Skip to content

Improve folder sharing and ZIP downloads - #124

Merged
jR4dh3y merged 6 commits into
masterfrom
hoplite/phigaleia-bbde5f09
Sep 26, 2026
Merged

jR4dh3y merged 6 commits into
masterfrom
hoplite/phigaleia-bbde5f09

Conversation

@usehoplite

@usehoplite usehoplite Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

What changed

  • Add view-only, upload-only, and upload-plus-delete folder links with per-link upload limits, plus owner-side share listing and revocation in Settings.
  • Preserve legacy write-link replacement behavior without granting replacement to modern upload-only links.
  • Add bounded ZIP downloads for regular and public shared folders, with path-boundary checks and collision-safe names.
  • Make the file context menu opaque over wallpapers.

Screenshots

Opaque right-click context menu over the wallpaper

Folder share dialog with upload-only access and per-file size limit

Settings screen listing active folder shares with revoke controls

The Settings image shows disposable test links; those links were revoked after verification.

Verification

  • cd backend && go test ./...
  • cd frontend && pnpm run check
  • cd frontend && pnpm run lint
  • cd frontend && pnpm run build (passes; Vite reports the existing large-chunk warning)
  • Browser flows verified: opaque context menus; folder share modes and upload limits; Settings listing/revocation; public upload/delete controls; and ZIP downloads from the browser and public share page, with expected files in both archives.

RetriggerConfidence Score: 4/5

The PR is not yet safe to merge because older public clients cannot upload through modern upload-only links.

Findings

  1. P1 Upload links appear read-only ▶

Summary

The PR adds folder-share permission modes and upload caps, owner-side link management, and ZIP downloads for private and public folders. The follow-up changes preserve limits on permissions-only updates, address the previously reported symlink deletion and archive-route issues, and add ZIP name disambiguation.

Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Owner[Owner] --> Shares[Create or manage share]
  Shares --> Token[Public token]
  Token --> Access{Permissions}
  Access --> Browse[Browse and download]
  Access --> Upload[Upload with per-link cap]
  Access --> Delete[Delete or replace]
  Browse --> ZIP[Bounded folder ZIP]
Loading

Reviews (2) · Last reviewed commit: "Align share API examples with legacy ali..."

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
@vercel

vercel Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
box-box Ready Ready Preview Sep 26, 2026 10:48am UTC

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: ad9ff82f-42bb-4e4a-a3b9-a8a89e9336e6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread backend/internal/pkg/filesystem/fs.go Outdated
Comment thread backend/internal/service/share.go Outdated
Comment thread backend/internal/service/share.go Outdated
Comment thread backend/internal/service/archive.go Outdated
Comment thread backend/internal/handler/archive_test.go Outdated
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
@jR4dh3y

jR4dh3y commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

@coderabbitai

Comment thread backend/internal/model/share.go Outdated
Upload: p.Upload,
Delete: p.Delete,
CanReplace: p.Delete || p.LegacyReplace,
Write: p.Delete || p.LegacyReplace,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Upload links appear read-only A modern upload-only folder link returns upload: true but write: false. The previous public share page checks write before showing Add files, so recipients using that client cannot upload through a link that allows it. Keep the legacy write field aligned with upload access; canReplace already reports replacement access.

Suggested change
Write: p.Delete || p.LegacyReplace,
Write: p.Upload,

Knowledge Base Used: File sharing

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
@jR4dh3y

jR4dh3y commented Sep 26, 2026

Copy link
Copy Markdown
Owner

@coderabbitai full review

@jR4dh3y
jR4dh3y merged commit b104140 into master Sep 26, 2026
12 checks passed

This branch was successfully deployed

1 active deployment
Preview — 11c5b52e Deployed Sep 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant