Files, terminal and editor

In preview

File operations run as the account's own Linux user, so the kernel, not the panel, decides what they can touch. The browser terminal is a real shell in the same place.

Built and lab-tested

  • List, read, write, move, copy, trash, permissions, search, disk usage, archives and resumable uploads.
  • Paths are resolved with openat2(RESOLVE_BENEATH) against the home directory, so symlink and .. escapes are refused by the kernel.
  • Sub-users are confined to the folders granted to them.
  • Archives are extracted with size, file-count and ratio limits, and never create links or devices.
  • SSH keys with restrictions (source addresses, git-only or SFTP-only, expiry). Per user: SSH off, SFTP-only in a chroot, or a shell. Every sshd change is checked with sshd -t.
  • Browser terminal: a real PTY as the account user inside its slice, opened with a single-use ticket bound to your browser session, with idle timeout and optional recording.
  • Root terminal for administrators needs a fresh confirmation and is always recorded and audited.

Coming soon

  • The file manager screens: drag and drop, previews and a quick editor.
  • VS Code in the browser (code-server) per account, with Open VSX extensions.
  • Share links, file versions, FTP and WebDAV users.
  • Jailed shells with bubblewrap.

Dedicated screens for this area are being built on the RespireCloud design system. Today every action has a generated form in the panel, is one keystroke away in the command palette (Ctrl K), and is callable through the API.

Modules in this area