Open-source project
qkqpttgf/OneManager-php avatar
qkqpttgf/OneManager-php

OneManager-php: a serverless OneDrive index you deploy to Vercel, Replit or a PHP host

An index & manager of Onedrive based on serverless. Can be deployed to Vercel/Heroku/SCF/FG/FC/CFC/PHP web hosting/VPS.

3,793 stars2,508 forksHTMLLicense varies

At a glance

What is it?
OneManager-php turns a OneDrive or SharePoint account into a browsable file index, with the PHP code running on Vercel, Replit, a VPS or a cloud function. The README is honest about what has stopped working, and the release tags are an archive rather than the current code.
Who is it for?
Adopt OneManager-php if you want a self-hosted OneDrive listing and you are willing to read the Chinese README for the cloud function platforms, since the English one only says 'see CN readme' for Huawei FG, Aliyun FC and Baidu CFC. Do not adopt it if you expect a maintained release channel: the README states the Releases page is an archive, not the newest code, and the newest tag, v3.5, is dated 2022-01-29.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 155 days ago.
What is it written in?
Mainly HTML, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What OneManager-php replaces

OneDrive gives you a share link, not a directory listing. If you keep a folder of files there and want to hand out a browsable index, with sorting, a logo, a guest upload area and a readme rendered on the page, you either build that yourself or you run something like this. OneManager-php is a PHP application that reads a OneDrive or SharePoint account and renders its contents as a web page. The repository topics list SharePoint alongside OneDrive, and the deploy targets are all places that can run PHP without you owning a machine: Vercel, Replit, Huawei Function Graph, Aliyun Function Compute, Baidu CFC, Tencent SCF, plus a plain VPS or shared PHP host.

The audience is narrow and specific. It is for people who already have storage in Microsoft's cloud and want a front end they control, rather than for teams looking for a document management system. There is no database in the top-level layout, no user table, no search index. The state lives in .data/config.php, and the rest is files in OneDrive.

How the redirect mechanism keeps bandwidth off your server

The README describes the core trick plainly: when a visitor downloads a file, the program produces a direct URL and the visitor downloads from MS OFFICE through that URL, so the server spends only a little bandwidth producing it. Uploads work the same way in reverse. That is the whole architecture. The PHP process authenticates, lists, and mints links; the bytes never pass through it.

This matters on the free tiers the project targets, where outbound traffic is the first thing you run out of. It also means the listing page is the only thing your host actually serves, so a cheap PHP host is enough for a folder of large files. The trade-off is that the direct URL is a link to Microsoft's infrastructure, and the README does not describe how long those URLs stay valid or what happens when one expires mid-download.

Configuration is path-based. The README notes that the XXX_path setting is a path inside OneDrive, not a URL path, and the program resolves it against the account. Several behaviours are driven by filenames rather than settings: an index.html in a folder makes the program show that file's content instead of listing the folder, readme.md and head.md are rendered as markdown at the top or bottom, and head.omf and foot.omf are rendered as HTML with javascript enabled. A favicon.ico placed in the home folder of the first disk becomes the site icon.

Deploying to Vercel and finishing the first-run setup

Vercel is the target the English README leads with. It gives the official site, a demo at onemanager-php.vercel.app, and points installation at an external page rather than repeating the steps. Two constraints are stated: you must wait 30 to 50 seconds after changing config to be sure the deploy is READY, and Vercel limits you to 100 deploys per day. On a platform where a config edit is a deploy, that second number is the one that bites during setup, when you are changing settings repeatedly.

Replit is the other path with concrete steps in English. The README gives two methods; the first is import from GitHub, and the second clones the repository into a fresh PHP Web Server repl:

bash
git clone https://github.com/qkqpttgf/OneManager-php && mv -b OneManager-php/* ./ && mv -b OneManager-php/.[^.]* ./ && rm -rf *~ && rm -rf OneManager-php

After that you press Run, and the README insists you open the resulting page in a new tab or window rather than the embedded preview. Replit has its own maintenance cost: the README says you should Republish after 30 days to keep the repl active.

On a VPS or shared PHP host the steps are enumerated. Serve the directory over HTTP, enable rewrite_module (or RewriteEngine, or URL_rewrite), upload the code, make sure the rule in .htaccess (or web.config under IIS) sends queries to index.php, and make .data/config.php readable and writable, with 666 suggested. Then open the site in a browser. Nothing here is unusual for PHP, but every step is load-bearing: a host without URL rewriting will serve the files but not the application.

Platforms the README has already written off

The English README is more useful for what it crosses out than for what it recommends. Heroku is struck through with the reason 'Dyno will no longer free', and the deploy button is disabled because the source violates the Salesforce Acceptable Use and External-Facing Services Policy. Tencent SCF is struck through with 'SCF no longer free', and its install section just says to see the Chinese README. Glitch is struck through with 'End service'. Three of the eight listed platforms are dead in the documentation itself.

Huawei FG, Aliyun FC and Baidu CFC remain listed with no strike-through, but all three say 'see CN readme' for installation, and every one of them has a demo listed as null. If you cannot read the Chinese README, those platforms are effectively undocumented for you. That is a real constraint, not a formatting complaint.

The release history reinforces the point. The newest tag is v3.5 from 2022-01-29, and it is about Replit and Gitlab. v3.3, from 2021-08-18, is the Vercel platform release. The README opens by stating that Releases is used as an archive, not the newest code, which means the tags tell you when a platform was added, not what the current code supports. The last push to the repository was on 2026-04-30, so work has happened since those tags, but there is no release channel that reflects it.

Guest uploads, sorting and the folder behaviours to know about

Two features get a sentence each and deserve more. The guest upload path is a folder where guests can upload files but cannot list them, with the admin excluded from that restriction. It is a drop box, not a shared folder, and the README does not describe any validation of what gets uploaded, so the folder is only as safe as your willingness to accept arbitrary files from anyone who has the URL.

Sorting is client-side in effect: clicking EditTime or Size sorts the list by time or size, and clicking File resumes the default sort. There is no search, no pagination setting and no filter described. For a large folder this is a listing, not a browsing experience.

The functional files are the closest thing to a template system. index.html replaces the listing entirely with its own content, readme.md and head.md render as markdown, and head.omf and foot.omf render as HTML with javascript working. That last pair is the extension point: you can inject markup and script above or below the listing without touching PHP. It is also the sharpest edge, since the content comes from the storage account and runs in your visitors' browsers.

Where OneManager-php is the wrong tool

If you need permissions, audit trails or user accounts, this is the wrong project. There is no visible authentication model beyond the admin and the guest upload folder, and the repository layout has no place for a user store. Anything that must be restricted per person belongs behind something else.

If your files are not in OneDrive or SharePoint, nothing here applies. The project is a front end for Microsoft's storage, and the redirect design depends on Microsoft issuing the direct URLs. The same idea for other backends would be a different program.

If you want a release you can pin and upgrade on a schedule, look elsewhere. The README's own notice says the Releases page is an archive, and the newest tag predates the last push by more than four years. You would be deploying the master branch and tracking it yourself.

And if your host cannot rewrite URLs, or you cannot make .data/config.php writable, the install stops at step four. The README suggests 666 permissions on that file, which on a shared host means other accounts may be able to write to your configuration. That is a deployment decision the project leaves to you.

How it compares with a static file index

The obvious alternative is a static site generator pointed at a storage bucket, or a plain directory index served by nginx. Those give you a listing with no PHP, no config file to make writable, and no cloud function to keep alive. The difference in approach is where the listing comes from: a static index is generated from a snapshot, while OneManager-php reads the OneDrive account at request time, so a file you add in OneDrive appears without a rebuild.

That live read is the reason to pick this project, and it is also its cost. Every listing depends on the account being reachable and on the credential in .data/config.php still being valid. A static index keeps serving after the storage credential is revoked; this one does not.

A second alternative is running a general PHP file manager against a mounted drive. That moves the bytes through your server, which is exactly what the redirect design avoids, and it puts you back on the bandwidth limits the project was built to dodge. The README's framing is consistent: the server produces links, Microsoft serves files.

Licence and upgrade cost

The repository does not declare a licence in the code listing, and the README does not discuss one. Without a licence file, the default position is that no rights are granted beyond what the platform's terms allow, which is a problem if you plan to redistribute the code or ship it inside a product. That is a question for your own legal review, not something the README answers.

The upgrade path is manual by design. Because Releases is an archive and the newest tag is v3.5 from 2022-01-29, the practical approach is to track the master branch. The repository includes update.sh, writeable.sh and a version file, so there is tooling for updating an existing install, but the README does not document a rollback procedure or a migration step between versions. On Vercel, where a config change triggers a deploy and the README caps you at 100 deploys per day, an upgrade is a deploy you should schedule rather than improvise.

The running cost is mostly the platform's. Vercel and Replit have their own limits, Tencent SCF and Heroku are documented as no longer free, and a VPS costs whatever your host charges. The project itself adds no service to pay for.

Editorial conclusion

Adopt OneManager-php if you want a self-hosted OneDrive listing and you are willing to read the Chinese README for the cloud function platforms, since the English one only says 'see CN readme' for Huawei FG, Aliyun FC and Baidu CFC. Do not adopt it if you expect a maintained release channel: the README states the Releases page is an archive, not the newest code, and the newest tag, v3.5, is dated 2022-01-29. Before committing, verify that your host can run the rewrite rule from .htaccess (or web.config on IIS) so that queries reach index.php, and that .data/config.php can be made writable, because the README suggests 666 and the setup writes into that file.

Frequently asked questions

How do I install OneManager-php on Vercel?

The English README points installation at an external page, https://scfonedrive.github.io/Vercel/Deploy.html, and gives a demo at onemanager-php.vercel.app. It warns that you must wait 30 to 50 seconds after changing config to be sure the deploy is READY, and that Vercel limits you to 100 deploys per day.

Does OneManager-php work on Tencent SCF or Heroku?

Both are struck through in the README. Tencent SCF is marked 'SCF no longer free' and Heroku is marked 'Dyno will no longer free', with the Heroku deploy button disabled because the source violates the Salesforce Acceptable Use and External-Facing Services Policy.

Where does OneManager-php store its configuration?

In .data/config.php. The VPS install steps say to change that file so it can be read and written, suggesting 666, and the program writes into it when you change settings.

Can visitors upload files with OneManager-php?

Yes, through the guest upload path, which the README describes as a folder where guests can upload files but cannot list them, with the admin excluded. The README does not describe any validation of what is uploaded.

Official sources

  1. Issues
  2. qkqpttgf/OneManager-php on GitHub
  3. README
  4. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/qkqpttgf-onemanager-php.svg)](https://hysenlabs.com/projects/qkqpttgf-onemanager-php)