Earlier quoted context omitted.
What seems truly scary is how little the developer seemed to care about those security bugs (following related issues, you also find an exploit, SQL injection and so on) and being dismissive of the guy who found them.
https://github.com/haiwen/seafile/issues/587#issuecomment-40... > We don't roll our own crypto. > There are two parts of the code base in which "we roll our own crypto": the transfer protocl and encrypted library. That's just ridiculous.
About metadata : https://seacloud.cc/group/3/wiki/seafile-roadmap.md there is one line saying "Ability to encrypt all data by server key. Key has to be generated by administrator" but it's not on the changelog page ( https://seacloud.cc/group/3/wiki/Server%20ChangeLog.md )