Repository navigation
Release v0.1.4
Release Notes
v0.1.4 — Migration Consolidation & Bug Fixes
Bug Fixes
- Fixed
validate_parents_privacySQL —path = (?1 OR ?2)replaced withpath = ?1 OR path = ?2(Issue #14) - Fixed Postgres
EXISTS()— wrapped inCASE WHEN EXISTS(...) THEN 1 ELSE 0 ENDfor all engines (Issue #11) - Fixed Postgres
idcolumns — now useGENERATED BY DEFAULT AS IDENTITYfor compatibility (Issue #11) - Fixed MySQL
idcolumns — now useAUTO_INCREMENTduring migration preprocessing (Issue #11) - Fixed
BOOLEANdecode failures —BOOLEANreplaced withSMALLINT NOT NULL DEFAULT 0in base migration (Issue #15) - Fixed
ppdrive serve—--portis now optional, defaults to config file value or8000(Issue #13) - Fixed SQLite database path — resolved against
root_dir()instead of CWD (Issue #13) - Fixed public file serving — uses
root_dir().join(relative)to prevent..traversal (Issue #13) - Fixed
SHA256SUMS.txt— uses shell glob instead offind .for cross-platform compatibility (Issue #12) - Fixed
validate_bucket_path— absolute paths now rejected before trimming (Issue #10) - Fixed
bucket::create— paths normalized to always start with/(Issue #9) - Fixed
root_dir.join()— bucket paths trimmed of leading/to prevent double-joining - Fixed upload file containment — validates storage path is within bucket rather than re-resolving
- Fixed privacy rules — public buckets cannot be created inside private parents (bidirectional enforcement)
Internal
- Consolidated migrations into a single
migrations/folder (removedmigrations_postgres/) shared::db— complete rewrite:resolve_sqlite_url(),run_mysql_migrations(),run_postgres_migrations(),MIGRATION_FILESconst withinclude_str!for compile-time embeddingDbEnginederivesPartialEq, Eqfor testabilitysqlx::migrate::MigratorwithMigrator::with_migrations()for preprocessed migrations
Documentation
- Updated bucket API docs — path validation rules, absolute path rejection, bidirectional privacy constraint
- Updated database schema docs —
SMALLINTinstead ofBOOLEAN,file_permissionstable, Postgres identity columns - Updated config docs —
root_dirnote about SQLite resolution,file_permissionsindex - Updated CLI bucket docs — path validation rules added
v0.1.3 — Bug Fixes
Bug Fixes
- Fixed
ppdrive servefailing when run outside the project root — server binary now resolves viashared::root_dir()instead of CWD-relative./server - Fixed Postgres startup crash — created
migrations_postgres/withBYTEA(notBLOB) and engine-specific migration dispatch - Fixed SQLite BOOLEAN decode failures —
publicandEXISTSqueries now decode asi32across all engines - Fixed 500 "Unable To Extract Key!" without a proxy — rate limiter now falls back to the direct
SocketAddrviainto_make_service_with_connect_info - Fixed config parse failure when
static_foldersis omitted — added#[serde(default)]
v0.1.1 — File-Level Privacy & User Auth
Highlights
- File-level permissions — Fine-grained ACLs on private bucket files. Grant read, write, or admin permissions to clients or users.
- User authentication —
POST /auth/loginendpoint for email/password login. Users can manage file permissions alongside clients. - Permission API —
POST/DELETE/GET /buckets/{pid}/permissionsfor granting, revoking, and listing file permissions. - Auto-registration — Files uploaded to private buckets are automatically registered as assets with admin permissions for the uploader.
- Asset CLI —
ppdrive asset grant/revoke/listcommands for managing file permissions from the terminal. - User CLI —
ppdrive user createcommand for creating user accounts. - AuthExtractor — Middleware supports both client tokens (
x-ppdrive-client) and user Bearer tokens (Authorization: Bearer).
Bug Fixes
- Fixed download flow to use proper bucket owner check instead of broken
check_ownership - Fixed
list_permissionsqueries to resolve grantees from both clients and users tables - Fixed user
createto includeupdated_atfield
Documentation
- Added File Permissions API reference
- Added User Authentication API reference
- Added Asset and User CLI command docs
- Added "How It Works" section to homepage with upload/download examples
- Updated Authentication page to cover both client and user auth
- Updated Download page to document file-level permission checks
- Updated Upload page to document private bucket asset auto-registration
Internal
- Made
validatoralways enabled in shared crate (no longer feature-gated) - Added
hexdependency for user token signing - Added
is_adminfield to users migration
v0.1.0 — First Stable Release
Highlights
- Per-IP rate limiting (100 req/s, burst 200)
POST /bucketsAPI for client bucket creation- HTTP metrics at
/metrics(Prometheus) - Health check at
/health - Graceful shutdown (SIGINT/SIGTERM)
- Configurable DB pool size via
db_pool_size - Request timeout (30s, HTTP 408)
- Temp file background cleanup (hourly, 2hr max age)
Security
- Timing-safe token comparison (Blake3)
- Stable ChaCha20-Poly1305 encryption
- Path traversal protection via
Path::components() - No hardcoded database credentials
- Secrets file: 56 bytes, mode
0600, zeroed on drop #[serde(deny_unknown_fields)]on all API request structs- Input validation on all API fields (length, range, format)
Bug Fixes
- Fixed dollar-sign format string in token parsing
- Fixed download route concurrency limit
- Fixed JSON error responses (no HTML leaking)
- Fixed path resolution (no directory creation on check)
- Fixed bucket size check using
get_folder_size - Fixed
AssetOwnerName::from(i16)silent default - Fixed
.unwrap()onHeaderValue::from_strin download handler
Performance
spawn_blockingfor path resolution (N+1 query fix)- SQLite WAL mode enabled
- Configurable connection pool size (
db_pool_size, default 10) - Connection pool: 30min max lifetime, 5min idle timeout
Docker & Deployment
- Multi-stage Dockerfile with non-root user
HEALTHCHECKin Dockerfile- Docker Compose with PostgreSQL + Redis
- Docker Compose health checks with
service_healthyconditions - Fixed port mapping (8000:8000)
- Volume mounts preserve config file
Install Scripts
- macOS support in
install.sh - ARM64 support (Linux, macOS, Windows)
- Version check (skip install if up to date)
- Windows: fixed URLs, User PATH (no admin required)
- Cleanup on failure (not just happy path)
Platforms
Linux (x86_64, arm64), macOS (x86_64, arm64), Windows (x86_64)