v0.20.3
filex v0.20.3
Self-hosted file manager — Go single binary + multi-framework frontend.
Download a binary below, or pull a Docker image:
docker pull ghcr.io/brf-tech/filex:slim-v0.20.3
docker pull ghcr.io/brf-tech/filex:full-v0.20.3What changed
Three desktop fixes that came out of a real macOS 26 (Apple Silicon)
deployment (Berk, PR #9), one Connections-page fix, and — as a consequence of
the first — macOS packages on the release for the first time.
- Desktop pairing died in a browser that was already signed in. The
router's "signed-in users skip /login" redirect destroyed the query string
before the login view could stashdesktop_state/desktop_challenge, so
the browser showed a file manager with no code and no error while the app
waited forever. The stash now happens in the router guard, ahead of the
firstawait; a failed hand-off keeps the overlay and says so instead of
disappearing. - The embedded sync engine was x86_64 inside an arm64 app.
fetch-cli.mjs
defaultedGOARCHtoamd64; every launch on Apple Silicon raised macOS
26's Rosetta deprecation alert. It now follows the host arch (an explicit
GOARCHstill wins; CI's x64 runners are unaffected). - macOS packages:
filex-desktop-arm64.dmg+.zip, built on a pinned
macos-14runner. Unsigned, but ad-hoc sealed by anafterPackhook: a
no-certificate electron-builder output is only linker-signed, and macOS 26
treats that as tampering ("malware blocked and moved to Trash", no override);
the deep ad-hoc re-seal turns it into the ordinary "unverified developer /
Open Anyway" dialog. Auto-update on macOS stays inert until the app carries a
Developer ID (Squirrel.Mac refuses to swap an unsigned app); the zip and
latest-mac.ymlship anyway so the feed is right the day it does. The docs,
the README and the web app's download banner now list macOS honestly —
Apple Silicon only, unsigned, first-launch step included. - Connections page in dark mode: the panel painted its own page ground, and
five theme tokens did not exist..fe-connsetbackground: var(--fe-bg)
and drew a blue-black rectangle over the admin's zinc page (and a white one
over the light page) that ended where the panel ended; the API-tokens box
referenced--fe-surface,--fe-muted,--fe-accent,--fe-surface-2and
--fe-mono, none declared, so it had no ground, un-muted muted text and a
hardcoded-blue button next to a token-blue one. Fixed in the shared package
(web admin and the desktop app render the same component), 17 phantom token
uses corrected across core, and a test now refuses anyvar(--fe-*)that
variables.cssdoes not declare. - docs site: the hourly release rebuild had failed silently since 08-11 (no
PATHunder cron); it now sets its own, reports failure, and refuses to
publish an empty release list.