8ef62109a38145eac80d6e3e73f0cbe973c40de1
Implements OIDC Authorization Code Flow for external identity providers (Authentik, Keycloak, etc.) with JIT user provisioning. New features: - OidcService with OpenID Discovery, JWKS caching, RS256 ID token validation - Authorization Code Flow: /api/auth/oidc/authorize -> IdP -> /api/auth/oidc/callback - JIT user provisioning from OIDC claims (sub, email, name, groups) - OIDC group-to-role mapping (admin_groups config) - Provider info endpoint: GET /api/auth/oidc/providers - Option to disable password login entirely (OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN) - Auto-provision toggle (OXICLOUD_OIDC_AUTO_PROVISION) - Email collision detection (security: prevents account takeover) Configuration (env vars): - OXICLOUD_OIDC_ENABLED, OXICLOUD_OIDC_ISSUER_URL - OXICLOUD_OIDC_CLIENT_ID, OXICLOUD_OIDC_CLIENT_SECRET - OXICLOUD_OIDC_REDIRECT_URI, OXICLOUD_OIDC_SCOPES - OXICLOUD_OIDC_FRONTEND_URL, OXICLOUD_OIDC_PROVIDER_NAME - OXICLOUD_OIDC_AUTO_PROVISION, OXICLOUD_OIDC_ADMIN_GROUPS - OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN DB migration: - ALTER TABLE auth.users ADD oidc_provider, oidc_subject columns - UNIQUE index on (oidc_provider, oidc_subject) Files changed: 14 files, ~1400 lines added Dependencies: reqwest 0.12 (rustls-tls-webpki-roots), base64 0.22
A fast, simple alternative to NextCloud
NextCloud was too slow on my home server. So I built OxiCloud: a file storage system written in Rust that runs on minimal hardware and stays out of your way.
Why OxiCloud?
| Feature | What you get |
|---|---|
| Low resources | Runs on 512MB RAM. No PHP, no bloat. |
| Fast | Rust with LTO optimization. Sub-second responses. |
| Clean UI | Works on desktop and mobile. No clutter. |
| Easy setup | One binary, one database, done. |
| Multi-language | English, Spanish and Persian out of the box. |
Quick Start
You need Rust 1.70+, Cargo, and PostgreSQL 13+.
git clone https://github.com/DioCrafts/oxicloud.git
cd oxicloud
# Set up your database connection
echo "DATABASE_URL=postgres://username:password@localhost/oxicloud" > .env
# Build and run
cargo build --release
cargo run --bin migrate --features migrations
cargo run --release
Open http://localhost:8085 in your browser.
Docker (alternative)
docker compose up -d
That's it. The app runs on port 8086.
Architecture
OxiCloud uses Clean Architecture with four layers:
┌─────────────────────────────────────────┐
│ Interfaces │ API routes, handlers │
├─────────────────────────────────────────┤
│ Application │ Use cases, services │
├─────────────────────────────────────────┤
│ Domain │ Business logic │
├─────────────────────────────────────────┤
│ Infrastructure│ Database, filesystem │
└─────────────────────────────────────────┘
Each layer only talks to the one below it. You can swap out the database or add new API endpoints without touching business logic.
Development
cargo build # Build
cargo run # Run locally
cargo test # Run tests
cargo clippy # Lint
cargo fmt # Format
# For debugging
RUST_LOG=debug cargo run
Current Features
- File upload, download, and organization
- Folder management with drag-and-drop
- Trash bin with restore functionality
- User authentication with JWT
- Personal folders per user
- File deduplication
- Write-behind cache for fast uploads
- Search across files and folders
- Favorites and recent files
- Responsive grid/list views
What's Next
I'm working on these when I have time:
- File sharing via links
- WebDAV for desktop sync
- Basic versioning
- Mobile app improvements
Check TODO-LIST.md for the full list.
Contributing
The project is early stage. There's plenty to improve.
Read CONTRIBUTING.md before submitting a PR. Follow the Code of Conduct.
License
MIT. See LICENSE.
Questions? Open an issue. Want to help? PRs welcome.
Languages
Rust
63.5%
Hurl
10.2%
TypeScript
8.5%
Svelte
8.2%
Shell
3.8%
Other
5.6%
