Security
- CSRF protection: All requests now go through Go's
http.CrossOriginProtection. Cross-origin state-changing requests (uploads, deletes, policy changes) are rejected. - Safer object serving: Downloads always get
Content-Disposition: attachment,application/octet-streamandX-Content-Type-Options: nosniff. Objects opened inline use the content type stored in S3 and never one sniffed from the body. Filenames inContent-Dispositionare now properly escaped. SHOW_VERSIONSnow applies to the metadata endpoint too: With versions turned off, old versions can no longer be read through/metadata?versionId=….
Bug fixes
- Listing large prefixes on older Ceph RGW (#10): Some providers mark a ListObjects V2 page as truncated but send no continuation token. When that happens, the bucket view, bulk delete and bulk ZIP download now fall back to ListObjects V1. Bulk operations resume from the last key they processed, so no object is handled twice.
- SSE-C objects can be read back: The configured SSE-C key is now sent with downloads, inline views, metadata lookups and bulk ZIP downloads, not only with uploads. Presigned and public links still don't carry the key, so they don't work for SSE-C objects.
- An invalid
SSE_TYPE/SSE_KEYnow fails at start-up instead of on the first upload. - An object that can't be read now returns a proper error status. Previously the response could start before the error was known.
- S3 errors are mapped to status codes and messages by their S3 error code instead of by matching message text, so 404s and "access denied" hints work across providers.
- "Last modified" in the metadata dialog now uses the same format and time zone (
TZ) as the bucket view. - The "Delete bucket" action only shows when
ALLOW_DELETEis on and you're on the unsearched top level of an empty bucket. It now asks for confirmation. - Version IDs in open/download links are URL-escaped.
- File icons: extension matching is case-insensitive, and
.jpegis recognized.
Breaking changes
FORCE_DOWNLOADhas been removed. "Download" always downloads and "Open" always opens inline.- Removed API endpoints:
DELETE /{instance}/api/buckets/{bucket}/objects/{key}: usePOST …/objects/bulk-deleteinstead, which also handles folders.GET /api/s3-instances
POST …/objects/bulk-deletenow returns204 No Contentinstead of200with{"success": true}.
Packaging & development
- Multi-arch container images: Release images are built for
linux/amd64andlinux/arm64(GoReleaser v2dockers_v2). Thelatesttag is no longer pushed by the release workflow. - CI only logs in to Docker Hub and pushes images on
pushevents, not on pull requests. - The CI Go version is read from
go.mod. - The local
compose.yamlsetup uses RustFS instead of MinIO. moqis pinned as a Go tool (go tool moq).- README: clarified
ALLOW_DELETE,BUCKET_NAME(a display filter, not an access restriction),SSE_TYPE/SSE_KEYand the reverse-proxy guidance.