Repository navigation
What's Changed
Important
This version represents the most significant change to date. It requires both a database migration and config structural changes. See the migration guide for step-by-step upgrade instructions, About v2.0.0 for a full summary.
Tip
Also, consider enabling "analytics" in admin settings, which will help me populate an anonymous public dashboard for everyone to see. Currently, there are 60 deployments details populated from beta, so after a percentage of you enable this, there should be plenty to make the dashboard available to everyone soon. No private information is used -- you can see exactly what data is sent in the UI.
Breaking Changes:
- Removed:
GET /api/rawandGET /public/api/rawdownload routes β use/api/resources/downloadinstead. - Removed:
/share/β¦URL redirect to/public/share/β¦β use/public/share/β¦directly. - Removed: singular
sourcesearch api param (usesources), barescopepaths withoutsourceName:prefix, andglob/useGlobaliases (useuseWildcard). - Removed
config.conditionals, source-levelindexingIntervalMinutes(indexing always uses adaptive scheduling), and deprecated rule fieldsfileNames/folderNames/ top-levelhiddenβ useconfig.ruleswithfileName,folderName, andignoreHiddenon rules. See Exclusion rules. - Removed: deprecated
userDefaultsconfig formats (nested and flat) β use the config migration tool to convert before upgrading. - Changed:
PUT /api/usersmoved to the more appropriatePATCHmethod and requires specifyingwhichin the body. Blank orallvalues are rejected. - Changed: HTTP-related config options in
serverconfig key moved tohttpconfig key. See HTTP settings. - Changed (reverse proxy):
http.trustedHeaders(v1.5.x list) removed β usehttp.trustProxyHeaders: truewhen behind nginx, Traefik, or Caddy. When enabled, FileBrowser honorsX-Forwarded-Host,X-Forwarded-Proto,X-Forwarded-For, andX-Real-IPfor client IP, cookies, OIDC callbacks, WebAuthn, share URLs, rate limiting, and activity logs. Default isfalse(direct connection values). The config migration tool converts v1trustedHeaderslists totrustProxyHeaders: true. See Reverse proxy and HTTP trustProxyHeaders. - Changed:
FILEBROWSER_DATABASEenvironment variable β useFILEBROWSER_DATABASE_PATHinstead. See Environment variables and Server settings. - Changed: Moved stream api to
/api/media/stream. See API reference. - Changed: CLI user management β canonical commands are
user set <username> --password [value]anduser promote <username>;set -u username,passwordis deprecated. See CLI reference.
Security:
- [Low] Public share lyrics and subtitle routes honor the share's file-viewer setting, download disable flag, and download limits (GHSA-p7x3-p5jj-9xfh) -- thanks Yves Soete of Blacksight LLC. @yssoe
- Fresh installs with default
admin/admingenerate a random initial password and log it once (#2977). - OIDC login binds OAuth
stateto an HttpOnly cookie and rejects tampered callbacks; login/logout/session-expiry redirects reject open-redirect targets, and signup sends credentials in a JSON body instead of query parameters.
New Features:
- View grant mechanism to distinguish between UI viewing and download. See Access control overview.
- granular per-source file permissions (view, download, modify, create, delete) with automatic migration from global permissions
- per-source defaults configurable in
settings > access management viewpermission is automatically set to true unless explicitly set to false. See Access control overview.- can be enforced for all users. See Access control overview.
- per-source defaults configurable in
- New activity logs for user activity.
- charts and historical data
- export to csv reports
- Media player improvements:
- Refreshed playback queue UI: Supports thumbnails, stored into session storage, and has a "clear queue" button (#2575) (#2600).
- Loop now has 3 states (off/single/all) and neither of them will clear the existing queue (#2600).
- New "Audio visualizer" for audio files (desktop-only), you can configure some basic things to your taste (#2575) (#2620).
- The current state of the audio panel now is stored into local storage.
- More gestures: Swipe up to enter/exit fullscreen, long-press to change playback speed, single tap to pause (#2575).
- Videos now will resume fullscreen and PiP when navigating (queue auto-navigation, swipes gestures or next/previous) (#2649).
- Added
F4shortcut to refresh the current directory and metadata (#2600). - opt-in feature to send deployment analytics to filebrowser quantum developer servers
- anonymized with a viewer so users can see what info would be sent.
- if opt-in, every month a snapshot of your deployment config would be sent to developer servers
- this will help me know what features are being used and what versions everyone is on over time. I will also provide a public dashboard with this information in the future.
- WebDAV now supports set modification time via the
X-OC-Mtimeheader for clients that support it (#2626). See WebDAV docs. - Copy operations now preserve their original modification times (#2642) (#2647):
- WebUI preserves both, files and directories.
- WebDAV
COPYpreserves modification times only for files, is limitation we have with webdav.
- User default enhancements
- Config
userDefaultsseeds SQLite on first run; only fields explicitly set in config stay locked in Settings β User defaults (other defaults remain editable) - Added administrator controls for universal user defaults and enforced preferences in
settings > user management > user defaults. - Added configurable default file permissions per source in
settings > access management. - Added a User Defaults editor for account, permission, and profile preferences in the edit/create user prompt. See User management.
- Config
- Database env var rename:
FILEBROWSER_DATABASEis removed (startup fails if set). UseFILEBROWSER_DATABASE_PATH(defaultfilebrowser.sqlite) orserver.database.pathin config. See Environment variables and Server settings. - CLI:
user setwith--password(inline value, interactive prompt on TTY, or piped stdin);user promotefor admin grant without password reset. See CLI reference. - Require password change at next login for password-based users: new user setting
requirePasswordChange(user defaults + per-user admin toggle). Bootstrap admins with a generated initial password get this automatically (#2977). Generated bootstrap passwords use a speakableword-xxxxx-xxform. - PWA improvements for installed mobile apps: dedicated maskable icons (192/512), manifest and splash colors that follow the instance default theme, runtime
theme-colorsync on dark-mode toggle, and edge-to-edge safe-area layout for notched devices (#2625) (#2869) -- thanks @APatenaude - Users can set default view mode and thumbnail size from Profile settings (Listing options). Admins can set the same defaults for existing users and edit all profile preference defaults from the user management panel (#2884).
- Added "Upload only what's missing" to the upload conflict prompt (#2985) (#2553)
- Added
initCLI command, which creates a minimal commented config.yaml instead of a full config (#2957) - Config YAML expands
$VARand${VAR}so values such asuserPassword: "${FILEBROWSER_LDAP_USER_PASSWORD}"work (#3042). - Sidebar source links can switch between aggregated usage (default) and a root-filesystem-only view via a new "Limit disk usage to source filesystem" toggle.
Notes:
- v2.x.x uses a new write-through backend state management. Changes go through a fast memory layer and also write changes to database to stay in sync. See About v2.0.0.
- CLI server start (
./filebrowser),setup,version, andset rulesyntax unchanged; see CLI docs - new dropdown and input styles
- swipe gestures to dismiss notifications (#2672)
- user updates are more granular, don't include entire user payload.
user.idhas been moved to a backend property and all frontend apis now query users by username. Swagger has been updated. See API reference.- removed legacy and deprecated properties from API responses and generated config output
/api/media/streamis audio/video only (range-based chunking). Non-media inline viewing usesGET /api/resources/view. Both endpoints use the sameviewTokenfrom file metadata. See API reference.- removed exiftool as an optional helper, always built with the supported libraries (requires 64 bit os)
- If migration issues arise, see Migration troubleshooting.
- default browser media player option removed, always uses themed plyr
- [docker] upgraded ffmpeg from 8.1.2 to 9.0
- Sidebar navigation tree rows are real hyperlinks: middle-click, Ctrl/Cmd+click, and Shift+click use the browser's default new-tab or new-window behavior.
- Pop-up preview has a 200ms debounce delay so it doesn't flash when moving the cursor across files quickly.
- Improved UI responsiveness for larger directories and Firefox, with marginal memory improvement (#1773) (#2879)
- Improvements to document thumbnail generation performance.
- Changed behavior for typing to select files in listing view; added more actions in advanced search (#2776).
- Session renew is handled by client keep-alive; per-request
X-Renew-Tokenheader handling removed. defaultEnablednow means the source is always added to users on startup and login.- Webdav always shows hidden files, ignores the user preference. (#3004)
- Share download links no longer embed a token; they link to the UI, which prompts for the password before download. For direct downloads use the documented
/api/share/directAPI. (#2888) - Sidebar links follow source changes: renaming a source updates links, disabling/deleting a user source removes them (#2878) (#2942), and adding a source via scopes auto-adds a link.
/api/resources/downloadand/public/api/resources/downloadreturn HTTP 404 for missing files/directories instead of 500 (#2981);GET /api/resourcesreturns 400 whenpathis missing or empty (#2801).- Added risc-v to official releases.
- A CLI password reset returns the user to a password-method user.
Bugfixes:
- Long uploads/downloads no longer lose the session mid-transfer; session keep-alive renews before expiry and auto-logout is disabled during active transfers (#2638).
- OIDC:
groupsClaimis always requested and falls back to UserInfo; the verified ID-token identifier is preserved on fallback; sessions respecttokenExpirationHours(#3006). - LDAP
userGroupsmatching accepts CN-only values against fullmemberOfDNs and is case-insensitive (#3044). - Fixed PDF thumbnail process aborts (#2763), PDF preview blocking uploads (#2752), and 401 on the PDF download button (#2978).
- Fixed multiple embedded subtitles with the same language (#2756).
- Fixed Fuji
.rafthumbnail preview; unsupported image preview formats return HTTP 415 instead of 500. - Members without download permission could not open text-based files with OnlyOffice enabled (#2777).
- Fixed iOS 26 / WebKit multi-chunk upload stall by isolating chunk connections (#2734).
- Mobile/UI fixes: upload options cut off (#2685), uploaded image cut off (#2765), next/previous buttons hiding on photos (#2767), missing gallery download button (#2767), double-tap to zoom, html viewer height, tooltips on mobile, assorted styling inconsistencies (#2908).
- Public share folder and multi-file ZIP downloads were empty for anonymous visitors on sources with deny-by-default/path rules (#2631) (#2365).
- Preserve Ctrl-click selection with stale keyboard state (#2958) (#2923); avoid false stalls in parallel transfers (#2950) (#2948) thanks @gudcks0305; hide Replace on conflict prompts when the user lacks modify permission (#2837).
- Disk usage: fixed overstatement on virtiofs/Docker Desktop (#2894), inflated usage across ZFS datasets/btrfs subvolumes (#3025) (#2997), capped usage bars at 100% and summed nested mounts on Linux (#2761) (#2238).
- Support non-ASCII share passwords (#2933); fall back to buffered copies when FUSE rejects fast paths (#2938) (#2924); tilde (
~) source paths expand properly. - Fixed slow/broken file listing when
http.baseURLis a subpath.
Full Changelog: v1.5.8-stable...v2.0.0-stable