{
  "id": 12349815,
  "title": "BoxBox v0.3.0: file and folder sharing for a self-hosted file manager",
  "url": "https://urgent.news/2026/10/06/boxbox-v0-3-0-file-and-folder-sharing-for-a-self-hosted-file-manager",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T09:50:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jr4dh3y/boxbox-v030-file-and-folder-sharing-for-a-self-hosted-file-manager-3aof"
  },
  "original_language": "en",
  "account": "BoxBox v0.3.0 has been released, introducing file and folder sharing capabilities for self-hosted file managers in homelabs and NAS boxes. Each file or folder is assigned a unique token link, with four sharing options: View only, Upload only, Upload + delete, and Full access. Links can expire and be revoked. A public share page allows recipients to access a path bar, file list, previews, a read-only code editor (editable with full access), arrow-key navigation, and ZIP downloads without requiring an account.\n\nFolder uploads are supported by simply dropping a folder into the share. Uploads occur in chunks, preserving nested paths. Drives and Places are introduced, with top-level mounts representing drives and nested mounts showing up under Places. Recipients can override the mount type using the kind: option in the config.\n\nEach user's wallpaper is stored on the server and displayed on share pages. Sharing from a box that holds everything requires careful consideration, as the token serves as the sole credential. Each link consists of 32 random bytes from crypto/rand, encoded as 43 URL-safe characters. Recipient endpoints are public, with their own per-IP rate limit separate from login. All failure cases return a 404 status, ensuring that guessing tokens reveals no information about past links. The path is re-checked on every request, as shares store paths rather than promises. If a mount is removed, renamed, or becomes read-only, its links will no longer function or allow uploads. Upload-only restrictions prevent recipients from overwriting existing files, which are saved in a temporary file and renamed using renameat2(RENAME_NOREPLACE) on Linux, guaranteeing no replacement. On other platforms, a hard link is created followed by a removal, maintaining the same atomic replacement prevention. Revocation of a link halts ongoing uploads.\n\nRecipient previews and downloads utilize the same sandboxed Content-Security-Policy as the main app, preventing scripts from running on the BoxBox origin. ZIP archives are contained within the share, with traversal and resolved path checks against the share root to prevent symlink attacks from accessing files outside the intended scope. Recipient responses do not include mount names or server paths, ensuring privacy. The share store is set to 0700 permissions, and the token-bearing shares.json file is set to 0600 permissions. Upgrading to v0.3.0 requires changing the container to listen on port 8080 instead of 80, with corresponding adjustments in port mapping, healthcheck configuration, and reverse proxy settings.",
  "summary": "A few months ago I wrote about building BoxBox , a self-hosted file manager for homelabs and NAS boxes. v0.3.0 is out, with file and folder sharing. Music: \"the kill 2\" by Lex Amarni & 2muchmotion. What's new File and folder sharing. Every file or folder gets a token link. Folder links come in four levels: View only, Upload only, Upload + delete, and Full access. Links can expire and can be…",
  "key_points": [
    "BoxBox v0.3.0 adds file and folder sharing for self-hosted file managers",
    "Unique token links assigned to each file/folder with four sharing options",
    "Recipients can view, upload, delete, or have full access to shared content"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}