BoxBox v0.3.0: file and folder sharing for a self-hosted file manager
A few months ago I wrote about building BoxBox , a self-hosted file manager for homelabs and NAS boxes. v0.3.0 is out, with file and folder sharing. Music: "the kill 2" by Lex Amarni & 2muchmotion. What's new File and folder sharing. Every file or folder gets a token link. Folder links come in four levels: View only, Upload only, Upload + delete, and Full access. Links can expire and can be…
BoxBox v0.3.0 has been released, introducing file and folder sharing capabilities for self-hosted file managers in homelabs and NAS boxes. Each file or folder is assigned a unique token link, with four sharing options: View only, Upload only, Upload + delete, and Full access. Links can expire and be revoked. A public share page allows recipients to access a path bar, file list, previews, a read-only code editor (editable with full access), arrow-key navigation, and ZIP downloads without requiring an account.
Folder uploads are supported by simply dropping a folder into the share. Uploads occur in chunks, preserving nested paths. Drives and Places are introduced, with top-level mounts representing drives and nested mounts showing up under Places. Recipients can override the mount type using the kind: option in the config.
Each user's wallpaper is stored on the server and displayed on share pages. Sharing from a box that holds everything requires careful consideration, as the token serves as the sole credential. Each link consists of 32 random bytes from crypto/rand, encoded as 43 URL-safe characters. Recipient endpoints are public, with their own per-IP rate limit separate from login.
All failure cases return a 404 status, ensuring that guessing tokens reveals no information about past links. The path is re-checked on every request, as shares store paths rather than promises. If a mount is removed, renamed, or becomes read-only, its links will no longer function or allow uploads. Upload-only restrictions prevent recipients from overwriting existing files, which are saved in a temporary file and renamed using renameat2(RENAME_NOREPLACE) on Linux, guaranteeing no replacement.
On other platforms, a hard link is created followed by a removal, maintaining the same atomic replacement prevention. Revocation of a link halts ongoing uploads.
Recipient previews and downloads utilize the same sandboxed Content-Security-Policy as the main app, preventing scripts from running on the BoxBox origin. ZIP archives are contained within the share, with traversal and resolved path checks against the share root to prevent symlink attacks from accessing files outside the intended scope.
Recipient responses do not include mount names or server paths, ensuring privacy. The share store is set to 0700 permissions, and the token-bearing shares.json file is set to 0600 permissions. Upgrading to v0.3.0 requires changing the container to listen on port 8080 instead of 80, with corresponding adjustments in port mapping, healthcheck configuration, and reverse proxy settings.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.