Account and running it · Chapter 16
Running it: settings, backups, updates and the interface
Whoever runs nexpaper is usually the person who set it up. They invite the others, keep the server in order and make sure a broken disk does not cost the papers. The “Settings” belong to them: they stand in the menu of the round account button, for accounts with the role operator only. Everything personal stands for everybody under “My account”.
The thirteen tabs
The settings are a row of tabs. The tab is part of the address, so a link can point straight at one.
| Tab | What you do there |
|---|---|
| Accounts | invite somebody, manage accounts (see below) |
| Sign-in | at the top the card “Ready for the internet?”, below it the public address, “Require a second factor”, “Sign-in with a password” and the sign-in provider with the authentik button |
| the mail server for sending invitations, reset links and notices, with a test mail | |
| AI | whether and which service nexpaper uses for proposals, plus “Leave out personal vaults” and the daily limit |
| Storage | kinds for all vaults, rules for the whole server, “Uploading and limits”, text recognition and the card “Storage” |
| Inputs | intake folder and mailbox |
| Sharing | “Allow links to the outside”, “Valid for at most” and the overview “Open right now” |
| Web Push | contact for the push services, more push services, a new key pair |
| Backup | backups and the card “Check files” |
| Languages | add more languages as a JSON file |
| Import | the import from Paperless-ngx |
| Log | what the server did, without the content of documents |
| API | interface, “Allow API keys”, shortcut for the iPhone |
Most cards have sensible values out of the box. It gets serious in four places: signing in, backups, inputs and updating. The rest of this chapter is about them.
Managing accounts
Under “Accounts” you invite with “Invite somebody”: “Valid for” 1, 7 or 30 days, a mail address if you like and “Send the link by mail”; otherwise you copy the link with “Create invitation link” and pass it on yourself. How that works is in the chapter Inviting.
At each account “More for …” opens the tools:
- “Make operator” and “Make member”: An operator may change every setting; they do not look into the personal vaults of the others.
- “Send a link to reset”: Nobody sets a password for another person. They choose it themselves, through a link that works once and for 24 hours. Without a mail server nexpaper shows you the link once to pass on.
- “Remove second factor”: For a lost phone. The code, the passkeys and the recovery codes go, every device is signed out, and the person is told. At the next sign-in they set it up again.
- “Sign out everywhere”, “Block”, “Unblock”: A blocked account no longer gets in, open sessions end at once.
- “AI allowed”: takes the AI away from a single account.
- “Delete account”: The dialog names the number of documents in the personal vault and asks where they should go: “To another person”, “Into a shared vault” or “Delete them too, with their files”. To confirm, you type the account name. Whoever manages a vault alone cannot be deleted before somebody else has “Manage” there.
Good to knowMake a second person an operator and set up the mail server before you need it. A sole operator who forgets their password and has no mail cannot make the link for themselves. There is no command on the server for that in this version.
Setting up backups
nexpaper backs up every night out of the box. It is still worth looking once.
- Under “Backup” open the card “Backup”
Under “Automatically” it reads “Daily” out of the box, at night between three and six o'clock by the container's clock. “Weekly” and “Off” are the alternatives. Under “Keep” stands the number of backups that stay, 7 out of the box.
- Press “Back up now” once
That shows you it works: “Backup made.” The list shows every backup as “by hand”, “scheduled”, “before a change” or “uploaded”.
- “Download” one and put it somewhere else
The backups lie in
/data/backups, so on the same disk. Downloading asks for your password again. The file is not encrypted and holds the server's secret: keep it like a password. - Put the documents into your server's own backup
The card says it itself: “The documents themselves are not in the backup.” The folder
/data/dokumentebelongs in the backup your server makes anyway, such as Hyper Backup, restic or snapshots.
Checking, restoring, moving
- “Check” makes a trial run
nexpaper starts the backup's database on a copy and says whether it is whole, which version made it, how many documents it knows, which files are missing on the disk or have another checksum, and which documents of today would drop out. It also counts which blocked devices, keys and links would be valid again, because a backup does not know what you blocked afterwards.
- “Restore”
The current state is backed up first, then nexpaper restarts with the backup, and everybody signs in again. The search builds itself anew afterwards and finds more and more. nexpaper refuses a backup from a newer version: update nexpaper first, then restore. Downloading, deleting and restoring ask for your password.
- Moving to a new server
Set nexpaper up there, upload the backup with “Upload a backup”, check it, restore it and copy the folder
dokumenteacross. The database stays on a local disk.
Checking the files
Every file carries a checksum. On the same page, under “Check files”, nexpaper looks once a week whether all documents are still there and unchanged, for example after a backup of the folder was put back. With “Check now” you start it yourself. If a file is missing or no longer matches, the document carries a warning sign in the archive, in the inbox and on its page, and you get a notice. nexpaper reads in small portions with pauses, so the disk does not work all the time.
Updating
With Docker Compose: docker compose pull && docker compose up -d. Before the structure of the database changes, nexpaper makes a backup by itself (“before a change”). Whether a new version is out is shown on the page “About nexpaper”, which every person opens through the account button. The switch “Check once a day” is there too, on out of the box. If somebody opens the page and the last answer is older than a day, nexpaper asks GitHub, with nothing but the question. nexpaper never updates itself.
Log and interface
- Log: The tab shows what the server did, never the content of a document. The “Detail” is on “Normal” out of the box; “Detailed (1 hour)” and “Everything (1 hour)” switch back by themselves after an hour. You can filter, download and empty the log with “Clear”.
- API: Everything the web app can do works through
/api/v1as well. The description is at/api/v1/docs, machine readable at/api/v1/openapi.json. Programs sign in with a device or an API key. The keys are off out of the box: under “API” you switch on “Allow API keys”, and then every person makes their own under “My account”. You see all keys, never the key itself, and block single ones. Each key may make 120 requests a minute and 50 uploads an hour. - Shortcut for the iPhone: If you built a shortcut on an iPhone, you enter its iCloud link under “Shortcut for the iPhone”, and everybody sees “Load the shortcut”. How the shortcut comes about is in the chapter On the phone.
Good to knowPut a fixed version in the compose file instead of latest and update on purpose. And try the move once with a second instance before you need it: then you know that backup and documents folder fit together.