Skip to content

ocis

File Storage & Sync

A scalable file sync & share platform that serves as the foundation for data management, supporting multiple clients and office integrations.

Go Latest v8.0.6 · 10d ago Security brief →

Features

  • Supports web, Android, iOS, and desktop clients via standard APIs (WebDAV, CS3)
  • Integrates collaborative office suites like Collabora Online and OnlyOffice
  • Authenticates users with OpenID Connect using external IdP or embedded provider

Security Response History

1 CVE
CVE Severity Disclosed Patched (this tool) vs Ecosystem Median
CVE-2023-44487 KEV medium
CVSS 7.5
2023-10-10 2026-02-05 2y 4mo / median 2y 3mo

Recent releases

View all 9 releases →
Upgrade now
v8.0.6 Mixed
Dependencies

libvips upgrade + Go upgrade + sign‑in toggle

Review required
v8.1.0 Breaking risk
Auth Dependencies

Breaking changes — review before upgrading.

Upgrade now
v8.0.5 Breaking risk
Dependencies

Go bump + libvips upgrade

Upgrade now
v8.0.4 Security relevant
Dependencies Breaking upgrade

Go bump + libvips upgrade + role fix

v8.0.2 Breaking risk patches CVE-2023-44487
Notable features
  • Added `spaceid` field to REPORT responses
  • Allow multiple LDAP objectClasses on group creation via env var
  • New space role: SpaceEditorWithoutVersionsWithoutTrashbin
Full changelog

Table of Contents

Changes in 8.0.2

Summary

  • Bugfix - Fix OCM share permission change notification: #12190
  • Bugfix - Fix the internal links: #12231
  • Bugfix - Return 200 OK for WOPI Lock requests in read-only and view-only modes: #12257
  • Bugfix - Fix space management middleware removing users from spaces on download: #12285
  • Enhancement - Add spaceid to REPORT: #12241
  • Enhancement - Allow multiple objectClasses on group creation: #12242
  • Enhancement - Add SpaceEditorWithoutVersionsWithoutTrashbin space membership role: #12245
  • Enhancement - Bump Web to 12.3.3: #13705

Details

  • Bugfix - Fix OCM share permission change notification: #12190

    Fix the OCM share permission change notification handling.

    https://github.com/owncloud/ocis/pull/12190

  • Bugfix - Fix the internal links: #12231

    We fixed the internal links access control

    https://github.com/owncloud/ocis/pull/12231

  • Bugfix - Return 200 OK for WOPI Lock requests in read-only and view-only modes: #12257

    OnlyOffice sends a WOPI Lock request when opening any document, even when the
    user only has read access. The WOPI Lock handler was attempting to acquire a CS3
    write lock regardless of the view mode, causing a permission error for read-only
    tokens that OnlyOffice displayed as an error message on load.

    The Lock handler now returns 200 OK immediately for READ_ONLY and VIEW_ONLY view
    modes without attempting to acquire a lock, consistent with the WOPI spec.

    https://github.com/owncloud/ocis/pull/12257

  • Bugfix - Fix space management middleware removing users from spaces on download: #12285

    The space management middleware ran on every authenticated request, including
    signed URL requests used for file downloads. Since signed URL auth does not
    carry OIDC claims, the middleware interpreted the absence of claims as "user
    should have no space access" and removed the user from all project spaces. On
    the next OIDC request the user was re-added, causing an oscillating add/remove
    cycle that led to intermittent download failures and transient "space not found"
    errors.

    The middleware now skips reconciliation entirely when no OIDC claims are present
    in the request context.

    https://github.com/owncloud/ocis/issues/12285
    https://github.com/owncloud/ocis/pull/12285

  • Enhancement - Add spaceid to REPORT: #12241

    Added the spaceid to the REPORT responses. This is aligning the REPORT
    method with the PROPFIND method.

    https://github.com/owncloud/ocis/pull/12241

  • Enhancement - Allow multiple objectClasses on group creation: #12242

    Added support for configuring additional LDAP objectClasses when creating
    groups. The new OCIS_LDAP_GROUP_ADDITIONAL_OBJECTCLASSES /
    GRAPH_LDAP_GROUP_ADDITIONAL_OBJECTCLASSES environment variable accepts a list
    of extra objectClasses that are set alongside the primary
    GRAPH_LDAP_GROUP_OBJECTCLASS when a new group is created in LDAP.

    https://github.com/owncloud/ocis/pull/12242

  • Enhancement - Add SpaceEditorWithoutVersionsWithoutTrashbin space membership role: #12245

    Added a new space membership role "Can edit"
    (SpaceEditorWithoutVersionsWithoutTrashbin) that grants full editor permissions
    (create, upload, download, edit, move, delete) on a space without access to file
    versions or the trashbin.

    https://github.com/owncloud/ocis/pull/12245

  • Enhancement - Bump Web to 12.3.3: #13705

    https://github.com/owncloud/web/pull/13705
    https://github.com/owncloud/web/releases/tag/v12.3.3

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
2,054
Forks
265
Languages
Go TypeScript Gherkin

Install & Platforms

Install via
docker
Platforms
linux arm64
Mobile
Android IOS

Community & Support

Beta — feedback welcome: [email protected]