FileRise folder encryption switches off WebDAV, sharing and OnlyOffice, and the compose file ships SECURE false
🗂️ FileRise – lightweight, self-hosted file manager & storage hub with granular ACLs, resumable uploads, encrypted folders, WebDAV & SSO. Fully Docker / Unraid compatible.
At a glance
- What is it?
- FileRise is a self-hosted PHP file manager with per-folder permissions, WebDAV and optional encryption at rest, split into an MIT core and a paid tier. Two facts in the deployment files matter more than the feature list: enabling folder encryption automatically disables four other features for those folders, and the shipped compose file defaults its SECURE variable to false while deliberately leaving the token key unset so each install generates its own.
- Who is it for?
- This is a credible self-hosted file manager if your needs stop at storage, sharing and permissions, and the ACL enforcement claim across the interface, the API and WebDAV is the part that would take the most work to get right in a homegrown alternative. Two decisions to make before you install.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 3 days ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.
Editorial analysis
Folder encryption switches off four other features
Encryption at rest is the feature to read the fine print on. Folders and all their descendants are encrypted on disk with authenticated encryption, transparently decrypted on download, with protection inherited by subfolders. The master key is either generated by the application or supplied through an environment variable. And then the clause that decides whether it is usable for you: when encryption is enabled on a folder, the incompatible features are automatically disabled for safety. Those features are WebDAV, sharing, ZIP operations and OnlyOffice. So a single toggle removes your drive mount, your share links, your archive handling and your document editor for that subtree, with no partial mode and no per-feature choice. The readme puts this in a sub-bullet rather than in a warning, which is the one thing to fix in your own planning.
SECURE ships false, and the token key is generated on purpose
The compose file is candid in two directions. It sets its security flag off by default, with the value taken from an environment variable that falls back to false, so an install that copies the file and runs it gets the relaxed setting. In the other direction it leaves the persistent tokens key blank on purpose, with a comment saying a pristine install should generate and persist a unique key under the metadata directory, and the image build states in its own comments that no default token key is baked in. That is the right call and it is worth crediting, since a shipped default signing key is a common way self-hosted apps get compromised. Three host directories are bind mounted for uploads, users and metadata, and the container has a health check that curls the local site every thirty seconds with a twenty second start period.
Six build toggles, and the PDF thumbnails hang off one of them
The image takes six build arguments that decide what gets installed, and they are not all on:
ARG INSTALL_FFMPEG=0
ARG INSTALL_CLAMAV=1
ARG INSTALL_7ZIP=1
ARG INSTALL_UNAR=1
ARG INSTALL_SMBCLIENT=1
ARG INSTALL_POPPLER=1Virus scanning, archive extraction, the SMB client and the PDF toolkit are installed by default; the video toolkit is not. The readme names the utility behind the optional first-page PDF thumbnails, and that utility comes from the PDF toolkit package, so turning that one argument off removes the thumbnail feature with nothing in the compose file to tell you. The package list also explains why the build appends the universe component to the Ubuntu source list: several of these packages do not live in main. Reading these six values is faster than reading the install guide.
The image sets PUID 99 and home root, the compose file sets 1000
The two deployment files disagree about who the process runs as. The image sets a user id of 99 and a group id of 100, and it also sets the home directory to root. The compose file sets the user id to 1000 and the group id to 1000, and it turns ownership fixing on at start. Nothing reconciles the two, so which identity your files end up owned by depends on which path you installed from, and the home directory setting inside the image is at odds with the intent of a user id switch. Upload limits are triplicated the same way: the image sets three separate variables to five gigabytes and the compose file sets a fourth. The date and time format has a default of a US style month, day, year with a twelve hour clock, which is a small thing that surprises people outside that locale.
The pitch names a client portal that the free tier does not include
The open core split is where the marketing and the packaging part company. The audience line says the project is for anyone who wants a self-hosted file manager, a storage hub, a client portal and an AI workflow workspace. The core tier is then defined as the open-source feature set covering permissions, folder and file sharing, uploads, tags and search, PDF previews, multiple local roots and WebDAV sources. The paid tier adds user groups, client portals, automation, extra source adapters, gateway shares, search everywhere with audit tooling, and a permissions-aware AI workspace. So two of the four things the audience line promises are the paid tier. The same pattern runs through the security features: single sign-on and automatic user provisioning are core while group mapping is not, and virus scanning is core while the detection log with CSV export is not. The capability ships free; the visibility into it does not.
The only scale claim is a sidebar tree
Scan the highlights for a number and there is one: tested with more than a hundred thousand folders in the sidebar tree without the interface becoming unusable. That is a claim about one tree widget, and it comes with no hardware, no version, no folder depth and no method. Everything else in the highlights is a capability statement, and several of those are strong on their own terms, such as chunked resumable uploads that continue after a dropped connection, WebDAV mounts that honour the same permissions as the browser interface, fuzzy search across names, tags, uploader and content, and a trash with time-based retention. But if you are sizing this for a large shared drive, the readme gives you one unverified sentence and a live demo, and that is the whole of it.
A PHP application that a language detector reports as JavaScript
The repository layout says PHP. There is a Composer manifest and a lock file, a code sniffer configuration, a custom PHP settings file at the root, a start script, and the usual source, public, resources, configuration, scripts and tests directories. There is also a security policy, a third party notices file, a directory of licence files, and a CodeQL configuration, which together suggest a project that expects to be audited. What the repository reports as its primary language is JavaScript, which almost certainly comes from the front end assets and the bundled code editor rather than from the application logic. One packaging detail is worth noting: the dependency stage copies only the two Composer files and nothing else before installing, so no install-time script can reach the application source, which is a tighter build than most projects manage.
Behind a reverse proxy you may need three settings
Subpath awareness is handled properly and needs to be configured. The application is designed to sit behind Nginx, Traefik, Caddy or Apache, including under a path prefix such as a files subdirectory, and it generates URLs for assets, the API, portals, the progressive web app and share links accordingly. Two things then have to line up. If the proxy strips the prefix before forwarding, you set a base path variable or send a forwarded prefix header, and if your proxy or firewall rewrites the public address there is a separate explicit published URL setting for it. Otherwise share links point at the wrong host. Forwarded headers and Kubernetes ingress setups are supported. One oddity: the URL generation covers portals, which belong to the paid tier, so a free installation is still generating portal URLs it will never serve.
Editorial conclusion
This is a credible self-hosted file manager if your needs stop at storage, sharing and permissions, and the ACL enforcement claim across the interface, the API and WebDAV is the part that would take the most work to get right in a homegrown alternative. Two decisions to make before you install. Decide whether you need folder encryption, because accepting it means losing WebDAV, sharing, archive operations and document editing on those folders, and there is no partial setting. And change the SECURE default and the upload limits before exposing the container to a network, since the compose file ships with the first off and a five gigabyte ceiling in three separate variables. Finally, note what the readme claims about scale: one sentence about a hundred thousand folders in a sidebar tree, with no hardware, no version and no method behind it.
Frequently asked questions
What is FileRise and what licence is the core under?
It is a self-hosted web file manager and storage hub with WebDAV, sharing and per-folder permissions, delivered as one PHP application you control. The core feature set is MIT licensed and covers permissions, sharing, uploads, tags and search, PDF previews, multiple local roots and WebDAV sources, with a separate paid tier on top.
What happens when I turn on folder encryption in FileRise?
Folders and their descendants are encrypted on disk and decrypted transparently on download, with the master key generated by the application or supplied by environment variable. The incompatible features are then disabled automatically for safety: WebDAV, sharing, ZIP operations and OnlyOffice. There is no partial setting.
Is the SECURE setting enabled by default in the FileRise compose file?
No. The compose file sets it from an environment variable that falls back to false. The same file deliberately leaves the persistent tokens key blank, with a comment saying a pristine install should generate and persist a unique key under the metadata directory, and the image build ships no default key.
What does FileRise need in order to show PDF thumbnails?
The pdftoppm utility, which comes from the poppler package. The image installs it behind a build argument that is on by default, alongside virus scanning, archive tools and an SMB client, while the video toolkit argument is off by default.
Is the client portal included in the free FileRise tier?
No. The MIT core covers permissions, sharing, uploads, tags and search, PDF previews, multiple local roots and WebDAV sources. User groups, client portals, automation, extra source adapters, gateway shares, search everywhere with audit tooling and the AI workspace are all in the paid tier.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/error311-filerise)