Summary
- Major security hardening and auth upgrades
- New API token and passkey support
- Better OIDC handling, session persistence, and safer cookie/redirect rules
- Upload improvements, including chunked/resumable uploads and storage safeguards
- Trash and versioning features added/expanded
- Browser and archive support improvements
- Office document templates and integration enhancements
- Docker/runtime modernization for Node 24 and custom ffmpeg/7-Zip packaging
- Significant OpenAPI and API documentation work
Detailed changelog
1. Major security and auth improvements
- Added API token authentication support for scripts and automation.
- Tokens are scoped to read/write access.
- Read-only tokens are restricted from admin and sensitive routes.
- API tokens are explicitly rejected from account/admin routes.
- Added support for TOTP/2FA workflows and passkeys.
- Supports both password login and passkey sign-in.
- Added better error codes for invalid TOTP/passkey and unsupported auth flows.
- Improved OIDC configuration and reliability.
- Enforces required OIDC client secret and origin-aware callback handling.
- Better handling of provider outages and misconfigurations.
- Improved return URL validation and origin-specific session cookies.
- Added checks to ensure OIDC user info matches the authenticated subject.
- Added persisted session secret storage in CONFIG_DIR.
- Prevents logout storms caused by random secrets changing on restart.
- Can still be overridden explicitly with SESSION_SECRET.
- Added security header middleware.
- X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-Robots-Tag, and disables x-powered-by.
- Added request context middleware and better forwarding-address handling.
- Helps identify real client IPs when behind trusted proxies.
- Improved error handling and classification.
- Added service-unavailable and insufficient-storage error flows.
- Better sanitization of log output and client messages to avoid leaking filesystem paths.
2. Filesystem and access model improvements
- Added reserved system hidden directory protection.
- .nextexplorer is now treated as a reserved area and excluded from browsing/search.
- Added trash system and admin-controlled retention.
- Files are moved to a reserved trash area instead of immediate deletion.
- Supports retention days, size limits, and maintenance cleanup.
- Added file versioning support.
- Keeps previous versions of files with retention policies.
- Includes version cleanup and admin controls.
- Added folder-size indexing improvements.
- Supports modes like off/shallow/full.
- Allows more precise exclusion rules and refresh scheduling.
- Added access rules and finer permission handling.
- Supports read/write and hidden access patterns.
- Added activity logging.
- Records meaningful actions/outcomes for audit and admin review.
- Can be enabled/disabled and retained for a configurable period.
3. Uploads and transfer reliability
- Added upload inactivity timeout and upload storage reserve controls.
- Added chunked/resumable upload support via TUS.
- Upload metadata, finalization, cleanup, and resume logic.
- Added more robust multipart upload refusal handling.
- Better 400/413 responses for oversized or malformed uploads.
- Added upload storage guards to avoid disk-full and invalid write conditions.
- Added safeguards for direct uploads and JSON request limits.
- Prevents excessive request bodies and runaway uploads.
- Added support for folder-upload sessions and upload finalization tracking.
4. Archive handling and extraction
- Significant archive support upgrades.
- Added better handling for browsing archive contents without extraction.
- Added extraction support for entries/folders.
- Added archive limits for total size and entry count.
- Added archive browsing cache and preflight size checks.
- Added 7-Zip integration with official static binary.
- Supports RAR, encrypted ZIP/7z archives, and password-protected extraction.
- Improved extraction and validation safety.
- Detects encrypted archives, oversized archives, invalid entries, and missing destinations.
- Added archive-specific route handling for listing, extracting, and reading entries.
5. Preview and thumbnail generation
- Stronger media and preview pipeline.
- Added better ffmpeg selection and validation.
- Added thumbnail diagnostics and background queue settings.
- Added configurable video thumbnail settings, concurrency, and seek behavior.
- Improved RAW and document preview handling.
- Better support for EXIF and document previews with configurable cache settings.
- Added safer thumbnail access handling and derived secrets.
- Improved preview rendering constraints and cache cleanup logic.
6. Office document and editor integration
- Added blank office template assets:
- new.docx
- new.xlsx
- new.pptx
- new.pdf
- Added new office document creation support from templates.
- Improved OnlyOffice integration.
- Added config, session heartbeat, end-of-session, force-save, history, save-as, and file-serving flows.
- Includes secure signing and integration-specific auth.
- Improved Collabora/WOPI integration support.
- Added WOPI file info, lock handling, file read/write, and config flows.
- Added support for editor and document session tracking.
7. OpenAPI/API documentation expansion
- Added a major OpenAPI spec and route documentation layer.
- Builds an OpenAPI 3.1 schema for the application.
- Documents auth, browsing, files, uploads, sharing, versions, activities, integrations, and admin routes.
- Added route-level access metadata and clearer API semantics.
- Improved API documentation around token scope restrictions and editor integrations.
8. Docker and runtime modernization
- Dockerfiles were substantially overhauled.
- Updated base images to Node 24 and Alpine 3.24.
- Added custom ffmpeg build and validation steps.
- Added official static 7-Zip installation.
- Improved runtime package selection to reduce image size and security issues.
- Custom ffmpeg variants allow:
- lean builds using compiled-source ffmpeg
- full package-based variant
- selective runtime installation depending on build args
- Added environment-driven runtime options to control:
- ffmpeg variant
- VAAPI support
- RAW support
- many preview and performance settings
- Added runtime versioning and health endpoints:
- /healthz
- /readyz
- Added Node engine requirement:
- backend package now declares Node >=24 <25
9. Developer experience and build upgrades
- Dependency updates across the backend:
- upgraded Node-pty, adm-zip, archiver, better-sqlite3, express-openid-connect, sharp, vitest, etc.
- Added OpenAPI generation script and build tooling.
- Added docs package and dev Docker support.
- Improved lint/test configuration and coverage output.
10. Configuration and environment changes
- Added many new configuration options for:
- uploads
- archive limits
- trash/versions
- previews
- OIDC
- activity log
- folder-size indexing
- performance diagnostics
- demo mode
- Deprecated and tightened previous defaults:
- CORS now defaults to deny unless explicitly configured
- OIDC is only enabled with sufficient config
- session secret handling is safer and more persistent
- security headers are enabled by default
- Added secret read helper to avoid exposing secrets from environment in logs.
11. Notable behavioral changes / breaking considerations
- This is not an incremental maintenance release; it changes operational behavior.
- A stricter default security posture:
- fewer routes are public by default
- CORS is more restrictive unless configured
- auth settings are validated more strictly
- OIDC deployment requirements:
- OIDC_CLIENT_SECRET is effectively now required
- public/base URL/origin handling is more strict
- Storage-related changes:
- trash/versioning and upload protections are active by default
- Docker/runtime changes:
- Node 24 requirement and Alpine 3.24 runtime
- custom ffmpeg/7-Zip packaging may affect image build and runtime expectations