1a1dee9179ca4bf4f1438575921d763ffe46c82d
Security fixes for OIDC authentication flow: 1. CSRF state validation (High): State nonce is now stored server-side and validated on callback (single-use, 600s TTL) 2. PKCE S256 (Medium): code_challenge/code_verifier pair generated per RFC 9126, sent in authorize URL and token exchange 3. Nonce in ID token (Medium): Random nonce included in authorize URL, verified against ID token claims to prevent token replay 4. Secure token delivery (Medium): Tokens no longer in URL fragments. One-time exchange code redirected to frontend, tokens retrieved via POST /api/auth/oidc/exchange endpoint (60s TTL, single-use) 5. Registration guard (Low): POST /api/auth/register returns 403 when disable_password_login is active in OIDC-only mode
A fast, simple alternative to NextCloud
NextCloud was too slow on my home server. So I built OxiCloud: a file storage system written in Rust that runs on minimal hardware and stays out of your way.
Why OxiCloud?
| Feature | What you get |
|---|---|
| Low resources | Runs on 512MB RAM. No PHP, no bloat. |
| Fast | Rust with LTO optimization. Sub-second responses. |
| Clean UI | Works on desktop and mobile. No clutter. |
| Easy setup | One binary, one database, done. |
| Multi-language | English, Spanish and Persian out of the box. |
Quick Start
You need Rust 1.70+, Cargo, and PostgreSQL 13+.
git clone https://github.com/DioCrafts/oxicloud.git
cd oxicloud
# Set up your database connection
echo "DATABASE_URL=postgres://username:password@localhost/oxicloud" > .env
# Build and run
cargo build --release
cargo run --bin migrate --features migrations
cargo run --release
Open http://localhost:8085 in your browser.
Docker (alternative)
docker compose up -d
That's it. The app runs on port 8086.
Architecture
OxiCloud uses Clean Architecture with four layers:
┌─────────────────────────────────────────┐
│ Interfaces │ API routes, handlers │
├─────────────────────────────────────────┤
│ Application │ Use cases, services │
├─────────────────────────────────────────┤
│ Domain │ Business logic │
├─────────────────────────────────────────┤
│ Infrastructure│ Database, filesystem │
└─────────────────────────────────────────┘
Each layer only talks to the one below it. You can swap out the database or add new API endpoints without touching business logic.
Development
cargo build # Build
cargo run # Run locally
cargo test # Run tests
cargo clippy # Lint
cargo fmt # Format
# For debugging
RUST_LOG=debug cargo run
Current Features
- File upload, download, and organization
- Folder management with drag-and-drop
- Trash bin with restore functionality
- User authentication with JWT
- Personal folders per user
- File deduplication
- Write-behind cache for fast uploads
- Search across files and folders
- Favorites and recent files
- Responsive grid/list views
What's Next
I'm working on these when I have time:
- File sharing via links
- WebDAV for desktop sync
- Basic versioning
- Mobile app improvements
Check TODO-LIST.md for the full list.
Contributing
The project is early stage. There's plenty to improve.
Read CONTRIBUTING.md before submitting a PR. Follow the Code of Conduct.
License
MIT. See LICENSE.
Questions? Open an issue. Want to help? PRs welcome.
Languages
Rust
63.5%
Hurl
10.2%
TypeScript
8.5%
Svelte
8.2%
Shell
3.8%
Other
5.6%
