Skip to content
AsterDriveDeveloper
Security update: Docker images from v0.4.0-rc.1 fix the high-severity FFmpeg MagicYUV decoder vulnerability (CVE-2026-8461). Upgrade instances using older images immediately.View CVE advisory
Security update: v0.4.0-beta.3 fixes a WebDAV request issue that can terminate the server process. Upgrade older instances promptly.View advisory

System Settings

Entry point:

Admin -> System Settings
GoalCheck This Group FirstIf It Is Still Wrong
Site links, share links, or mail link domains are wrongSite ConfigurationThen check reverse proxy
Login cookie, token, activation link, or email-code MFA timing is unsuitableAuthentication and CookiesThen check login and sessions
Registration, Passkey sign-in, local email allow/block lists, avatars, or Gravatar behavior is unexpectedUser ManagementThen check login and sessions
Passkey, MFA, external login, or external identity binding is unexpectedSite Configuration / Admin -> External Authentication / Authentication and CookiesThen check login and sessions
Mail cannot be received, or links are wrongMail DeliveryThen check mail
Browser blocks cross-origin API callsNetwork AccessFirst confirm it is not a Public Site URL issue
Background tasks, thumbnails, image preview, archive preview, or trash retention behaves abnormallyRuntime / File Processing / Storage and RetentionThen check operations CLI
Link import file size, speed, concurrency, or timeout is unsuitableRuntime / File ProcessingThen check operations CLI
Audio/video playback links on share pages expire too quickly or too slowlyRuntimeThen check sharing and public access
WebDAV global switch, system-file blocking, or connection behavior is abnormalWebDAVThen check WebDAV
You need to see who changed what, or want to narrow the audit scopeAudit LogsThen check admin console
What you want to doWhere to change it
Make share links, mail links, WebDAV addresses, and online previews point to the correct domainSite Configuration -> Public Site URL
Change the title, logo, or favicon shown on login and share pagesSite Configuration
Add external preview or WOPI opening methods for Office filesSite Configuration -> Preview Apps
Enable or limit read-only archive previewFile Processing -> Archive Preview
Connect OIDC / Generic OAuth2 / GitHub / QQ / Google / Microsoft login providersAdmin -> External Authentication
Disable public registrationUser Management -> Allow Public User Registration
Temporarily disable Passkey sign-inUser Management -> Registration & Login -> Allow Passkey Sign-In
Restrict email addresses usable for local registration and local email changesUser Management -> Registration & Login -> Local Account Email Allowlist / Blocklist
Change the default quota for new users; teams created without an explicit quota also use it, so recheck actual team quotas after creationStorage and Retention -> New User Default Storage Quota
Tune cookie security requirements and Access / Refresh Token TTLsAuthentication and Cookies
Tune activation, email-change, and password reset link TTLsAuthentication and Cookies
Enable email-code MFA, or allow TOTP users to use email codes as fallbackAuthentication and Cookies
Tune the external login email verification mail templateMail Delivery -> External Login Email Verification
Tune the login email code mail templateMail Delivery -> Login Email Code
Configure SMTP, send test mail, or edit transactional mail templatesMail Delivery
Tune retention for trash, version history, and team archivesStorage and Retention
Tune temporary background task artifact retentionRuntime -> Background Tasks
Tune the online extraction staging size limitFile Processing -> Online Extraction Staging Size Limit
Tune thumbnail size limits, image preview strategy, and vips / ffmpeg / ffprobe processorsFile Processing -> Media Processing
Tune HTTP/HTTPS link import file size, speed, concurrency, and timeoutFile Processing -> Link Import
Disable WebDAV, or adjust blocking for system files such as .DS_Store and Thumbs.dbWebDAV
Tune mail dispatch, background task dispatch, concurrency, retry, and periodic cleanup frequencyRuntime
Tune the temporary audio/video streaming session TTL on share pagesRuntime -> Share Streaming Playback Session TTL
Enable or disable audit logs, or adjust the recorded scopeAudit Logs
  • Site Configuration - Public site URL, title, logo, favicon, preview apps
  • User Management - Public registration, registration activation, Passkey sign-in, local email allow/block lists, avatars, Gravatar
  • Authentication and Cookies - Cookie security rules, token TTLs, activation/email-change/reset link TTLs, email-code MFA
  • Mail Delivery - SMTP, sender, test mail, registration activation/email-change/password reset/external login email verification/login email code mail templates
  • Network Access - Browser cross-site access rules (CORS)
  • Runtime - Mail queue, background tasks, temporary task artifact retention, task-lane concurrency, share streaming playback sessions, periodic cleanup, low-level consistency checks, follower node health checks, list limits
  • Storage and Retention - Trash, version history, default quotas
  • File Processing - Online extraction, archive building, archive preview, link import, thumbnails, media metadata, and media processors
  • WebDAV - Global switch and common system-file blocking
  • Audit Logs - Switch, recorded scope, and retention time
  • Custom Configuration, Other - Advanced scenarios only
ChangeEffective Timing
Site address, title, logo, faviconShown with the new values after refreshing the page
Preview apps / online Office related settingsApplied to previews opened later
WOPI access token / lock / discovery cacheApplied to new WOPI sessions opened later
Public registration, registration activation, mail templatesApplied to later login flows and newly sent emails
Local email allowlist / blocklistApplied to later local registration and local email changes; third-party SSO is not affected
Passkey sign-in switchApplied to later Passkey sign-in requests; existing Passkeys are not deleted
External login providersApplied to the login page and later external login flows after saving
External login email verification mail template, login email code mail templateApplied to newly sent matching emails
Email-code MFA switch, fallback policy, TTL, and resend cooldownApplied to later MFA login flows and newly sent email codes
Cookie security, token TTLsApplied to later login, refresh, and share password verification
Avatar directory, avatar size limitApplied to avatar uploads after the change
Default quotaOnly affects accounts created later, and teams created later without an explicit quota
Audit log switch and recorded scopeLater audit writes follow the new scope
Audit log retention windowBackground cleanup tasks work with the new rules
Version history limitApplied when new versions are produced later
Online extraction staging limitApplied to online extraction tasks created later
Online extraction source, uncompressed size, entry count, path depth, compression ratio, and duration limitsApplied to online extraction tasks created later
Online archive compression global switchApplied to online-compression tasks created later; does not affect online extraction, folder archive downloads, or archive preview
User and share archive-download switchesAfter saving, the official frontend refreshes public capabilities and hides or shows the matching ZIP methods; new requests are also enforced by the backend
Archive build entry, total source size, and output size limitsApplied to online compression and archive download tasks created later
Link import engine registry, temp directory, file size, speed, concurrency, request timeout, and aria2 parametersApplied to link-import tasks created later; manual retries clean old artifacts from both the default temp directory and the current offline-download temp directory
Archive preview switches and limitsApplied to later requests and new archive_preview_generate tasks
Thumbnail source file size limitApplied to files entering thumbnail and image-preview tasks later
Thumbnail and image-preview max dimensionsApplied to later thumbnail and image-preview generation; non-default dimensions use dimension-specific cache paths and ETags
Image preview strategyApplied when the frontend later opens image previews and chooses the default source
Media processor switches, commands, extension bindingsApplied to files entering thumbnail and image-preview tasks later
Media metadata switch, size limit, processor bindingApplied to files entering media metadata tasks later; existing caches are not automatically rescanned because configuration changed
Mail dispatch, background tasks, periodic cleanup, follower node health check frequencyApplied to later background polling
Background task lane concurrency and maximum attemptsApplied to background tasks scheduled or retried later
Share streaming playback session TTLApplied to audio/video playback sessions created later on share pages
WebDAV switch, system-file blocking rules, CORSNew requests respond with the new rules immediately

The Custom Configuration group is mainly for custom frontend developers. It is a global-variable persistence layer reserved for custom frontend developers.

If you replace the frontend with your own version by using the ./frontend-override/ directory, and you need to persist some site-level configuration such as theme, brand color, custom entry points, or third-party integration credentials, you can write them into the database through Custom Configuration, then expose them to the frontend through backend APIs.