# filebrowser-ng A simple, noob-friendly web file browser. Single binary, SQLite-backed. ## Features (status) - [x] First-boot admin setup (create the admin account in the browser) - [x] Login/logout with cookie sessions (argon2id password hashing) - [x] Per-user folder access ("virtual roots"), read-write or read-only - [ ] File browsing (grid/list, breadcrumbs, context menu) - [ ] Upload (files & folders, drag & drop, overwrite warning) - [ ] Download (files as-is; folders as zip / tar / tar.gz / tar.zst, streamed) - [ ] Move / copy / rename / delete / new folder - [ ] File info, previews (image/PDF/video/audio/text), text editor (CodeMirror) - [ ] Shares (token links, optional expiry, optional writable, admin toggle) - [ ] Admin UI (user management, settings) ## Usage ``` filebrowser-ng --root /path/to/files --db /path/to/filebrowser.db [--port 8080] [--bind 127.0.0.1] [--https] ``` - `--root` — the folder the server has access to (required) - `--db` — path to the SQLite database (required) - `--https` — assume a TLS-terminating reverse proxy in front (Secure cookies) First run: open the URL and create the admin account. The admin gets the whole root as their folder. ## Development ```sh just dev-server # backend on :8081 (needs the dev data dir; created automatically) just dev-web # Trunk dev server on :8080, proxies /api to :8081 ``` Open http://localhost:8080 . Production single binary: ```sh just build # trunk build + embed into server/dist + cargo build --release just run # build, then run against .dev/root and .dev/db.sqlite ``` Reset dev users/settings: `just reset-db` ## Architecture - `server/` — Axum (Rust). SQLite via `rusqlite` (bundled). All user paths are stored **relative to `--root`**; every filesystem operation resolves `//`, canonicalizes it, and verifies it is still inside the user's root (blocks `..` and symlink escapes). Writes additionally require the root to be `rw`. - `web/` — Leptos 0.8 CSR, built with Trunk. In production the frontend is embedded into the binary (`--features embedded`, folder `server/dist`); in dev it is served from `web/dist` on disk.