2.0.0
What's Changed
Summary
Complete refactor of the WebDAV server adding per-folder access control, LDAP support, OAuth/OIDC fix, security hardening, and a local test suite that mirrors CI.
Changes
Per-folder permissions
- New
FOLDER_PERMISSIONSenv var — define access per path:"/public:public:ro,/private:*:rw,/alice:alice:rw" - Supports
public(no auth),*(any authenticated user), or named users ro/rwmode per folder using configurableRO_METHODS/RW_METHODSAUTO_CREATE_FOLDERS— automatically creates directories at startup- Backward-compatible: omitting
FOLDER_PERMISSIONSfalls back to legacy single-root mode
Security hardening
TraceEnable Off— blocks HTTP TRACE method (XST prevention)- Removed pre-created empty DAV lock file that caused BDB0004 warnings
BROWSER_ACCESS_BLOCKED=false— optional flag to return 403 for all Mozilla/* User-Agents (blocks browsers, allows curl/cadaver/rclone/davfs2)
Test suite
- New
tests/directory with scenario scripts mirroring every CI job tests/run-all.sh— build once, run all scenarios locally- Scenarios: basic auth, read-only, user isolation, public-only, LDAP
tests/test-security.sh— full security assertions: path traversal, method restrictions, headers, user isolation- CI simplified to a single job with one build step and one step per scenario
Environment variables added
| Variable | Default | Description |
|---|---|---|
FOLDER_PERMISSIONS |
— | Per-folder access rules |
AUTO_CREATE_FOLDERS |
true |
Create folders at startup |
RO_METHODS |
GET HEAD OPTIONS PROPFIND |
Allowed methods for ro folders |
RW_METHODS |
GET HEAD OPTIONS PROPFIND PUT DELETE MKCOL COPY MOVE LOCK UNLOCK PROPPATCH |
Allowed methods for rw folders |
LDAP_ENABLED |
false |
Enable LDAP auth |
LDAP_URL |
— | LDAP server URL |
LDAP_BASE_DN |
— | Base DN for user search |
LDAP_ATTRIBUTE |
uid |
Attribute to match username |
LDAP_BIND_DN |
— | Bind DN for LDAP search |
LDAP_BIND_PASSWORD |
— | Bind password |
BROWSER_ACCESS_BLOCKED |
false |
Block Mozilla/* User-Agents |
- feat: WebDAV server refactor — per-folder permissions, LDAP, OAuth fix, security hardening by @vaggeliskls in #8
- feat: docsify github pages by @vaggeliskls in #9
Full Changelog: 1.1.2...2.0.0