Storage: share files with a phone's browser (a web file manager) #88

Closed
opened 2026-10-07 21:49:32 +00:00 by twisla · 0 comments
Owner

Idea

Get files on and off the SD card from a phone on the same network, in the phone's browser, with nothing to install: the device serves a small file manager as a web page.

Why

Today a file reaches the card through the Debug Console's put and get (a PC and a script), or by taking the card out. A phone has neither.

Why a web page, and not FTP, SFTP or WebDAV

On the phone On the device
Web page any browser a small HTTP server streaming to and from the card
WebDAV an app, on iOS and Android the same server and more verbs: a later addition for computers
FTP an app; passwords in clear easy, two connections a transfer
SFTP an app a whole SSH server: too big for this device

Decided

  • Off unless asked for: a "Share files" screen in the Storage App. The server runs only while that screen is open.
  • A code shown on the device (and a QR code of the address), asked for by the page: someone else on the Wi-Fi can't just browse the card.
  • The Storage App's rules: the folders the firmware keeps for itself stay protected.
  • Streamed: an upload goes to the card in pieces, so a file's size isn't limited by memory; it is written under a temporary name and renamed when whole.
  • List, download, upload (several files), new folder, delete.

Known limit

No encryption. A TLS server costs about 40 KB of memory a connection. On a network that isn't trusted, the files and the code can be read by who listens. Through the WireGuard tunnel (#8) they are protected.

Later

WebDAV on the same server, renaming and moving from the page, sharing from the Shell.

## Idea Get files on and off the SD card from a phone on the same network, in the phone's browser, with nothing to install: the device serves a small file manager as a web page. ## Why Today a file reaches the card through the Debug Console's `put` and `get` (a PC and a script), or by taking the card out. A phone has neither. ## Why a web page, and not FTP, SFTP or WebDAV | | On the phone | On the device | |---|---|---| | Web page | any browser | a small HTTP server streaming to and from the card | | WebDAV | an app, on iOS and Android | the same server and more verbs: a later addition for computers | | FTP | an app; passwords in clear | easy, two connections a transfer | | SFTP | an app | a whole SSH server: too big for this device | ## Decided - **Off unless asked for:** a "Share files" screen in the Storage App. The server runs only while that screen is open. - **A code shown on the device** (and a QR code of the address), asked for by the page: someone else on the Wi-Fi can't just browse the card. - **The Storage App's rules:** the folders the firmware keeps for itself stay protected. - **Streamed:** an upload goes to the card in pieces, so a file's size isn't limited by memory; it is written under a temporary name and renamed when whole. - List, download, upload (several files), new folder, delete. ## Known limit **No encryption.** A TLS server costs about 40 KB of memory a connection. On a network that isn't trusted, the files and the code can be read by who listens. Through the WireGuard tunnel (#8) they are protected. ## Later WebDAV on the same server, renaming and moving from the page, sharing from the Shell.
twisla added this to the F1 Files and Notes milestone 2026-10-07 21:49:32 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: twisla/roro9stack#88