Release 2.3.0
linter / quality (push) Successful in 1m5s
tests / ci (8.5) (push) Successful in 3m24s
docker / build-and-push (push) Successful in 7m10s
docker / test (8.5) (push) Successful in 3m21s
docker / release (push) Successful in 4s

A share can now hold a private text (a password, a key, a short note)
with its files or on its own. The upload page's new "Private text" card
takes up to 100 KB; the browser encrypts the text and sends it through
the same chunk pipeline as a file, flagged is_text on share_files, so it
gets the share's password, expiry, download limit and cleanup.

The recipient sees the text only after pressing "Show text", which
counts as their download, so a messenger link preview cannot use up a
share limited to one download. The text is left out of the file list,
the ZIP and the file counts; the admin dashboard marks shares that hold
one with "Text".

The website gains a Private text feature card and a fifth phone
screenshot; every screenshot is retaken.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Andreas Reinhold / reini
2026-09-26 07:00:17 +02:00
co-authored by Claude Opus 5.5
parent 202813a1e6
commit f9a7839ad3
73 changed files with 806 additions and 134 deletions
+4 -2
View File
@@ -59,7 +59,9 @@ class AdminDashboard extends Component
// Shares whose files are still being uploaded are not shares yet; their bytes do count as used space.
$shares = Share::query()
->whereNotNull('completed_at')
->withCount('files')
// A share's private text is not one of its files.
->withCount(['files' => fn ($query) => $query->where('is_text', false)])
->withExists('textFile')
// Shares that never expire come after every share that does, whichever way expiry is sorted.
->when($column === 'expires_at', fn ($query) => $query->orderByRaw('expires_at is null'))
->orderBy($column, $direction)
@@ -74,7 +76,7 @@ class AdminDashboard extends Component
})->where(function ($q) {
$q->whereNull('max_downloads')->orWhereColumn('download_count', '<', 'max_downloads');
})->count(),
'totalFiles' => ShareFile::query()->whereHas('share', fn ($query) => $query->whereNotNull('completed_at'))->count(),
'totalFiles' => ShareFile::query()->where('is_text', false)->whereHas('share', fn ($query) => $query->whereNotNull('completed_at'))->count(),
'usedSpace' => $shareService->getTotalUsedSpace(),
'maxQuota' => $shareService->getMaxStorageQuota(),
'version' => config('app.version'),
+73 -17
View File
@@ -4,6 +4,7 @@ namespace App\Livewire;
use App\Models\Setting;
use App\Models\Share;
use App\Models\ShareFile;
use App\Services\PasswordGeneratorService;
use App\Services\ShareService;
use Carbon\CarbonInterval;
@@ -73,26 +74,50 @@ class FileUploader extends Component
continue;
}
if ($this->pendingToken !== $shareFile->share->token) {
$this->pendingToken = $shareFile->share->token;
session()->push('pending_shares', $this->pendingToken);
}
$this->rememberPendingShare($shareFile->share);
$header = $shareService->readHeader($shareFile);
$targets[] = [
'id' => $shareFile->id,
'url' => Str::beforeLast(route('upload.chunk', ['shareFile' => $shareFile, 'index' => 0]), '/'),
'key' => $shareFile->share->encryption_key,
'noncePrefix' => bin2hex($header['noncePrefix']),
'chunkSize' => $header['chunkSize'],
'chunkCount' => $header['chunkCount'],
];
$targets[] = $this->uploadTarget($shareFile, $shareService);
}
return $targets;
}
/**
* Register the private text as the share is created, in place of any text an earlier attempt
* registered, and hand the browser what it encrypts and sends it with. Only its size in UTF-8
* bytes reaches the server here: the text itself arrives encrypted, like a file. Nothing is
* registered for an empty text; a text an admin limit refuses gets `null` and the reason under
* `text`.
*
* @return array{id: int, url: string, key: string, noncePrefix: string, chunkSize: int, chunkCount: int}|null
*/
public function registerText(int $size, ShareService $shareService): ?array
{
$this->resetErrorBag('text');
$existingText = $this->pendingShare()?->textFile()->first();
if ($existingText !== null) {
$shareService->removeFile($existingText);
}
if ($size === 0) {
return null;
}
try {
$shareFile = $shareService->registerFile($this->pendingShare(), 'text.txt', $size, null, isText: true);
} catch (ValidationException $e) {
$this->addError('text', $e->errors()['files'][0]);
return null;
}
$this->rememberPendingShare($shareFile->share);
return $this->uploadTarget($shareFile, $shareService);
}
/**
* Take files out of the pending share, whether or not their upload finished.
*
@@ -153,7 +178,7 @@ class FileUploader extends Component
$pendingShare = $this->pendingShare();
if ($pendingShare === null) {
$this->addError('files', __('Please select at least one file to upload.'));
$this->addError('files', __('Add files or a text to share.'));
return;
}
@@ -183,17 +208,48 @@ class FileUploader extends Component
public function render(): mixed
{
$shareService = app(ShareService::class);
$pendingFiles = $this->pendingShare()?->files()->orderBy('id')->get() ?? collect();
$pendingFiles = $this->pendingShare()?->files()->where('is_text', false)->orderBy('id')->get() ?? collect();
return view('livewire.file-uploader', [
'pendingFiles' => $pendingFiles,
'allFilesUploaded' => $pendingFiles->isNotEmpty() && $pendingFiles->every(fn ($file): bool => $file->completed_at !== null),
'allFilesUploaded' => $pendingFiles->every(fn ($file): bool => $file->completed_at !== null),
'maxTextBytes' => ShareFile::MAX_TEXT_BYTES,
'isStorageFull' => $shareService->isStorageFull(),
'allowNeverExpire' => (bool) Setting::get('allow_never_expire', false),
'passwordGeneratorMode' => app(PasswordGeneratorService::class)->mode(),
]);
}
/**
* Make a share the one this page uploads into, and let this session reach it.
*/
private function rememberPendingShare(Share $share): void
{
if ($this->pendingToken !== $share->token) {
$this->pendingToken = $share->token;
session()->push('pending_shares', $this->pendingToken);
}
}
/**
* What the browser encrypts and sends a registered file with.
*
* @return array{id: int, url: string, key: string, noncePrefix: string, chunkSize: int, chunkCount: int}
*/
private function uploadTarget(ShareFile $shareFile, ShareService $shareService): array
{
$header = $shareService->readHeader($shareFile);
return [
'id' => $shareFile->id,
'url' => Str::beforeLast(route('upload.chunk', ['shareFile' => $shareFile, 'index' => 0]), '/'),
'key' => $shareFile->share->encryption_key,
'noncePrefix' => bin2hex($header['noncePrefix']),
'chunkSize' => $header['chunkSize'],
'chunkCount' => $header['chunkCount'],
];
}
/**
* This page's pending share, while it is still pending and this session started it.
*/
+24
View File
@@ -7,6 +7,7 @@ use App\Services\ShareService;
use Carbon\CarbonInterval;
use Illuminate\Support\Facades\RateLimiter;
use Livewire\Attributes\Layout;
use Livewire\Attributes\Renderless;
use Livewire\Attributes\Validate;
use Livewire\Component;
@@ -60,11 +61,34 @@ class ShareDownload extends Component
$this->authenticated = true;
}
/**
* The share's private text, for the recipient who pressed "Show text": counted as their
* download, as a file would be. Returned to the browser only, never kept in a property, so it
* is not in the component's snapshot. Null when the text is no longer available; no abort(),
* which would open Livewire's error modal. Renderless: a re-render would morph the download
* note Alpine just switched back into the one it hid.
*/
#[Renderless]
public function revealText(ShareService $shareService): ?string
{
$share = $this->share;
if (! $share->isCompleted() || $share->isExpired() || ! $share->hasText()
|| ($share->isPasswordProtected() && ! session('share_key_'.$share->token))
|| ! $shareService->claimDownload($share, session()->driver())) {
return null;
}
return $shareService->readText($share, $shareService->sessionDecryptionKey($share, session()->driver()));
}
public function render(): mixed
{
$shareService = app(ShareService::class);
return view('livewire.share-download', [
'files' => $this->share->files->where('is_text', false)->values(),
'hasText' => $this->share->files->contains('is_text', true),
'downloadWindowEndsAt' => $shareService->downloadWindowEndsAt($this->share, session()->driver()),
'remainingDownloads' => $this->share->max_downloads ? max($this->share->max_downloads - $this->share->download_count, 0) : null,
'downloadWindow' => CarbonInterval::minutes(ShareService::DOWNLOAD_WINDOW_MINUTES)->cascade()->forHumans(),