5a679dfc904bc80c1ffc57268037926668a82a71
V1: Add owner-scoped folder pagination (list_folders_by_owner_paginated) - New method in FolderRepository trait, PG implementation, service & handler - Prevents IDOR by filtering folder listings to authenticated user V2: Enforce ownership checks on folder mutations - rename_folder, move_folder, delete_folder now require caller_id - Service verifies folder.owner_id == caller_id (returns 404 on mismatch) - Propagated to folder_handler, batch_handler, batch_operations, webdav_handler - delete_folder_with_trash upgraded from OptionalAuthUser to AuthUser - download_folder_zip now checks ownership before streaming V3: Fix XSS in frontend via DOM APIs - sharedView.js: innerHTML → createElement + textContent - contextMenus.js: innerHTML → DOM construction for share dialog Cleanup: removed unused OptionalAuthUser import, updated all stubs/mocks
A fast, simple alternative to NextCloud
NextCloud was too slow on my home server. So I built OxiCloud: a file storage system written in Rust that runs on minimal hardware and stays out of your way.
Why OxiCloud?
| Feature | What you get |
|---|---|
| Low resources | Runs on 512MB RAM. No PHP, no bloat. |
| Fast | Rust with LTO optimization. Sub-second responses. |
| Clean UI | Works on desktop and mobile. No clutter. |
| Easy setup | One binary, one database, done. |
| Multi-language | English, Spanish and Persian out of the box. |
Quick Start
You need Rust 1.70+, Cargo, and PostgreSQL 13+.
git clone https://github.com/DioCrafts/oxicloud.git
cd oxicloud
# Set up your database connection
echo "DATABASE_URL=postgres://username:password@localhost/oxicloud" > .env
# Build and run
cargo build --release
cargo run --bin migrate --features migrations
cargo run --release
Open http://localhost:8085 in your browser.
Docker (alternative)
docker compose up -d
That's it. The app runs on port 8086.
Architecture
OxiCloud uses Clean Architecture with four layers:
┌─────────────────────────────────────────┐
│ Interfaces │ API routes, handlers │
├─────────────────────────────────────────┤
│ Application │ Use cases, services │
├─────────────────────────────────────────┤
│ Domain │ Business logic │
├─────────────────────────────────────────┤
│ Infrastructure│ Database, filesystem │
└─────────────────────────────────────────┘
Each layer only talks to the one below it. You can swap out the database or add new API endpoints without touching business logic.
Development
cargo build # Build
cargo run # Run locally
cargo test # Run tests
cargo clippy # Lint
cargo fmt # Format
# For debugging
RUST_LOG=debug cargo run
Current Features
- File upload, download, and organization
- Folder management with drag-and-drop
- Trash bin with restore functionality
- User authentication with JWT
- Personal folders per user
- File deduplication
- Write-behind cache for fast uploads
- Search across files and folders
- Favorites and recent files
- Responsive grid/list views
What's Next
I'm working on these when I have time:
- File sharing via links
- WebDAV for desktop sync
- Basic versioning
- Mobile app improvements
Check TODO-LIST.md for the full list.
Contributing
The project is early stage. There's plenty to improve.
Read CONTRIBUTING.md before submitting a PR. Follow the Code of Conduct.
License
MIT. See LICENSE.
Star History
Questions? Open an issue. Want to help? PRs welcome.
Languages
Rust
63.5%
Hurl
10.2%
TypeScript
8.5%
Svelte
8.2%
Shell
3.8%
Other
5.6%
