// the find
kekingcn/kkFileView
Universal File Online Preview Project based on Spring-Boot
kkFileView is a Spring Boot service that converts and renders dozens of file formats (Office docs, CAD, 3D models, PDFs, archives, video) in the browser via LibreOffice/OpenOffice conversion under the hood. It's aimed at teams that need an in-house document preview endpoint instead of shipping raw files or relying on Office Online/Google Docs viewer.
The format coverage is genuinely unusual — CAD (dwg/dxf), 3D models (gltf, step, ifc), medical DICOM, and BPMN diagrams alongside the expected Office/PDF set — and the file-preview interface is abstracted so adding a new type doesn't mean forking the core. The maintainers are visibly responsive on security: 5.0.1/5.0.2 shipped fixes for a real SSRF (GHSA-gwwj-52hv-6g2m) and path traversal (GHSA-pmp8-g8p2-p6jq) with proper GHSA advisories, and untrusted HTML previews now run in a sandboxed opaque-origin iframe with scripts off by default. Async, multi-threaded conversion with disk caching means repeated previews of the same file don't re-run LibreOffice each time.
The changelog is a long tail of the same two vulnerability classes recurring release after release — path/directory traversal in compressed files, SSRF in host-trust filtering, XSS — which says the input validation was retrofitted rather than designed in from the start; anyone self-hosting this needs to stay current on every point release, not just deploy once. It hard-depends on a LibreOffice/OpenOffice install as an external process, which is a heavyweight, occasionally flaky conversion backend compared to a pure-library approach, and JDK 21 is a fairly steep minimum for a project many will want to drop into an older stack. Security also leans heavily on getting `trust.host` and the file blacklist config right — the SSRF/path traversal bugs were specifically filter bypasses, so a misconfigured deployment is one wrong regex away from reopening them.