Diocrafts
b81b7f7a0e
fix: eliminate all 420 compiler warnings
...
- Add allow(async_fn_in_trait) in lib.rs for async trait methods
- Add integration_tests feature to Cargo.toml for cfg gating
- Gate trash_service_test module with cfg(feature = integration_tests)
- Remove unused MockFileWritePort from idor_protection_test.rs
2026-03-04 23:29:20 +01:00
Dionisio
4a60fdc984
fix(security): IDOR protection for file operations
...
Adds ownership verification at repository, service, and handler layers
for download, rename, move, and delete file operations.
- Repository: get_file_for_owner() with AND user_id= SQL filter
- Service: _owned() methods with verify_owner() fail-closed guard
- Handlers: require AuthUser, delegate to _owned() methods
- Tests: 10 IDOR protection tests (all passing)
- Cleanup: remove dead OptionalUserId import, gate broken pre-existing
test modules behind integration_tests feature flag
2026-03-04 17:18:39 +01:00
Dionisio
efcf88c4d7
style: cargo fmt --all
2026-03-03 01:49:18 +01:00
Dionisio
81987e9321
fix: URL-decode DAV paths with spaces + feat: app passwords for Basic Auth
...
Bug fix:
- URL-decode paths in extract_webdav_path(), extract_caldav_path(),
extract_carddav_path() so folders with spaces (e.g. 'My Folder') no
longer return 404 when accessed via encoded URIs (%20)
- Properly encode href values in PROPFIND/PROPPATCH/LOCK XML responses
- Decode Destination header in MOVE/COPY operations
New feature - App Passwords (API keys for DAV clients):
- POST /api/auth/app-passwords → create (shows token once)
- GET /api/auth/app-passwords → list (prefix only)
- DELETE /api/auth/app-passwords/:id → revoke
- Auth middleware now accepts both Bearer JWT and Basic Auth
- Argon2 hashed, scoped (webdav/caldav/carddav), optional expiry
- Compatible with DAVx5, Thunderbird, rclone, curl
Tested: 12/12 E2E tests pass (create, list, WebDAV/CalDAV/CardDAV
Basic Auth, URL-decode with spaces, wrong password 401, revoke, post-
revoke 401).
2026-03-01 20:34:12 +01:00
Dionisio
48d853360e
feat: implement OAuth 2.0 Device Authorization Grant (RFC 8628) for WebDAV/CalDAV/CardDAV
...
Adds full Device Authorization Grant flow so DAV clients (rclone, etc.)
can authenticate without browser-based OAuth redirects.
New files:
- Domain entity: DeviceCode with status lifecycle (pending/authorized/denied/expired)
- Port: DeviceCodeStoragePort trait (7 async methods)
- DTOs: request/response types for all device auth endpoints
- Repository: DeviceCodePgRepository (PostgreSQL implementation)
- Service: DeviceAuthService (initiate, verify, approve, deny, poll, cleanup)
- Handler: 6 HTTP endpoints (2 public + 4 protected)
- Static: device-verify.html verification page served at /device
Flow:
1. Client POST /api/auth/device/authorize → device_code + user_code
2. User opens /device?code=XXXX in browser, approves
3. Client polls POST /api/auth/device/token → receives JWT tokens
4. Client uses Bearer token with existing WebDAV/CalDAV/CardDAV middleware
Schema: auth.device_codes table + device_code_status enum added to schema.sql
Closes #152
2026-03-01 11:54:43 +01:00
Jan Wiebe
4e2c9d2592
feat(wopi): add WOPI protocol support for collaborative editing
...
Implement the Web Application Open Platform Interface (WOPI) protocol
to enable collaborative document editing with Collabora Online and
OnlyOffice through OxiCloud.
Backend:
- WOPI token service with HMAC-SHA256 signed access tokens
- WOPI lock service with in-memory lock management and expiry
- WOPI discovery service for auto-detecting editor capabilities
- WOPI HTTP handler: CheckFileInfo, GetFile, PutFile, Lock/Unlock
- File entity extended with owner_id for WOPI file-info responses
- Configuration via WOPI_* environment variables
- Services wired through DI in AppState
Frontend:
- WOPI editor component with modal and new-tab viewing modes
- Context menu integration for opening files in online editors
- Inline viewer integration for document preview
Infrastructure:
- Docker Compose file for local Collabora/OnlyOffice dev setup
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-21 13:39:27 +01:00
Dionisio
bc01840fa4
chore: remove dead code from blob storage migration
...
Remove legacy abstractions that are no longer used after the
100% blob storage model migration (#113 ):
- IdMappingPort trait from application/ports/outbound.rs
- storage_mediator.rs module (StorageMediator trait + impls)
- StorageMediator impl from PathService
- write_behind_cache.rs (FS-based, incompatible with blob model)
The WriteBehindCachePort trait and Optional fields in services
are preserved for potential future blob-compatible caching.
-968 lines of dead code removed. Build clean, RC=0.
2026-02-14 18:10:37 +01:00
Dionisio
4c98c5a657
style: apply cargo fmt to entire codebase
...
Standardize code formatting across all 173 Rust source files
using rustfmt. No functional changes - purely cosmetic.
This establishes a consistent code style baseline for the
project going forward.
2026-02-14 01:29:34 +01:00
Dionisio
f60c0df9f9
feat(admin): add admin settings panel for OIDC configuration
...
- Admin UI at /admin.html with settings management interface
- REST API: GET/PUT /api/admin/settings/oidc, POST .../test, GET .../general
- DB-backed settings in auth.admin_settings table (PostgreSQL)
- OIDC auto-discovery from issuer URL (.well-known/openid-configuration)
- Hot-reload: OIDC config changes apply without server restart
- Role-based access: admin-only endpoints with 403 for regular users
- Client secret stored securely, never exposed in GET responses
- Env var override detection shown in admin UI
- Clean architecture: repository trait, PG implementation, service, handler
2026-02-11 00:15:26 +01:00
Diocrafts
a82faa5eaf
refactoring hexagonal and clean architecture
2026-02-08 13:40:23 +01:00
DioCrafts
52d8250d51
adding card dav and cald dav
2025-04-13 01:04:04 +02:00
DioCrafts
8f1d213526
improve postgresql performance
2025-04-09 00:21:20 +02:00
DioCrafts
a79c335b73
adding recent feature + bug fixed
2025-04-02 05:08:30 +02:00
DioCrafts
7069a54d8d
adding favorite feature
2025-04-02 03:43:44 +02:00
DioCrafts
3a4cb75ac7
configuring backend topology
2025-03-28 12:38:48 +01:00
DioCrafts
bfbef18117
fix warnings
2025-03-27 23:41:56 +01:00
DioCrafts
7affff379d
adding search engine
2025-03-27 01:13:34 +01:00
DioCrafts
38b0e9594b
fix auth errors and add primigenial paper trash
2025-03-24 16:47:42 +01:00
DioCrafts
cafad0fbfd
adding user authentication
2025-03-20 09:22:31 +01:00
DioCrafts
6e055c3043
adding features
2025-03-19 19:52:12 +01:00
DioCrafts
d9bbd575d2
adding several features
2025-03-19 00:44:27 +01:00
root
fe19bc8505
Initial commit
2025-03-17 21:28:08 +01:00