Cargo.toml
⎇
Raw
1[package]
2name = "server"
3version = "0.1.0"
4edition = "2024"
5license = "AGPL-3.0-or-later"
6
7[[bin]]
8name = "filebrowser-ng"
9path = "src/main.rs"
10
11[dependencies]
12api-types = { path = "../api-types" }
13anyhow = "1"
14argon2 = "0.5"
15axum = "0.8"
16bytes = "1"
17chrono = { version = "0.4", features = ["serde"] }
18clap = { version = "4", features = ["derive", "env"] }
19# WebDAV protocol only. The bundled `localfs`/`memfs` backends are off: the
20# dav filesystem is `api::dav`, which goes through `crate::fs` so that root
21# containment, read-only roots and share scoping apply to a mount too.
22dav-server = { version = "0.11", default-features = false }
23# Thumbnails: decode only what the grid can show. The default feature set
24# also pulls in rav1e and exr, which are large and unused here.
25image = { version = "0.25", default-features = false, features = [
26 "jpeg",
27 "png",
28 "gif",
29 "webp",
30 "bmp",
31 "tiff",
32] }
33# Lanczos3 downscaling. `image`'s own is 15x slower at the same quality.
34fast_image_resize = { version = "5", features = ["image"] }
35# libwebp for the encoder. The crate vendors the C source and builds it with
36# `cc`; no system library, same as the bundled SQLite.
37webp = "0.3"
38# `default-features = false` drops the `cfb` dependency (compound-document
39# detection we do not need) and makes this a zero-dependency crate.
40infer = { version = "0.16", default-features = false, features = ["alloc"] }
41mime_guess = "2"
42multer = "3"
43rusqlite = { version = "0.37", features = ["bundled"] }
44serde = { version = "1", features = ["derive"] }
45serde_json = "1"
46sha2 = "0.10"
47tokio = { version = "1", features = [
48 "rt-multi-thread",
49 "macros",
50 "fs",
51 "io-util",
52 "sync",
53 "time",
54 "signal",
55 "process",
56] }
57tar = "0.4"
58flate2 = "1"
59zstd = "0.13"
60# Deflate only; the defaults add AES, bzip2, lzma, ppmd, zopfli.
61zip = { version = "9.0.0-pre3", default-features = false, features = ["deflate-flate2-zlib-rs"] }
62tower-http = { version = "0.6", features = ["trace", "set-header", "fs"] }
63# Named in the `DavLockSystem` impl. dav-server does not re-export it, so the
64# version has to track dav-server's own.
65xmltree = "0.12"
66futures-util = "0.3"
67# Typed `Authorization: Basic` parsing. Already in the tree via dav-server.
68headers = "0.4"
69tracing = "0.1"
70tracing-subscriber = { version = "0.3", features = ["env-filter"] }
71ignore = "0.4"
72grep = "0.4"
73webauthn-rs = { version = "0.5.5", features = ["conditional-ui"], default-features = false }
74getrandom = "0.4"
75# For `ResidentKeyRequirement` and `AllowCredentials`, which `webauthn-rs` uses
76# internally but does not re-export. Keep this version equal to webauthn-rs'
77# own: it already pulls this crate in, and two different versions would compile
78# while being different types.
79webauthn-rs-proto = "0.5.5"
80
81[dev-dependencies]
82base64 = "0.22"
83tempfile = "3"
84tower = { version = "0.5", features = ["util"] }
85http-body-util = "0.1"
86
87[dependencies.rust-embed]
88version = "8"
89optional = true
90
91[features]
92# Embed the frontend (built into server/dist by `just build`).
93# Without this feature the server reads the frontend from disk at runtime
94# (Trunk's output directory, or $FBNG_DIST), which is the dev flow.
95embedded = ["dep:rust-embed"]
96