github nxzai/NextExplorer v4.0.0
Major security, auth, file lifecycle, upload, archive, and editor integration

pre-release3 hours ago

Summary

  • Major security hardening and auth upgrades
  • New API token and passkey support
  • Better OIDC handling, session persistence, and safer cookie/redirect rules
  • Upload improvements, including chunked/resumable uploads and storage safeguards
  • Trash and versioning features added/expanded
  • Browser and archive support improvements
  • Office document templates and integration enhancements
  • Docker/runtime modernization for Node 24 and custom ffmpeg/7-Zip packaging
  • Significant OpenAPI and API documentation work

Detailed changelog

1. Major security and auth improvements

  • Added API token authentication support for scripts and automation.
    • Tokens are scoped to read/write access.
    • Read-only tokens are restricted from admin and sensitive routes.
    • API tokens are explicitly rejected from account/admin routes.
  • Added support for TOTP/2FA workflows and passkeys.
    • Supports both password login and passkey sign-in.
    • Added better error codes for invalid TOTP/passkey and unsupported auth flows.
  • Improved OIDC configuration and reliability.
    • Enforces required OIDC client secret and origin-aware callback handling.
    • Better handling of provider outages and misconfigurations.
    • Improved return URL validation and origin-specific session cookies.
    • Added checks to ensure OIDC user info matches the authenticated subject.
  • Added persisted session secret storage in CONFIG_DIR.
    • Prevents logout storms caused by random secrets changing on restart.
    • Can still be overridden explicitly with SESSION_SECRET.
  • Added security header middleware.
    • X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-Robots-Tag, and disables x-powered-by.
  • Added request context middleware and better forwarding-address handling.
    • Helps identify real client IPs when behind trusted proxies.
  • Improved error handling and classification.
    • Added service-unavailable and insufficient-storage error flows.
    • Better sanitization of log output and client messages to avoid leaking filesystem paths.

2. Filesystem and access model improvements

  • Added reserved system hidden directory protection.
    • .nextexplorer is now treated as a reserved area and excluded from browsing/search.
  • Added trash system and admin-controlled retention.
    • Files are moved to a reserved trash area instead of immediate deletion.
    • Supports retention days, size limits, and maintenance cleanup.
  • Added file versioning support.
    • Keeps previous versions of files with retention policies.
    • Includes version cleanup and admin controls.
  • Added folder-size indexing improvements.
    • Supports modes like off/shallow/full.
    • Allows more precise exclusion rules and refresh scheduling.
  • Added access rules and finer permission handling.
    • Supports read/write and hidden access patterns.
  • Added activity logging.
    • Records meaningful actions/outcomes for audit and admin review.
    • Can be enabled/disabled and retained for a configurable period.

3. Uploads and transfer reliability

  • Added upload inactivity timeout and upload storage reserve controls.
  • Added chunked/resumable upload support via TUS.
    • Upload metadata, finalization, cleanup, and resume logic.
  • Added more robust multipart upload refusal handling.
    • Better 400/413 responses for oversized or malformed uploads.
  • Added upload storage guards to avoid disk-full and invalid write conditions.
  • Added safeguards for direct uploads and JSON request limits.
    • Prevents excessive request bodies and runaway uploads.
  • Added support for folder-upload sessions and upload finalization tracking.

4. Archive handling and extraction

  • Significant archive support upgrades.
    • Added better handling for browsing archive contents without extraction.
    • Added extraction support for entries/folders.
    • Added archive limits for total size and entry count.
    • Added archive browsing cache and preflight size checks.
  • Added 7-Zip integration with official static binary.
    • Supports RAR, encrypted ZIP/7z archives, and password-protected extraction.
  • Improved extraction and validation safety.
    • Detects encrypted archives, oversized archives, invalid entries, and missing destinations.
  • Added archive-specific route handling for listing, extracting, and reading entries.

5. Preview and thumbnail generation

  • Stronger media and preview pipeline.
    • Added better ffmpeg selection and validation.
    • Added thumbnail diagnostics and background queue settings.
    • Added configurable video thumbnail settings, concurrency, and seek behavior.
  • Improved RAW and document preview handling.
    • Better support for EXIF and document previews with configurable cache settings.
  • Added safer thumbnail access handling and derived secrets.
  • Improved preview rendering constraints and cache cleanup logic.

6. Office document and editor integration

  • Added blank office template assets:
    • new.docx
    • new.xlsx
    • new.pptx
    • new.pdf
  • Added new office document creation support from templates.
  • Improved OnlyOffice integration.
    • Added config, session heartbeat, end-of-session, force-save, history, save-as, and file-serving flows.
    • Includes secure signing and integration-specific auth.
  • Improved Collabora/WOPI integration support.
    • Added WOPI file info, lock handling, file read/write, and config flows.
  • Added support for editor and document session tracking.

7. OpenAPI/API documentation expansion

  • Added a major OpenAPI spec and route documentation layer.
    • Builds an OpenAPI 3.1 schema for the application.
    • Documents auth, browsing, files, uploads, sharing, versions, activities, integrations, and admin routes.
  • Added route-level access metadata and clearer API semantics.
  • Improved API documentation around token scope restrictions and editor integrations.

8. Docker and runtime modernization

  • Dockerfiles were substantially overhauled.
    • Updated base images to Node 24 and Alpine 3.24.
    • Added custom ffmpeg build and validation steps.
    • Added official static 7-Zip installation.
    • Improved runtime package selection to reduce image size and security issues.
  • Custom ffmpeg variants allow:
    • lean builds using compiled-source ffmpeg
    • full package-based variant
    • selective runtime installation depending on build args
  • Added environment-driven runtime options to control:
    • ffmpeg variant
    • VAAPI support
    • RAW support
    • many preview and performance settings
  • Added runtime versioning and health endpoints:
    • /healthz
    • /readyz
  • Added Node engine requirement:
    • backend package now declares Node >=24 <25

9. Developer experience and build upgrades

  • Dependency updates across the backend:
    • upgraded Node-pty, adm-zip, archiver, better-sqlite3, express-openid-connect, sharp, vitest, etc.
  • Added OpenAPI generation script and build tooling.
  • Added docs package and dev Docker support.
  • Improved lint/test configuration and coverage output.

10. Configuration and environment changes

  • Added many new configuration options for:
    • uploads
    • archive limits
    • trash/versions
    • previews
    • OIDC
    • activity log
    • folder-size indexing
    • performance diagnostics
    • demo mode
  • Deprecated and tightened previous defaults:
    • CORS now defaults to deny unless explicitly configured
    • OIDC is only enabled with sufficient config
    • session secret handling is safer and more persistent
    • security headers are enabled by default
  • Added secret read helper to avoid exposing secrets from environment in logs.

11. Notable behavioral changes / breaking considerations

  • This is not an incremental maintenance release; it changes operational behavior.
  • A stricter default security posture:
    • fewer routes are public by default
    • CORS is more restrictive unless configured
    • auth settings are validated more strictly
  • OIDC deployment requirements:
    • OIDC_CLIENT_SECRET is effectively now required
    • public/base URL/origin handling is more strict
  • Storage-related changes:
    • trash/versioning and upload protections are active by default
  • Docker/runtime changes:
    • Node 24 requirement and Alpine 3.24 runtime
    • custom ffmpeg/7-Zip packaging may affect image build and runtime expectations

Don't miss a new NextExplorer release

NewReleases is sending notifications on new releases.