Security update: Docker images from v0.4.0-rc.1 fix the high-severity FFmpeg MagicYUV decoder vulnerability (CVE-2026-8461). Upgrade instances using older images immediately.View CVE advisory
Security update: v0.4.0-beta.3 fixes a WebDAV request issue that can terminate the server process. Upgrade older instances promptly.View advisory
System Settings
Entry point:
Admin -> System SettingsStart from Your Goal
Section titled “Start from Your Goal”| Goal | Check This Group First | If It Is Still Wrong |
|---|---|---|
| Site links, share links, or mail link domains are wrong | Site Configuration | Then check reverse proxy |
| Login cookie, token, activation link, or email-code MFA timing is unsuitable | Authentication and Cookies | Then check login and sessions |
| Registration, Passkey sign-in, local email allow/block lists, avatars, or Gravatar behavior is unexpected | User Management | Then check login and sessions |
| Passkey, MFA, external login, or external identity binding is unexpected | Site Configuration / Admin -> External Authentication / Authentication and Cookies | Then check login and sessions |
| Mail cannot be received, or links are wrong | Mail Delivery | Then check mail |
| Browser blocks cross-origin API calls | Network Access | First confirm it is not a Public Site URL issue |
| Background tasks, thumbnails, image preview, archive preview, or trash retention behaves abnormally | Runtime / File Processing / Storage and Retention | Then check operations CLI |
| Link import file size, speed, concurrency, or timeout is unsuitable | Runtime / File Processing | Then check operations CLI |
| Audio/video playback links on share pages expire too quickly or too slowly | Runtime | Then check sharing and public access |
| WebDAV global switch, system-file blocking, or connection behavior is abnormal | WebDAV | Then check WebDAV |
| You need to see who changed what, or want to narrow the audit scope | Audit Logs | Then check admin console |
Places Administrators Change Most Often
Section titled “Places Administrators Change Most Often”| What you want to do | Where to change it |
|---|---|
| Make share links, mail links, WebDAV addresses, and online previews point to the correct domain | Site Configuration -> Public Site URL |
| Change the title, logo, or favicon shown on login and share pages | Site Configuration |
| Add external preview or WOPI opening methods for Office files | Site Configuration -> Preview Apps |
| Enable or limit read-only archive preview | File Processing -> Archive Preview |
| Connect OIDC / Generic OAuth2 / GitHub / QQ / Google / Microsoft login providers | Admin -> External Authentication |
| Disable public registration | User Management -> Allow Public User Registration |
| Temporarily disable Passkey sign-in | User Management -> Registration & Login -> Allow Passkey Sign-In |
| Restrict email addresses usable for local registration and local email changes | User Management -> Registration & Login -> Local Account Email Allowlist / Blocklist |
| Change the default quota for new users; teams created without an explicit quota also use it, so recheck actual team quotas after creation | Storage and Retention -> New User Default Storage Quota |
| Tune cookie security requirements and Access / Refresh Token TTLs | Authentication and Cookies |
| Tune activation, email-change, and password reset link TTLs | Authentication and Cookies |
| Enable email-code MFA, or allow TOTP users to use email codes as fallback | Authentication and Cookies |
| Tune the external login email verification mail template | Mail Delivery -> External Login Email Verification |
| Tune the login email code mail template | Mail Delivery -> Login Email Code |
| Configure SMTP, send test mail, or edit transactional mail templates | Mail Delivery |
| Tune retention for trash, version history, and team archives | Storage and Retention |
| Tune temporary background task artifact retention | Runtime -> Background Tasks |
| Tune the online extraction staging size limit | File Processing -> Online Extraction Staging Size Limit |
| Tune thumbnail size limits, image preview strategy, and vips / ffmpeg / ffprobe processors | File Processing -> Media Processing |
| Tune HTTP/HTTPS link import file size, speed, concurrency, and timeout | File Processing -> Link Import |
Disable WebDAV, or adjust blocking for system files such as .DS_Store and Thumbs.db | WebDAV |
| Tune mail dispatch, background task dispatch, concurrency, retry, and periodic cleanup frequency | Runtime |
| Tune the temporary audio/video streaming session TTL on share pages | Runtime -> Share Streaming Playback Session TTL |
| Enable or disable audit logs, or adjust the recorded scope | Audit Logs |
Current Groups
Section titled “Current Groups”- Site Configuration - Public site URL, title, logo, favicon, preview apps
- User Management - Public registration, registration activation, Passkey sign-in, local email allow/block lists, avatars, Gravatar
- Authentication and Cookies - Cookie security rules, token TTLs, activation/email-change/reset link TTLs, email-code MFA
- Mail Delivery - SMTP, sender, test mail, registration activation/email-change/password reset/external login email verification/login email code mail templates
- Network Access - Browser cross-site access rules (CORS)
- Runtime - Mail queue, background tasks, temporary task artifact retention, task-lane concurrency, share streaming playback sessions, periodic cleanup, low-level consistency checks, follower node health checks, list limits
- Storage and Retention - Trash, version history, default quotas
- File Processing - Online extraction, archive building, archive preview, link import, thumbnails, media metadata, and media processors
- WebDAV - Global switch and common system-file blocking
- Audit Logs - Switch, recorded scope, and retention time
- Custom Configuration, Other - Advanced scenarios only
When Changes Take Effect
Section titled “When Changes Take Effect”| Change | Effective Timing |
|---|---|
| Site address, title, logo, favicon | Shown with the new values after refreshing the page |
| Preview apps / online Office related settings | Applied to previews opened later |
| WOPI access token / lock / discovery cache | Applied to new WOPI sessions opened later |
| Public registration, registration activation, mail templates | Applied to later login flows and newly sent emails |
| Local email allowlist / blocklist | Applied to later local registration and local email changes; third-party SSO is not affected |
| Passkey sign-in switch | Applied to later Passkey sign-in requests; existing Passkeys are not deleted |
| External login providers | Applied to the login page and later external login flows after saving |
| External login email verification mail template, login email code mail template | Applied to newly sent matching emails |
| Email-code MFA switch, fallback policy, TTL, and resend cooldown | Applied to later MFA login flows and newly sent email codes |
| Cookie security, token TTLs | Applied to later login, refresh, and share password verification |
| Avatar directory, avatar size limit | Applied to avatar uploads after the change |
| Default quota | Only affects accounts created later, and teams created later without an explicit quota |
| Audit log switch and recorded scope | Later audit writes follow the new scope |
| Audit log retention window | Background cleanup tasks work with the new rules |
| Version history limit | Applied when new versions are produced later |
| Online extraction staging limit | Applied to online extraction tasks created later |
| Online extraction source, uncompressed size, entry count, path depth, compression ratio, and duration limits | Applied to online extraction tasks created later |
| Online archive compression global switch | Applied to online-compression tasks created later; does not affect online extraction, folder archive downloads, or archive preview |
| User and share archive-download switches | After saving, the official frontend refreshes public capabilities and hides or shows the matching ZIP methods; new requests are also enforced by the backend |
| Archive build entry, total source size, and output size limits | Applied to online compression and archive download tasks created later |
| Link import engine registry, temp directory, file size, speed, concurrency, request timeout, and aria2 parameters | Applied to link-import tasks created later; manual retries clean old artifacts from both the default temp directory and the current offline-download temp directory |
| Archive preview switches and limits | Applied to later requests and new archive_preview_generate tasks |
| Thumbnail source file size limit | Applied to files entering thumbnail and image-preview tasks later |
| Thumbnail and image-preview max dimensions | Applied to later thumbnail and image-preview generation; non-default dimensions use dimension-specific cache paths and ETags |
| Image preview strategy | Applied when the frontend later opens image previews and chooses the default source |
| Media processor switches, commands, extension bindings | Applied to files entering thumbnail and image-preview tasks later |
| Media metadata switch, size limit, processor binding | Applied to files entering media metadata tasks later; existing caches are not automatically rescanned because configuration changed |
| Mail dispatch, background tasks, periodic cleanup, follower node health check frequency | Applied to later background polling |
| Background task lane concurrency and maximum attempts | Applied to background tasks scheduled or retried later |
| Share streaming playback session TTL | Applied to audio/video playback sessions created later on share pages |
| WebDAV switch, system-file blocking rules, CORS | New requests respond with the new rules immediately |
About “Custom Configuration”
Section titled “About “Custom Configuration””The Custom Configuration group is mainly for custom frontend developers. It is a global-variable persistence layer reserved for custom frontend developers.
If you replace the frontend with your own version by using the ./frontend-override/ directory, and you need to persist some site-level configuration such as theme, brand color, custom entry points, or third-party integration credentials, you can write them into the database through Custom Configuration, then expose them to the frontend through backend APIs.