Files
bookhoard/docs/developer/api/libraries/browse-folders.md
T
john-okeefe f91b1bf54b docs(api): document library folder browsing endpoint
- Add docs/developer/api/libraries/browse-folders.md
- Document security features (path traversal protection, admin-only)
- Include usage examples and error responses
- Clarify browses server filesystem, not client's

docs(user): add admin library folder browser documentation

- Add docs/user/admin-library-management.md
- Document how to use the folder browser UI
- Include security notes and manual entry instructions
- Explain server filesystem browsing behavior

Fixes: Issue 2 (documentation)
2026-02-23 17:03:35 -05:00

1.3 KiB

Browse Library Folders

Browse server directories for folder selection in library management.

Endpoint: GET /api/libraries/browse Auth: Required (Admin only)

Query Parameters

Parameter Type Required Description
path string No Directory path to browse (default: "/")

Request Headers

Header Type Required Description
Authorization string Yes Bearer token (admin only)

Example Request

GET /api/libraries/browse?path=/home/user
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

Response (200 OK)

{
  "current_path": "/home/user",
  "parent_path": "/home",
  "directories": ["Documents", "Downloads", "Books", "Music"]
}

Error Responses

Code Description
400 Path traversal attempt or invalid path
401 Invalid or expired token
403 User is not an admin
400 Path does not exist
400 Path is not a directory

Security

  • Path traversal protection: Blocks requests containing ".."
  • Admin only: Regular users receive 403 Forbidden
  • Directories only: Returns only directory names, not file listings
  • Server filesystem: Browses server's filesystem, not client's