Ghost FTP 0.93.0 — cross-platform cloud storage foundations
Candidate source follows the verified public v0.92.2 release. A public 0.93.0 release requires exact-SHA CI and official artifact verification.
Windows and Linux
Retain authenticated S3-compatible storage, Google Cloud Storage, Azure Blob, WebDAV, Google Drive, OneDrive, Dropbox and Box adapters. Custom S3/Azure endpoints require HTTPS without userinfo, query or fragment. WebDAV now also requires HTTPS before Basic/Bearer authorization, blocks credential-bearing URL fields and refuses redirects. Regression tests cover rejected unsafe endpoints.
macOS and Android
Introduce Cloud storage workspaces supporting short-lived provider-signed one-object HTTPS PUT and GET for S3/R2/B2, GCS and Azure SAS, without storing bearer URLs or relaying data through a Ghost FTP service. Default OS TLS verification is retained and redirects are rejected.
- macOS: Ephemeral URLSession, Finder open/save panels, 1 GiB object limit and destination staging.
- Android: Android document picker (SAF), HttpsURLConnection with no redirects, public-address checking, bounded transfer sizes and a temporary download stage before writing an output document.
Security and limitations
The signed link is itself a bearer secret, valid only for the provider-authorized object/operation. Signed cloud links are not Google Drive sharing-page links. macOS and Android do not yet support full authenticated cloud account browsing, OAuth Google Drive sign-in, S3 bucket listings, multipart transfers or background resumable transfers. Provider/device acceptance and additional DNS rebinding defense remain future gates. No published tag is retargeted.
Candidate hardening and Android artifact delivery
- Android/macOS reject missing, empty, duplicated or provider-mismatched signature query markers; tests cover these negative cases. Downloads request identity content encoding and fail on an unexpected Content-Encoding response. Parameter-shape validation is not cryptographic signature verification; the provider enforces authorization.
- Android CI additionally builds
bundleRelease, checks the App Bundle ZIP/manifest structure and passes the unsigned AAB through exact-SHA release artifact gating alongside the unsigned APK and separately installable preview APK. App-store signing and real device acceptance remain outstanding. - DNS rebinding/socket binding, Android SAF partial write recovery and live provider authorization tests remain P0 blockers. Consult cloud QA and production readiness.