Omahub
← All plugins
F

OmaSeafile

by Felipe Mayer

Seafile in the Omarchy bar: synced libraries, live state, size on disk, server libraries, starred items and transfer notifications. It starts its own seaf-daemon and connects to the server by itself — the Seafile desktop client is optional.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
3681c2d
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
3681c2d
Reviewed
1 month ago

The plugin is a transparent Seafile integration: it talks to the local seaf-daemon over its RPC socket, stores a Seafile API token in the user config, and can start/stop the daemon and trigger a user-initiated package install if the daemon binary is missing. The deterministic scan found nothing, and I found no obfuscation, hidden persistence, or credential-stealing behavior; low rather than none reflects the broad operations (package-manager install, background daemon, stored token) rather than any detected malicious code.

  • The install button can run `yay -S --needed seafile` or `flatpak install ...` with the user's privileges; this is documented but the UI should clearly confirm before executing.
  • The API token is stored in ~/.config/omarchy/omaseafile/account.json; the code comments say mode 0600, but that permission should be verified after every write.
  • autostart defaults to true, so seaf-daemon will be launched at login; this is the advertised behavior but should remain easy to disable in settings.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/FelipeMayerDev/omaseafile --enable
System #bar #quickshell #system

OmaSeafile

Seafile in the Omarchy bar — without depending on the desktop client.

OmaSeafile

Install

omarchy plugin add https://github.com/FelipeMayerDev/omaseafile.git --enable

The only requirement is the seaf-daemon binary. If it is not on the machine, the panel offers a button that installs it (yay -S --needed seafile on Arch, which ships the daemon and seaf-cli, no GUI).

Remove

omarchy plugin remove io.github.felipemayerdev.omaseafile

That takes the widget out of the bar and deletes the plugin folder. It leaves your Seafile data alone, on purpose — removing the plugin is not a reason to drop synced files or stop the daemon. To clean up the rest yourself:

rm -rf ~/.config/omarchy/omaseafile   # the API token this plugin stored
seaf-cli stop                          # if you also want the daemon down

Your synced libraries in ~/Seafile and the Seafile packages are untouched.

The desktop client is optional

OmaSeafile talks straight to seaf-daemon's RPC socket (~/Seafile/.seafile-data/seafile.sock), the same one seaf-cli uses. So it never needs the Seafile applet running — or even installed:

  • starts and stops seaf-daemon from the switch in the panel, and brings it up automatically at login;
  • signs into the server and keeps its own API token;
  • adds and removes libraries on its own.

If you already use the desktop client, the account configured there is picked up automatically and nothing changes.

What it shows

Local — synced libraries with live state (in sync, uploading, downloading, indexing, paused, error), transfer rate, size on disk, downloads in progress with a percentage, folders inside ~/Seafile that no library syncs, and per-file errors.

Remote — libraries that exist on the server but do not sync here, with size and date. The 󰇚 button syncs one right away.

Starred — items starred on the server. If the library is already synced the click opens the local file, otherwise it opens in the browser.

Notifications when a library starts uploading or downloading, when a download finishes, and when something fails. A red dot on the bar icon marks errors; the icon pulses during a transfer.

Controls

  • Switch at the top of the panel: start/stop seaf-daemon.
  • 󰅖 on a local library: stop syncing it (two taps; the files stay on disk).
  • Click a row: open the folder/file, or the library on the server.
  • Middle click on the bar icon: refresh now.

Sign in

Server, email and password in the panel. The password is only exchanged for an API token (/api2/auth-token/) and then discarded; the token lives in ~/.config/omarchy/omaseafile/account.json with mode 0600.

Encrypted libraries still need the desktop client, for the library password.

Icon

seafile.png is the colored logo, used in the panel. seafile-mono.png is the monochrome mask, tinted at runtime with the theme color through MultiEffect — the same treatment Omarchy's Tray gives symbolic icons. In the bar the icon follows the theme; in the panel it stays colored.

Settings

interval (local poll, default 10s), remoteInterval (server calls, only while the panel is open), autostart (bring the daemon up automatically) and notifyTransfers.

CLI

bin/seafile-status works on its own in a terminal and only needs python3:

seafile-status                 # local state as json
seafile-status --sizes         # plus size on disk
seafile-status --remote        # account, server libraries, starred items
seafile-status --daemon-start | --daemon-stop
seafile-status --login         # {"server","user","password","otp"} on stdin
seafile-status --logout
seafile-status --sync <id> | --desync <id>
seafile-status --install-cmd   # command that installs seaf-daemon
seafile-status --selftest

License

MIT.