|
|
|
|
@ -0,0 +1,160 @@
|
|
|
|
|
# Cloudreve Fork — Analysis & Roadmap
|
|
|
|
|
|
|
|
|
|
Fork: `Dvorinka/cloudreve` · Upstream: `cloudreve/cloudreve` · Baseline: `4.19.1` (exact upstream HEAD, zero divergence)
|
|
|
|
|
|
|
|
|
|
Original work by the Cloudreve authors (cloudreve.org). This fork continues it as a fully open-source project — every "Pro" feature reimplemented and free, desktop client on all platforms, native Android app.
|
|
|
|
|
|
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
## 1. Analysis
|
|
|
|
|
|
|
|
|
|
### 1.1 Repo state
|
|
|
|
|
|
|
|
|
|
| Fact | Value |
|
|
|
|
|
|---|---|
|
|
|
|
|
| Fork vs upstream | `0 ahead / 0 behind` — clean mirror of `master` @ 4.19.1 |
|
|
|
|
|
| Backend | Go 1.26, Gin, ent ORM, `go build ./...` compiles (only `assets.zip` embed fails until frontend is built — expected) |
|
|
|
|
|
| Frontend | `assets/` submodule → `cloudreve/frontend` (React + Vite + TS, 69 deps), not yet initialized locally |
|
|
|
|
|
| Storage drivers present | local, S3, OSS, COS, Qiniu, Upyun, OneDrive, remote node (`service/explorer/slave.go`) |
|
|
|
|
|
| Auth present | password+2FA, passkey (`ent/schema/passkey.go`), generic OAuth client/grant, WebDAV accounts (`davaccount.go`) |
|
|
|
|
|
|
|
|
|
|
### 1.2 Security posture
|
|
|
|
|
|
|
|
|
|
16 published GHSAs on upstream — **all fixed at our baseline** (vuln ranges ≤ 4.17.0, we run 4.19.1). Spot-verified in tree, not just by version:
|
|
|
|
|
|
|
|
|
|
- GHSA-f8xp (account takeover, insecure PRNG): `pkg/util/common.go` uses `crypto/rand` primary, `math/rand` only on crypto failure — fix present
|
|
|
|
|
- GHSA-vgj4 (OAuth scope bypass, missing client_id): `service/oauth/oauth.go:159` validates `authCode.ClientID != s.ClientID` — fix present
|
|
|
|
|
- Remaining highs (WebDAV path traversal, quota TOCTOU, OneDrive cred update via Admin.Read) — all ≤ 4.16.x ranges, patched
|
|
|
|
|
|
|
|
|
|
Ongoing security work is in the roadmap (§5), not the backlog.
|
|
|
|
|
|
|
|
|
|
### 1.3 Pro feature map (cloudreve.org/pricing — all 5 slides captured)
|
|
|
|
|
|
|
|
|
|
The community repo contains **zero Pro code** — Pro ships as a separate licensed binary (`--license-key`, `proupgrade` DB migration). BUT the community **frontend already contains the full Pro UI skeleton** — every surface below renders a `ProChip` badge that opens `ProDialog.tsx`. Implementation = backend endpoints + remove the chips.
|
|
|
|
|
|
|
|
|
|
| Pro slide | Features | Frontend hooks found |
|
|
|
|
|
|---|---|---|
|
|
|
|
|
| Sharing & collaboration | write/upload/delete via share link, paid share links, granular file permissions (users/groups/anonymous), anonymous upload via share, default shares for new users | `ShareSection.tsx` (group editor) |
|
|
|
|
|
| Storage policy mgmt | multiple policies per group, per-directory policies, load-balancer policy, file migration between policies | `SelectProvider.tsx`, `storage_policy_id` exists (single) on group |
|
|
|
|
|
| User & auth | multi-account switching, Logto SSO, OIDC SSO, QQ Connect, sign-up email filtering | `SSOSettings.tsx`, `SSO/` |
|
|
|
|
|
| Monetization (VAS) | storage plans, membership plans, redemption codes, credits | `VAS/` dir: `GroupProducts`, `StorageProducts`, `PaymentProviders`, `GiftCodes` — **full UI exists** |
|
|
|
|
|
| System extensions | activity/audit logs, site announcements, node selection, report abuse | `Events.tsx` (admin), `Home.tsx` |
|
|
|
|
|
|
|
|
|
|
Backend gaps are concrete: `ShareProps` = `{share_view, show_read_me}` only; `group.storage_policy_id` is single; no order/product/credit entities at all. `NavigatorCapability_CommunityPlaceholder1–9` in `pkg/filemanager/fs/dbfs/navigator.go` are the reserved capability slots Pro fills.
|
|
|
|
|
|
|
|
|
|
### 1.4 Org repo decisions
|
|
|
|
|
|
|
|
|
|
| Repo | Verdict | Reason |
|
|
|
|
|
|---|---|---|
|
|
|
|
|
| `cloudreve` (this fork) | **Keep — base** | The core |
|
|
|
|
|
| `frontend` | **Fork — required** | UI is source-available and already holds Pro skeleton; we need our own fork to strip gates |
|
|
|
|
|
| `desktop` | **Fork — port** | Tauri+React; portable core (`cloudreve-api`, `inventory`, `tasks`, `uploader`, `drive/sync`) vs Windows-only glue (`cfapi`, `shellext`, `win32_notif`) |
|
|
|
|
|
| `docs` | **Fork later** | Needed when we ship; low priority |
|
|
|
|
|
| `docker-compose` | **Fork — small** | One file we extend (add pro-less compose + dev compose) |
|
|
|
|
|
| `taskqueue` | **Skip** | Dead since 2024; OneDrive offload queue superseded by in-app queue |
|
|
|
|
|
| `remote-server` | **Skip** | Dead PHP-era remote; v4 has native remote nodes |
|
|
|
|
|
| `ios-feedback` | **Skip** | Tracker for closed-source iOS app; we do Android instead |
|
|
|
|
|
| `theme-editor`, `frontend_v2`, `v2` | **Skip** | Archived/ancient |
|
|
|
|
|
|
|
|
|
|
### 1.5 Upstream issues — 137 open, grouped
|
|
|
|
|
|
|
|
|
|
| Group | Count | Examples |
|
|
|
|
|
|---|---|---|
|
|
|
|
|
| Bug — upload/download/sync | ~25 | #3574 trash_bin_collect OOM, #3454 PG FK on upload, #3118 WebDAV 500 on large files, #3005 WebDAV fragments, #2938 upload stuck |
|
|
|
|
|
| Bug — WebDAV | ~8 | #2878 mount path 404 after move, #3118, #3409 read-only groups |
|
|
|
|
|
| Bug — DB/migration | ~8 | #3452 MySQL HeatWave, #2880 unix socket, #2934 v3→v4 sqlite, #2981 PG18 |
|
|
|
|
|
| Enhancement — sharing/permissions | ~15 | #3555 preview-only shares, #3390 default share visibility, #3340 upload-only folders, #3033/#3032 multi-share ops |
|
|
|
|
|
| Enhancement — storage policy | ~8 | #3518 encrypt on relocation, #2961 enable/disable policy, #2262 site-wide migration |
|
|
|
|
|
| Enhancement — auth/SSO | ~7 | #3464 OIDC, #3056 auto-OIDC, #2179 TOTP manual key, #3479 IP whitelist |
|
|
|
|
|
| Enhancement — download/tasks | ~10 | #3491 advanced remote download, #3259 yt-dlp, #2427 download quota, #2270 cancel tasks |
|
|
|
|
|
| UX/polish | ~20 | #3288 breadcrumb restore, #3223 deselect on empty click, #3508 loop video, #3507 gallery names |
|
|
|
|
|
| Pro-related (becomes free here) | ~10 | #3572 ADFS OIDC, #3515 recurring billing, #3180 group-expiry downgrade, #3171 subaddress ban |
|
|
|
|
|
| Mobile/iOS requests | ~5 | #3003 captcha incompat, #2826 login fail, #2863 capacity 0KB — Android solves |
|
|
|
|
|
| Chinese-titled (mixed) | ~40 | folded into groups above after translation |
|
|
|
|
|
| wontfix by upstream (revisit) | ~10 | #2494 multi-group, #2883 slide captcha, #2842 file audit — **candidates for us** |
|
|
|
|
|
|
|
|
|
|
### 1.6 Upstream PRs — verdicts
|
|
|
|
|
|
|
|
|
|
| PR | Change | Verdict |
|
|
|
|
|
|---|---|---|
|
|
|
|
|
| #3524 | revalidate share/direct links after permission change (+185/-1, CLEAN) — fixes #3544, same class as GHSA-vx2m | **Merge** — security |
|
|
|
|
|
| #3549 | gorilla/websocket 1.5.0→1.5.3 | **Merge** — dep CVE hygiene |
|
|
|
|
|
| #2964 | nwaples/rardecode 2.1.0→2.2.0 | **Merge** — dep hygiene |
|
|
|
|
|
| #2851 | ulikunitz/xz 0.5.12→0.5.14 | **Merge** — dep hygiene |
|
|
|
|
|
| #3490 | IP range/CIDR filter in event logs (+668, 2 files) — fixes #3480 | **Merge** — small, self-contained |
|
|
|
|
|
| #3472 | OIDC provider support (+292/-6, 10 files) — fixes #3464, overlaps Pro SSO | **Merge after review** — strategic (free OIDC) |
|
|
|
|
|
| #2481 | multi-stage Dockerfile (+18/-2) | **Review** — conflicts w/ our own docker work likely; take if clean |
|
|
|
|
|
| #2507 | p2p QUIC (draft) | **Skip** — draft, scope creep |
|
|
|
|
|
| #2499 | multi-group users (draft, WIP) | **Watch** — big feature, matches #2494 wontfix; revisit when upstream matures it |
|
|
|
|
|
| #1802 | checksum on WOPI/text-edit update (draft, 2024) | **Skip** — stale draft |
|
|
|
|
|
|
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
## 2. Immediate actions (this change set)
|
|
|
|
|
|
|
|
|
|
- [x] Analysis + this roadmap
|
|
|
|
|
- [ ] Enable Issues on fork; label taxonomy (`upstream-####`, `group:*`, `pro-free`, `desktop`, `android`, `security`)
|
|
|
|
|
- [ ] Migrate upstream issues → fork (translate Chinese titles, tag `upstream-NNNN` + group labels, link originals)
|
|
|
|
|
- [ ] Cherry-pick merge: #3524, #3549, #2964, #2851, #3490 (and #3472 after compile review)
|
|
|
|
|
- [ ] `go build ./...` + `go test ./...` green
|
|
|
|
|
|
|
|
|
|
## 3. Phase A — foundation hardening (first weeks)
|
|
|
|
|
|
|
|
|
|
- Sync-fork automation: weekly `upstream → fork` merge workflow (GitHub Action) so security fixes keep landing
|
|
|
|
|
- Dependabot/renovate on the fork
|
|
|
|
|
- CI: build + test + vet + frontend build on PR (upstream azure-pipelines is theirs; ours = GitHub Actions)
|
|
|
|
|
- `docker-compose` dev stack (postgres + app + frontend hot reload)
|
|
|
|
|
- Remove `ProDialog`/`ProChip` gates in frontend fork; point `assets` submodule at our frontend fork
|
|
|
|
|
|
|
|
|
|
## 4. Phase B — Pro features, free (the big one)
|
|
|
|
|
|
|
|
|
|
Order = user-visible value first; each ships with backend + UI + tests.
|
|
|
|
|
|
|
|
|
|
1. **Share collaboration** — write/upload/delete via share link, anonymous upload, share ACL (users/groups), preview-only mode (fixes #3555, #3390, #3340, #3517, #3578; uses `NavigatorCapability` placeholder slots + `ShareProps` extension + `share` entity fields)
|
|
|
|
|
2. **Storage policy advanced** — multiple policies per group (group→policies join table), per-directory binding, load-balancer policy, file migration between policies (fixes #3518, #2961, #2262)
|
|
|
|
|
3. **SSO** — generic OIDC provider (PR #3472 base), Logto connector, multi-account switching, sign-up email filtering (fixes #3464, #3056, #3505)
|
|
|
|
|
4. **VAS/monetization-free** — credits + redemption codes as *free* features (gift codes for admin use), storage/membership plan definitions; skip payment processor integration initially — YAGNI until a real user asks (fixes #3231)
|
|
|
|
|
5. **System extensions** — activity/audit log surfaced in admin, site announcements, report-abuse queue (fixes #3480, #3479 IP whitelist)
|
|
|
|
|
|
|
|
|
|
## 5. Phase C — security + quality
|
|
|
|
|
|
|
|
|
|
- Own security review on top of upstream fixes: session/token entropy audit, SSRF guard re-test (NAT64 class), rate limiting on auth endpoints
|
|
|
|
|
- Fix upstream bug backlog by impact: #3574 OOM (trash_bin_collect streaming), #3118/#3005 WebDAV large-file, #3454 PG FK, #3375 SMTP auth discovery
|
|
|
|
|
- `desloppify` + `security-reviewer` passes; scorecard appended to README
|
|
|
|
|
|
|
|
|
|
## 6. Phase D — desktop, all platforms
|
|
|
|
|
|
|
|
|
|
Goal: Windows + macOS + Linux from one Tauri codebase (`cloudreve/desktop` fork).
|
|
|
|
|
|
|
|
|
|
| Layer | Windows (exists) | macOS | Linux |
|
|
|
|
|
|---|---|---|---|
|
|
|
|
|
| Placeholders/hydration | cfapi (keep) | File Provider ext (Swift bridge) | FUSE (`fuser`) or plain sync folder |
|
|
|
|
|
| Shell integration | shellext (keep) | Finder sync extension | Nautilus/Dolphin plugin (later) |
|
|
|
|
|
| Notifications | win32_notif → replace | `tauri-plugin-notification` (all platforms) | same |
|
|
|
|
|
| Sync core | shared: `cloudreve-api`, `inventory`, `tasks`, `uploader`, `drive/sync` | same | same |
|
|
|
|
|
|
|
|
|
|
- Port order: (1) strip `win32_notif`→tauri notifications (all platforms benefit), (2) abstract `drive/` behind a `HydrationProvider` trait (cfapi impl on Windows, stub→FUSE on Linux, FileProvider on macOS), (3) CI matrix build all 3, (4) MSIX→also ship .dmg/.AppImage/.deb.
|
|
|
|
|
- Feature fallback on Linux/macOS until providers land: full sync without placeholders (download-on-access still works via sync engine).
|
|
|
|
|
|
|
|
|
|
## 7. Phase E — Android app (native, no iOS)
|
|
|
|
|
|
|
|
|
|
New repo `Dvorinka/cloudreve-android`. Kotlin + Jetpack Compose, Material 3.
|
|
|
|
|
|
|
|
|
|
- **API**: `api/v4` REST + OAuth token (entities exist: `oauthclient`, `oauthgrant`) — same surface the desktop `cloudreve-api` crate documents; port its models as the spec
|
|
|
|
|
- **Core features**: browse/download/upload files, share links, camera-upload (auto photo backup), offline-favorite files, local sync folder via SAF/WorkManager
|
|
|
|
|
- **System integration** (the "native, complete" ask): share-sheet target (upload to Cloudreve from any app), DocumentsProvider (Cloudreve in Files app), quick-share tile, notifications on share/task events
|
|
|
|
|
- **Auth**: webview OAuth flow → token; later passkey if backend exposes
|
|
|
|
|
- **WebDAV bridge**: `/dav` works as fallback file access until SDK matures
|
|
|
|
|
- Non-goals: iOS, tablet-first layouts (works, not optimized)
|
|
|
|
|
|
|
|
|
|
## 8. Governance
|
|
|
|
|
|
|
|
|
|
- License/credit: keep `LICENSE` (GPL-3.0), add `AUTHORS`/credit line to original Cloudreve authors in README — attribution without endorsement
|
|
|
|
|
- Release cadence: tag `fork-4.19.x` line first (cherry-picks only), then `5.0.0-fork` once Phase B lands
|
|
|
|
|
- Every merge: build + test + lint green (pre-push gate, non-negotiable)
|
|
|
|
|
|
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
## Issue migration format
|
|
|
|
|
|
|
|
|
|
Each fork issue: title translated to English when needed, body = `Upstream: cloudreve/cloudreve#NNNN` + short restatement + group labels. Epics get `epic` label and link children. Upstream `wontfix` items we want get `revisit` label.
|