Dionisio 05135529ce fix(security): scope root folder listing to authenticated user
Non-admin users were seeing all users' root folders, including the
admin's. Three root causes fixed:

1. Backend: list_root_folders now extracts AuthUser and filters
   results so each user only sees their own home folder at the
   root level (folders matching 'My Folder - {username}' or
   'Mi Carpeta - {username}').

2. Frontend: findUserHomeFolder() searched only for the Spanish
   pattern 'Mi Carpeta - {username}' but the backend creates
   folders with the English pattern 'My Folder - {username}'.
   Now checks both naming conventions.

3. Frontend: when the home folder was not found, the code fell
   back to folderList[0] — which was usually the admin's folder.
   Removed that dangerous fallback; now shows empty root instead.

Fixes #94
2026-02-13 22:31:05 +01:00
2026-02-13 13:22:58 +01:00
2025-03-17 21:28:08 +01:00
2025-04-13 03:23:53 +02:00

OxiCloud

License: MIT Latest Release GitHub Stars GitHub Issues GitHub Forks Last Commit

A fast, simple alternative to NextCloud

NextCloud was too slow on my home server. So I built OxiCloud: a file storage system written in Rust that runs on minimal hardware and stays out of your way.

OxiCloud Dashboard

Why OxiCloud?

Feature What you get
Low resources Runs on 512MB RAM. No PHP, no bloat.
Fast Rust with LTO optimization. Sub-second responses.
Clean UI Works on desktop and mobile. No clutter.
Easy setup One binary, one database, done.
Multi-language English, Spanish and Persian out of the box.

Quick Start

You need Rust 1.70+, Cargo, and PostgreSQL 13+.

git clone https://github.com/DioCrafts/oxicloud.git
cd oxicloud

# Set up your database connection
echo "DATABASE_URL=postgres://username:password@localhost/oxicloud" > .env

# Build and run
cargo build --release
cargo run --bin migrate --features migrations
cargo run --release

Open http://localhost:8085 in your browser.

Docker (alternative)

docker compose up -d

That's it. The app runs on port 8086.

Architecture

OxiCloud uses Clean Architecture with four layers:

┌─────────────────────────────────────────┐
│  Interfaces    │ API routes, handlers   │
├─────────────────────────────────────────┤
│  Application   │ Use cases, services    │
├─────────────────────────────────────────┤
│  Domain        │ Business logic         │
├─────────────────────────────────────────┤
│  Infrastructure│ Database, filesystem   │
└─────────────────────────────────────────┘

Each layer only talks to the one below it. You can swap out the database or add new API endpoints without touching business logic.

Development

cargo build                 # Build
cargo run                   # Run locally
cargo test                  # Run tests
cargo clippy                # Lint
cargo fmt                   # Format

# For debugging
RUST_LOG=debug cargo run

Current Features

  • File upload, download, and organization
  • Folder management with drag-and-drop
  • Trash bin with restore functionality
  • User authentication with JWT
  • Personal folders per user
  • File deduplication
  • Write-behind cache for fast uploads
  • Search across files and folders
  • Favorites and recent files
  • Responsive grid/list views

What's Next

I'm working on these when I have time:

  • File sharing via links
  • WebDAV for desktop sync
  • Basic versioning
  • Mobile app improvements

Check TODO-LIST.md for the full list.

Contributing

The project is early stage. There's plenty to improve.

Read CONTRIBUTING.md before submitting a PR. Follow the Code of Conduct.

License

MIT. See LICENSE.


Star History


Questions? Open an issue. Want to help? PRs welcome.

S
Description
No description provided
Readme MIT 53 MiB
Languages
Rust 63.3%
Hurl 10.2%
TypeScript 8.6%
Svelte 8.3%
Shell 3.7%
Other 5.7%