SimpleW.Service.FileBrowser 26.1.1-alpha.20260917-2225

This is a prerelease version of SimpleW.Service.FileBrowser.
dotnet add package SimpleW.Service.FileBrowser --version 26.1.1-alpha.20260917-2225
                    
NuGet\Install-Package SimpleW.Service.FileBrowser -Version 26.1.1-alpha.20260917-2225
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="SimpleW.Service.FileBrowser" Version="26.1.1-alpha.20260917-2225" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="SimpleW.Service.FileBrowser" Version="26.1.1-alpha.20260917-2225" />
                    
Directory.Packages.props
<PackageReference Include="SimpleW.Service.FileBrowser" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add SimpleW.Service.FileBrowser --version 26.1.1-alpha.20260917-2225
                    
#r "nuget: SimpleW.Service.FileBrowser, 26.1.1-alpha.20260917-2225"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package SimpleW.Service.FileBrowser@26.1.1-alpha.20260917-2225
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=SimpleW.Service.FileBrowser&version=26.1.1-alpha.20260917-2225&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=SimpleW.Service.FileBrowser&version=26.1.1-alpha.20260917-2225&prerelease
                    
Install as a Cake Tool

SimpleW.Service.FileBrowser

website

License NuGet Downloads

SimpleW.Service.FileBrowser provides a small web file browser for SimpleW.

It can list files and directories, create folders, rename, move, manage an internal trash directory, upload files or directories, and create or safely extract ZIP archives. Large files are uploaded in chunks.

using System.Net;
using SimpleW;
using SimpleW.Service.FileBrowser;

var server = new SimpleWServer(IPAddress.Any, 8080);

server.Configure(options => {
    options.MaxRequestBodySize = 32 * 1024 * 1024;
});

server.ConfigureChallenge(session =>
    session.Response.Redirect("/auth/login").SendAsync());

server.UseFileBrowserModule(options => {
    options.Path = @"C:\uploads";
    options.Prefix = "/files";
    options.EventsPrefix = "/files/api/events";
    options.EnableEvents = true;
    // options.ClientPath = @"C:\custom-filebrowser-client";
    options.Authorize = session => session.Principal.IsAuthenticated;
    options.ScopeKey = session => session.Principal.Identity.Identifier!;
    options.CanList = session => true;
    options.CanDownload = session => true;
    options.CanUpload = session => session.Principal.IsInRole("file-editor");
    options.CanModify = session => session.Principal.IsInRole("file-editor");
    options.CanDelete = session => session.Principal.IsInRole("file-editor");
    options.CanManageTrash = session => session.Principal.IsInRole("file-admin");
    options.CanAccessPath = (session, path) => !path.StartsWith("private/", StringComparison.OrdinalIgnoreCase);
    options.UploadChunkThresholdBytes = 100 * 1024 * 1024;
    options.UploadChunkBytes = 16 * 1024 * 1024;
    options.UploadSessionTimeout = TimeSpan.FromMinutes(30);
    options.MaxConcurrentUploadSessions = 100;
    options.OperationHistoryTimeout = TimeSpan.FromMinutes(5);
    options.DefaultPageSize = 100;
    options.MaxPageSize = 1000;
});

await server.RunAsync();

By default, the module is closed. Configure Authorize, at least one capability callback, or set AllowAnonymous = true. When configured, Authorize is the common gate evaluated before explicit capabilities. Capability callbacks fall back to Authorize/AllowAnonymous when omitted, which keeps existing configurations compatible and makes read-only access possible with CanList and CanDownload only.

Use server.ConfigureChallenge(...) when a rejected Authorize request must redirect to a login URL, return 401 with WWW-Authenticate, or produce another application-owned authentication response. The callback is shared with the other server modules and must send the response. When omitted, the existing 403 response is preserved. Capability and path denials remain 403 and do not invoke the server challenge.

A browser navigation does not forward an Authorization: Bearer header from the page containing the link. A bearer-only application can use the server challenge to redirect to its own bootstrap endpoint, recover or request authentication there, establish a short-lived browser credential, and return to FileBrowser. The module does not put bearer tokens in URLs or prescribe a token transport.

ScopeKey must return the same non-empty value for every request from one owner. It isolates that owner's SSE room, upload sessions, and operations. The default uses the authenticated principal identifier, email, or name and falls back to anonymous; configure it explicitly when authentication does not populate session.Principal or when tenant-level isolation is required.

The web UI is embedded directly in SimpleW.Service.FileBrowser.dll; the NuGet package does not copy a client/ directory to the consuming application. Debug builds automatically serve the local SimpleW.Service.FileBrowser/client directory through StaticFilesModule when it can be found, so client changes are read directly from disk without rebuilding the module. Release builds and Debug builds without a local client directory serve the embedded resources. Set ClientPath to explicitly serve a custom client directory in any build configuration.

When events are enabled, the web UI opens an EventSource on EventsPrefix. File operations return 202 Accepted and publish:

  • filebrowser.operation.started
  • filebrowser.operation.completed
  • filebrowser.operation.failed
  • filebrowser.operation.cancelled
  • filebrowser.upload.progress
  • filebrowser.upload.completed
  • filebrowser.upload.cancelled
  • filebrowser.changed

GET /files/api/operations/:id returns the state and retained result of an operation owned by the current scope. POST /files/api/operations/:id/cancel requests cancellation of that operation only. Terminal states remain queryable for OperationHistoryTimeout, so clients can follow a 202 Accepted response even without SSE. DELETE /files/api/uploads/:id cancels an owned upload session.

Upload sessions expire after UploadSessionTimeout without activity, and at most MaxConcurrentUploadSessions sessions may be active at once. Old orphaned .part files are removed at startup and periodically. GET /files/api/uploads/:id returns each file's received byte ranges so a client can resume only the missing chunks. DELETE /files/api/uploads/:id cancels one session and removes its temporary files.

UploadChunkBytes must be lower than or equal to SimpleWServerOptions.MaxRequestBodySize, because SimpleW validates each request body before the module receives it.

File checksums

Use Checksum on a file row or select one file and choose Checksum in the selection toolbar. The dialog calculates SHA-256 by default and also offers SHA-1 and MD5. Copy copies the uppercase hexadecimal checksum; the value remains selectable when clipboard access is unavailable. Calculation runs on demand, reads the file as a stream, and is not cached. Closing the dialog or changing the algorithm cancels the previous request.

GET /files/api/checksum?path=documents/report.pdf&algorithm=sha256 returns { "ok": true, "path": "documents/report.pdf", "algorithm": "sha256", "checksum": "..." }. Routes are relative to the configured prefix. Accepted algorithms are sha256, sha1, and md5; omitting algorithm selects sha256. The endpoint uses the same authorization, CanDownload, and CanAccessPath checks as downloads and returns Cache-Control: no-store.

Compare with the local file using the same algorithm, for example in PowerShell:

Get-FileHash -LiteralPath 'C:\downloads\report.pdf' -Algorithm SHA256

Use SHA1 or MD5 when selected in the dialog. Matching checksums indicate matching file contents. This is a manual check of the current server file; uploads and downloads are not automatically verified.

Errors use { "ok": false, "error": "..." }: unsupported algorithms return 400 invalid_algorithm, missing files or directories return 404 file_not_found, denied access returns 403, and other read failures return 500 checksum_failed. If a size or modification-time change is detected during reading, the endpoint returns 409 file_changed; retry once the file is stable. Invalid paths and reparse points are rejected using the existing path-validation errors.

Listing, search, sorting, and pagination

GET /files/api/list lists only the direct children of the requested directory. Results are paginated by default and directories always appear before files.

Query parameter Description Default
path Relative directory to list. Root directory
search Case-insensitive text contained in the item name. Empty
sort name, size, or modified. name
direction asc or desc. asc
pageSize Number of entries, up to MaxPageSize. DefaultPageSize
continuationToken Opaque token returned by the preceding page. Empty
GET /files/api/list?path=documents&search=report&sort=modified&direction=desc&pageSize=100

The response contains keyCount, isTruncated, and nextContinuationToken in addition to path, parent, the effective search/sort parameters, and items. When isTruncated is true, pass nextContinuationToken unchanged as continuationToken to request the next page. Tokens are bound to the path, search, sort, direction, and page size that created them.

GET /files/api/download?path=documents/report.pdf streams an authorized file as an attachment. In the embedded UI, clicking a file name uses this endpoint to download it.

GET /files/api/trash lists deleted entries. POST /files/api/trash/restore restores selected trash ids to their original paths, or accepts destinationPath for one entry whose original path is unavailable. POST /files/api/trash/delete permanently removes selected ids, and POST /files/api/trash/empty permanently removes every trash entry. New deletions retain restore metadata across process restarts; the bundled UI asks for a destination when restoring a legacy entry.

POST /files/api/archive queues creation of a ZIP from one or more relative file or directory paths. The archive is built in the module's internal temporary directory and moved to its final destination only after successful completion.

POST /files/api/extract queues ZIP extraction with a relative archive path, a destination directory, and a createDestinationDirectory flag. Extraction rejects paths outside the destination, existing file conflicts, oversized entries, oversized expanded archives, and archives containing more than MaxArchiveEntries entries.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • SimpleW (>= 26.1.1-alpha.20260906-2197 && < 26.2.0)
  • net8.0

    • SimpleW (>= 26.1.1-alpha.20260906-2197 && < 26.2.0)
  • net9.0

    • SimpleW (>= 26.1.1-alpha.20260906-2197 && < 26.2.0)

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
26.1.1-alpha.20260917-2225 30 9/17/2026
26.1.1-alpha.20260907-2211 64 9/7/2026
26.1.0-alpha.20260906-2198 67 9/6/2026
26.1.0-alpha.20260906-2190 62 9/6/2026
26.1.0-alpha.20260905-2186 60 9/5/2026
26.1.0-alpha.20260904-2180 63 9/4/2026
26.1.0-alpha.20260829-2141 65 8/29/2026
26.1.0-alpha.20260825-2081 78 8/25/2026
26.1.0-alpha.20260825-2077 76 8/25/2026
26.1.0-alpha.20260825-2075 75 8/25/2026