> what they actually need seems to be a massive user positive
So positive for the user that they filed a bug report about it?
> what they actually need seems to be a massive user positive
So positive for the user that they filed a bug report about it?
Exactly. Many people use Nextcloud's auto-upload to backup important data from their phone. In addition to photos, I use it to backup FreeOTP and WhatsApp, for instance. This does not work with the version from Google Play, see
https://github.com/nextcloud/android/issues/14334
EDIT: After some research, I think even that use case should be possible with SAF, you just need to move your backups to external storage that you can access via SAF.
it stopped working well or at all over the last 2 years or so. I think if a simple "allow access to the photo folder" would have fixed it they out have used it. maybe it doesn't get the events when a photo is made?
Then request access to their media folder. You don't need full disk access.
PDFs that I download live in downloads folder (which you can't give access to for some reason anyway).
Music lives elsewhere and so on.
Downloads is blocked because it would include everything you download, possibly including private stuff you don't want other apps to access. Just save the stuff that you want synced to a different folder.
I guess if you really want everything synced (e.g. doing a full device backup) then that would fall under Google's exception for backup apps and it would be allowed full disk access. Those are kinda separate use cases though. Maybe Nextcloud could make a separate "Nextcloud Device Backup" app which does that?
- If you want to lose time for 2 hours, please do yourself this questionable favour but I do not want to do that because some "wise" people cannot comprehend that some people want copy of entire thing, not one folder, entire thing.
> Downloads is blocked because it would include everything you download, possibly including private stuff you don't want other apps to access. The point: This is cloud application that connects to server that sits on my desk on NUC.
Do you understand that in the (Google)-(Open Source)-(Own Server) the Google part is one that most reasonable people consider not private.
> Just save the stuff that you want synced to a different folder.
Do you move entire folders or every file each time you download something because app cannot backup it - or do you change app. What if that's the only app that does it privately?
> Those are kinda separate use cases though.
Maybe it is not system developer job to decide for me that I want to give application the permission to do what I want application to do. It is not system nor developer job to stop owner (administrator) from what owner decides to do.
> Maybe Nextcloud could make a separate "Nextcloud Device Backup" app which does that?
Maybe competitors should not have permission on deciding what their competitors should do.
Google essentially makes everything private so cumbersome to use that it own solution seems easy.
>I suspect people want their entire photo folders mirrored into Nextcloud from the device
That isn't remotely the contention, nor do photos even qualify for this as they use a different API. Further, the reason this company gives for refusing to use the obviously more suitable structured storage API is that they don't want their files -- presumably mirrored from the cloud storage -- visible to other apps. Their complaint is technical nonsense and doesn't pass an ounce of scrutiny.
The argument by this company is nonsensical, and their argument seems to be "we did it this way before and we don't want to change". Firstly they can have their own app storage without granting access to any other app, and they can go through a system UI process to get access to additional folders (for instance "I want to back up my WhatsApp folder to this cloud provider"). They argue against the latter because they seem to think it somehow reveals the former, but that isn't the case whatsoever.
[1] - Well it's a bug in the Nextcloud product where they seem to just ignore that the instance lacks a permission
I think they're trying to keep their story simple, for the sake of clarity. I believe the nextcloud team when they say they need the permission.
Part of the issue is that nextcloud has many use cases, including ones where your files don't get synced to your mobile device until you touch the file, replacing them with a reference to a file. It's cool cause you can access and manage a tb of pictures or documents from a 64gb android.
I don't (and I do use NC). The sentence "SAF cannot be used, as it is for sharing/exposing our files to other apps" is simply wrong and llm_nerd is right that SAF should be able to handle that use case,see
https://developer.android.com/training/data-storage/shared/d...
There are some restrictions regarding which directories you can access, but for most use-cases it should be perfectly fine. It's also not that this should come as a surprise to them. In fact, there's an issue about this from the NC team themselves from August '22:
https://github.com/nextcloud/android/issues/10123
Why they still think SAF cannot be used is a mystery to me.
Even if that interface is insecure and harmful to users ?
As an industry we've learnt a lot about how apps siphon and sell your data. And I appreciate this probably doesn't apply to NextCloud but it can be difficult to build an API that is flexible and secure so you will get casualties.
It's obviously not a security problem or a harm when used by an open source file synchronization app, and Google is being unsophisticated with its policy here.
https://www.bleepingcomputer.com/news/security/apps-with-15m...
https://www.zdnet.com/article/phantomlance-spying-campaign-b...
https://www.welivesecurity.com/2023/05/23/android-app-breaki...
There are also examples of apps using the filesystem to try to detect rooted devices, an invasion of user privacy:
https://www.reddit.com/r/Android/comments/g6cdl6/apps_have_a...
But does the policy solve this problem? The first link is a file explorer app. In theory that app should be granted the permision by Google. They could get established and then start collecting data later. So how does the policy help?
In practice the only way it helps is by Google basically telling everyone other than big trusted orgs no, and that's not an open ecosystem.
Why not just give the user a big fat warning, even telling them that apps which request this permission have been known to steal data in the past, then let them decide for themselves?
> that's not an open ecosystem
No, it is not. Did someone claim it was?
The open ecosystem of Android is that users can choose to install apps from any source they like. Apps like Syncthing-Fork and (full-featured) Nextcloud are available from other sources including F-Droid. Google does a couple things to privilege its own store, though I think those are being mitigated due to legislation and litigation.
No, we said that's what we want it to be.
(btw, not singling out Google - IMHO Apple is bad here too. This duopoly in the smartphone space is a major PITA)
So a backup app should add support for every Android application that the user is likely to back up?
For example, without using Google'' backup you can't backup the data of other apps, such as games' progress.