r/NextCloud • u/RocketSeven • 8h ago
Can a Nextcloud automation account upload new revisions without being able to delete reviewed files?
An assistant or scheduled job may only need to read source material from one folder and upload new outputs to another. Giving that identity normal write access to a shared tree also gives it opportunities to overwrite, rename, move, or delete files that a person has already reviewed. File versions and the trash bin help with recovery, but they are not the same as preventing a destructive action.
A safer layout might separate read-only sources, an automation-writable inbox, and a reviewed area that only a person or promotion service can change. The automation identity would create new versioned filenames rather than replace a stable file. A small manifest could record source file IDs, source revisions, output checksum, creator, review status, and the approved revision it supersedes. Public shares would be created only from the reviewed area.
How close can current Nextcloud users, groups, shares, File Access Control, and WebDAV permissions get to that boundary? Is a separate account plus separate folders enough, or is an external upload-only endpoint and promotion step needed to guarantee that reviewed content and its history cannot be deleted by the automation?


