobernanza a largo plazo e impulsado por la comunidad, creado para defender el código abierto frente a ataques basados en la confianza.</em></p>
OpenList is an open-source project independently maintained by the OpenList Team under the AGPL-3.0 license, with a commitment to code openness and modification transparency.
OpenList has no official association with third-party derivative projects that use similar names, including OpenListApp/OpenListApp or paid proprietary software using the same or similar names.
- All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.
- Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments.
- Downstream projects should not use the "OpenList" name for impersonation or commercial confusion, and must not distribute OpenList-based code as closed source in violation of the AGPL license.
- This software is provided "as is" without warranties. Please comply with applicable laws and regulations when using it.
## Características
- [x] Multiple storages
- [x] Local storage
- [x] [Aliyundrive](https://www.alipan.com)
- [x] OneDrive / Sharepoint ([Global](https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage), [CN](https://portal.partner.microsoftonline.cn), DE, US)
Please refer to [Discussions](https://github.com/OpenListTeam/OpenList/discussions) for general questions; Issues are for bug reports and feature requests only.
## Patrocinador
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## Donantes
Thanks to the following donors for their generous support:
- [HisAtri](https://github.com/HisAtri)
- 爱发电用户_7jTh
- suka
## Licencia
OpenList is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
We sincerely thank [Xhofe](https://github.com/Xhofe), author of the original project [AlistGo/alist](https://github.com/AlistGo/alist), and all other contributors.
<p><em>OpenList est un fork d’AList résilient, gouverné sur le long terme et porté par la communauté, conçu pour protéger l’open source contre les attaques fondées sur la confiance.</em></p>
OpenList is an open-source project independently maintained by the OpenList Team under the AGPL-3.0 license, with a commitment to code openness and modification transparency.
OpenList has no official association with third-party derivative projects that use similar names, including OpenListApp/OpenListApp or paid proprietary software using the same or similar names.
- All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.
- Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments.
- Downstream projects should not use the "OpenList" name for impersonation or commercial confusion, and must not distribute OpenList-based code as closed source in violation of the AGPL license.
- This software is provided "as is" without warranties. Please comply with applicable laws and regulations when using it.
## Fonctionnalités
- [x] Multiple storages
- [x] Local storage
- [x] [Aliyundrive](https://www.alipan.com)
- [x] OneDrive / Sharepoint ([Global](https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage), [CN](https://portal.partner.microsoftonline.cn), DE, US)
Please refer to [Discussions](https://github.com/OpenListTeam/OpenList/discussions) for general questions; Issues are for bug reports and feature requests only.
## Sponsor
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## Donateurs
Thanks to the following donors for their generous support:
- [HisAtri](https://github.com/HisAtri)
- 爱发电用户_7jTh
- suka
## Licence
OpenList is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
We sincerely thank [Xhofe](https://github.com/Xhofe), author of the original project [AlistGo/alist](https://github.com/AlistGo/alist), and all other contributors.
OpenList is an open-source project independently maintained by the OpenList Team under the AGPL-3.0 license, with a commitment to code openness and modification transparency.
OpenList has no official association with third-party derivative projects that use similar names, including OpenListApp/OpenListApp or paid proprietary software using the same or similar names.
- All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.
- Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments.
- Downstream projects should not use the "OpenList" name for impersonation or commercial confusion, and must not distribute OpenList-based code as closed source in violation of the AGPL license.
- This software is provided "as is" without warranties. Please comply with applicable laws and regulations when using it.
## 기능
- [x] Multiple storages
- [x] Local storage
- [x] [Aliyundrive](https://www.alipan.com)
- [x] OneDrive / Sharepoint ([Global](https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage), [CN](https://portal.partner.microsoftonline.cn), DE, US)
Please refer to [Discussions](https://github.com/OpenListTeam/OpenList/discussions) for general questions; Issues are for bug reports and feature requests only.
## 후원
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## 후원자
Thanks to the following donors for their generous support:
- [HisAtri](https://github.com/HisAtri)
- 爱发电用户_7jTh
- suka
## 라이선스
OpenList is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
We sincerely thank [Xhofe](https://github.com/Xhofe), author of the original project [AlistGo/alist](https://github.com/AlistGo/alist), and all other contributors.
<p><em>OpenList is een veerkrachtige, langetermijn, door de gemeenschap geleide fork van AList — gebouwd om open source te beschermen tegen op vertrouwen gebaseerde aanvallen.</em></p>
OpenList is een open-source project dat onafhankelijk wordt onderhouden door het OpenList Team, volgend op de AGPL-3.0 licentie en toegewijd aan het behouden van volledige code openheid en transparantie van wijzigingen.
We hebben gemerkt dat er in de gemeenschap enkele derde partij projecten zijn verschenen met namen vergelijkbaar met dit project, zoals OpenListApp/OpenListApp, evenals enkele betaalde eigendomssoftware die dezelfde of soortgelijke naamgeving gebruikt. Om verwarring bij gebruikers te voorkomen, verklaren we hierbij:
- OpenList heeft geen officiële associatie met enige derde partij afgeleide projecten.
- Alle software, code en diensten van dit project worden onderhouden door het OpenList Team en zijn gratis beschikbaar op GitHub.
- Projectdocumentatie en API diensten zijn voornamelijk afhankelijk van liefdadigheidsbronnen verstrekt door Cloudflare. Er zijn momenteel geen betaalplannen of commerciële implementaties, en het gebruik van bestaande functies brengt geen kosten met zich mee.
We respecteren de rechten van de gemeenschap voor vrij gebruik en afgeleide ontwikkeling, maar we roepen downstream projecten ook ten zeerste op:
- Mogen niet de "OpenList" naam gebruiken voor namaakpromotie of commercieel gewin;
- Mogen OpenList-gebaseerde code niet distribueren op een closed-source manier of AGPL licentievoorwaarden schenden.
Om een gezonde ecosysteemontwikkeling beter te onderhouden, bevelen we aan:
- Duidelijk de projectbron aangeven en passende open-source licenties kiezen in overeenstemming met de open-source geest;
- Bij commercieel gebruik, vermijd het gebruik van "OpenList" of enige verwarrende naamgeving als projectnaam;
- Als u materialen onder OpenListTeam/Logo moet gebruiken, kunt u deze wijzigen en gebruiken onder naleving van de overeenkomst.
Dank u voor uw ondersteuning en begrip
## Functies
- [x] Meerdere opslagmogelijkheden
- [x] Lokale opslag
- [x] [Aliyundrive](https://www.alipan.com)
- [x] OneDrive / Sharepoint ([Global](https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage), [CN](https://portal.partner.microsoftonline.cn), DE, US)
Stel algemene vragen in [*Discussions*](https://github.com/OpenListTeam/OpenList/discussions), ***Issues* zijn alleen voor bugmeldingen en feature requests.**
## Sponsoren
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## Donatie Bijdragers
Dank aan de volgende donateurs voor hun steun:
- [HisAtri](https://github.com/HisAtri)
- 爱发电用户_7jTh
- suka
## Licentie
`OpenList` is open-source software onder de [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) licentie.
## Disclaimer
- Dit project is gratis en open-source software, ontworpen om het delen van bestanden via netdisks te vergemakkelijken, voornamelijk bedoeld ter ondersteuning van het downloaden en leren van de programmeertaal Go.
- Houd u bij het gebruik van deze software aan alle toepasselijke wetten en voorschriften. Elk misbruik is ten strengste verboden.
- De software is gebaseerd op officiële SDK's of API's zonder enige wijziging, verstoring of beïnvloeding van hun gedrag.
- Het voert alleen HTTP 302-omleidingen of verkeersdoorsturing uit en onderschept, slaat of wijzigt geen gebruikersgegevens.
- Dit project is niet gelieerd aan enig officieel platform of dienstverlener.
- De software wordt geleverd "zoals deze is", zonder enige vorm van garantie, expliciet of impliciet, inclusief maar niet beperkt tot garanties van verkoopbaarheid of geschiktheid voor een bepaald doel.
- De beheerders zijn niet aansprakelijk voor enige directe of indirecte schade die voortvloeit uit het gebruik van of het onvermogen om deze software te gebruiken.
- U bent zelf verantwoordelijk voor alle risico's die gepaard gaan met het gebruik van deze software, inclusief maar niet beperkt tot accountblokkades of downloadbeperkingen.
- Dit project valt onder de [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) licentie. Zie het [LICENSE](../LICENSE) bestand voor details.
Wij danken de auteur [Xhofe](https://github.com/Xhofe) van het originele project [AlistGo/alist](https://github.com/AlistGo/alist) en alle andere bijdragers.
<p><em>OpenList — устойчивый, управляемый сообществом форк AList с долгосрочным управлением, созданный для защиты open source от атак, основанных на доверии.</em></p>
OpenList is an open-source project independently maintained by the OpenList Team under the AGPL-3.0 license, with a commitment to code openness and modification transparency.
OpenList has no official association with third-party derivative projects that use similar names, including OpenListApp/OpenListApp or paid proprietary software using the same or similar names.
- All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.
- Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments.
- Downstream projects should not use the "OpenList" name for impersonation or commercial confusion, and must not distribute OpenList-based code as closed source in violation of the AGPL license.
- This software is provided "as is" without warranties. Please comply with applicable laws and regulations when using it.
## Возможности
- [x] Multiple storages
- [x] Local storage
- [x] [Aliyundrive](https://www.alipan.com)
- [x] OneDrive / Sharepoint ([Global](https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage), [CN](https://portal.partner.microsoftonline.cn), DE, US)
Please refer to [Discussions](https://github.com/OpenListTeam/OpenList/discussions) for general questions; Issues are for bug reports and feature requests only.
## Спонсор
[](https://vps.town "VPS.Town - Trust, Effortlessly. Your Cloud, Reimagined.")
## Доноры
Thanks to the following donors for their generous support:
- [HisAtri](https://github.com/HisAtri)
- 爱发电用户_7jTh
- suka
## Лицензия
OpenList is open-source software licensed under the [AGPL-3.0](https://www.gnu.org/licenses/agpl-3.0.txt) license.
We sincerely thank [Xhofe](https://github.com/Xhofe), author of the original project [AlistGo/alist](https://github.com/AlistGo/alist), and all other contributors.
RootCmd.PersistentFlags().StringVar(&flags.DataDir,"data","data","data directory (relative paths are resolved against the current working directory)")
RootCmd.PersistentFlags().StringVar(&flags.ConfigPath,"config","","path to config.json (relative to current working directory; defaults to [data directory]/config.json, where [data directory] is set by --data)")
RootCmd.PersistentFlags().BoolVar(&flags.Debug,"debug",false,"start with debug mode")
UploadThreadint`json:"UploadThread" type:"number" default:"3" help:"the threads of upload"`
// 使用直链
DirectLinkbool`json:"DirectLink" type:"bool" default:"false" required:"false" help:"use direct link when download file"`
DirectLinkPrivateKeystring`json:"DirectLinkPrivateKey" required:"false" help:"private key for direct link, if URL authentication is enabled"`
DirectLinkValidDurationint64`json:"DirectLinkValidDuration" type:"number" default:"30" required:"false" help:"minutes, if URL authentication is enabled"`
Some files were not shown because too many files have changed in this diff
Show More
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.