⎇
server
web
.gitignore143 B
Cargo.lock80.7 KB
Cargo.toml87 B
justfile1.7 KB
README.md2.2 KB
READMERaw

filebrowser-ng

A simple, noob-friendly web file browser. Single binary, SQLite-backed.

Features (status)

  • First-boot admin setup (create the admin account in the browser)
  • Login/logout with cookie sessions (argon2id password hashing)
  • Per-user folder access ("virtual roots"), read-write or read-only
  • File browsing (grid/list, breadcrumbs, context menu)
  • Upload (files & folders, drag & drop, overwrite warning)
  • Download (files as-is; folders as zip / tar / tar.gz / tar.zst, streamed)
  • Move / copy / rename / delete / new folder
  • File info, previews (image/PDF/video/audio/text), text editor (CodeMirror)
  • Shares (token links, optional expiry, optional writable, admin toggle)
  • Admin UI (user management, settings)

Usage

filebrowser-ng --root /path/to/files --db /path/to/filebrowser.db
               [--port 8080] [--bind 127.0.0.1] [--https]
  • --root — the folder the server has access to (required)
  • --db — path to the SQLite database (required)
  • --https — assume a TLS-terminating reverse proxy in front (Secure cookies)

First run: open the URL and create the admin account. The admin gets the whole root as their folder.

Development

just dev-server   # backend on :8081 (needs the dev data dir; created automatically)
just dev-web      # Trunk dev server on :8080, proxies /api to :8081

Open http://localhost:8080 .

Production single binary:

just build        # trunk build + embed into server/dist + cargo build --release
just run          # build, then run against .dev/root and .dev/db.sqlite

Reset dev users/settings: just reset-db

Architecture

  • server/ — Axum (Rust). SQLite via rusqlite (bundled). All user paths are stored relative to --root; every filesystem operation resolves <root>/<user-root>/<requested-path>, canonicalizes it, and verifies it is still inside the user's root (blocks .. and symlink escapes). Writes additionally require the root to be rw.
  • web/ — Leptos 0.8 CSR, built with Trunk. In production the frontend is embedded into the binary (--features embedded, folder server/dist); in dev it is served from web/dist on disk.