User guide
This guide describes Proofing Gallery for gallery owners and managers. The controls available to you can be restricted by your Nextcloud administrator.
Create a gallery
- Open Proofing Gallery and choose New project.
- Choose the purpose that matches the job: Show photos only, Deliver finished photos, Collect a selection, Review together, or Receive files.
- Enter a title, then choose from the audiences and sources that fit that job. Existing folders, new folders, and curated collections remain available where they make sense. Delivery, presentation, selection, and proofing jobs can also create private links from event folders.
- Review the source and media count before configuring delivery. A receive-files project starts with one moderated upload inbox and cannot use collections or event delivery.
For a photobooth event, choose Fotobox instead. Enter an event title, parent folder and design, then choose Create and publish. This shared gallery is public immediately, even before the first upload. Copy its gallery link and copy or download the kiosk connection configuration. Account and app password are configured separately in the kiosk. The Fotobox integration reference describes the future kiosk API contract and QR workflow.
A folder gallery references one existing folder. A collection combines files from several folder galleries without copying them. Collection sources must belong to the same owner, and collections cannot accept guest uploads.
The wizard keeps three choices separate: the project purpose describes the workflow, the gallery mode is Presentation or Proofing, and the delivery mode is Standard or Event. Event delivery is available for the delivery, showcase, selection, and proofing purposes; receive-files projects use one moderated upload inbox and do not support collections or event delivery.
Image sorting
New galleries copy the instance default sort. In Deliver → Default sort, choose filename, capture date, last modified date or file size and the direction. Use current instance default copies the current administrator setting; later changes to that setting do not change existing galleries. Collections can also use their original stored membership order. Existing collections retain that order on upgrade.
Visitors choose an order under More options → Display, saved in their browser
for that link. Use gallery default clears only their sort override. Explicit
sort and order URL parameters take priority over the saved visitor choice.
Filename order is natural and case insensitive (img2 precedes img10), across
subfolders, with file ID as the final tie breaker. Story sections retain their
authored order.
Capture dates come from XMP exif:DateTimeOriginal, then embedded EXIF, then cached
Nextcloud Photos metadata. EXIF offsets are normalized to UTC; missing offsets
are interpreted as UTC. Files without a date remain visible at the end in both
directions. Modification time is never substituted for a capture date. Dates are
indexed in bounded background batches. Pending dates may move into their final
position as indexing completes. Sorting remains available when capture dates are
hidden by the public metadata policy; capture-date cursors are encrypted.
Deliver a volume event privately
For schools, sports events, and other jobs with many recipients, keep shared photos and each participant’s photos in separate subfolders of one project folder. Choose Private links from event folders when creating the project. The project opens directly in Event delivery; there is no separate publish step.
Work through Photos, Access, Recipients, and Release. Use an existing Nextcloud folder, or choose or drop a local event folder while retaining its subfolders. Assign each folder exactly one role: everyone, group, private, or not delivered. The recipient ledger combines contact editing, exact shared/group/private scope, current link, and link history in one row per recipient. The final action publishes the hidden technical base when needed and creates the client links.
In Release, choose the download access for the delivery round: disabled, individual files, saved selections, or files plus the entire gallery. The setting applies to every shared, group, and private folder in the round, while each recipient remains restricted to their assigned folders. Existing released links are not broadened automatically when a later round uses a wider policy.
Folder names provide initial recipient names. For large lists, expand the CSV
import in the recipient step and use folder, name, email, locale, pin,
and optional groups columns. Drafts, schedules, individual links, exports,
retries, repairs, and link rotation remain in the recipient and release areas.
Email addresses are encrypted at rest.
The final Release step creates one scoped link per recipient. The link only contains the shared folders, any assigned group folders, and that recipient’s private folder. A successful release can be inspected in the ledger; failed recipients can be retried without recreating successful links.
Work through a project
The gallery workspace separates the common tasks:
- Plan shows source, status, purpose, and media summary.
- Photos manages folder content, uploads, metadata, and collections.
- Cull provides ratings, picks, rejects, color labels, saved views, and explicit XMP synchronization.
- Style controls the opener, title visibility and size, photo-count visibility, title typeface, layout, theme, logo, cover, accent, welcome text, metadata, and preview watermark. Originals are never watermarked.
- Deliver creates independently configured public links.
- Results contains feedback, client selections, exports, and upload moderation.
- History records relevant gallery activity.
Changes to gallery settings use revision checks. If another browser changed the same gallery, reload the current state instead of overwriting it blindly.
Settings are intentionally layered. Administrators define instance policies and defaults, owners configure the gallery, each public link can further restrict access, and an event release wave can restrict its own recipient links again. The most restrictive applicable policy wins; a client cannot use a capability that is disabled at an earlier layer.
When an owner uploads files whose names already exist, Proofing Gallery opens the standard Nextcloud conflict dialog before transferring them. Each incoming file can replace the existing file, be kept under a numbered name, or be skipped. Replacing creates a new file and clears the old file’s gallery review data; use Upload new version when comments and selections must stay attached.
Cull and organize photographs
The culling view is keyboard friendly. Arrow keys move between images, number keys 0–5 set ratings, P toggles pick, X toggles reject, Space selects, and Ctrl/Command+Z undoes the most recent batch. Named views store filters and sort order in your Nextcloud account. The virtualized filmstrip remains in the workspace viewport and can be placed automatically, on the right, or below; the choice follows your Nextcloud account across devices.
App culling values remain separate from XMP until you explicitly preview and apply an XMP synchronization. Concurrent changes to the source or sidecar stop the write and are reported for review.
Publish and share
Open Deliver, create a public link, and configure its audience. Each link can have its own start folder, folder depth, language, presentation, password, expiry, download scope, metadata fields, feedback, upload permission, and minimum owner rating. Proofing Gallery uses native Nextcloud public-link rules and can make instance policy stricter, never weaker.
Copy the link or send an invitation through the configured Nextcloud mail server. Leaving an existing password field empty preserves the password; use the explicit removal action to remove it. Revoking one link immediately blocks that audience without affecting other links or source files.
Client proofing and selections
Proofing mode lets guests identify themselves and, when enabled, like, rate, pick, reject, label, comment, annotate, and save named selections. Guests do not need Nextcloud accounts. Their identity and mutation token are stored in a private browser session; clearing site data ends access to private feedback.
If you are signed in to Nextcloud, new feedback uses your account identity. Earlier guest comments remain linked to their original guest identity; signing in does not claim them. Account identity does not bypass gallery or link rules. Uploads still require a guest session; signed-in reviewers can open the link in a private browser window when they need to upload files.
Feedback opens General comments, newest first beneath the input. The Pins tab groups point conversations into expandable rows. Expand a row to read its replies, or use its separate open button to show the conversation beside the pin. These panels do not dim the image. Review state shows both the configured state name and its color indicator. Each pin has its own conversation, even when two pins share the same position. Replies remain available when the original comment is deleted; its text is replaced with a deletion notice.
Zoom with the viewer controls, mouse wheel, or a touch pinch. On desktop, hold the right mouse button and drag the zoomed image to pan. A right-click without dragging keeps the browser context menu. Pins retain their image-relative positions while zooming and panning. On touchscreens, drag with one finger after zooming to reach the image edges. Dragging does not create a new pin.
Click or tap an image to place a numbered point and open its comment editor. For keyboard placement, choose Add point comment, move the point with the arrow keys, press Enter to write, or Escape to cancel. Unpinned comments remain available in Feedback. Review controls stay visible in proofing mode; the lightbox auto-hide preference applies only to presentation viewing. Explicit filmstrip visibility settings are still respected.
Client ratings and decisions stay separate from owner culling. Authorized owners can inspect aggregates and individual responses, then preview an explicit promotion. Client signals never update XMP automatically.
Selection exports can include paths, owner culling values, client aggregates, selection names, or comments. Guests can export only filenames and their own rating or decision. Review the UTF-8 CSV preview before downloading or copying it.
Review rounds and Nextcloud follow-up
Each active client link can inherit or override the gallery’s minimum, maximum, and due date for selections. Guests may save incomplete drafts, but submission enforces those rules and locks the submitted selection. The gallery owner can approve it, request changes, or reopen an approved result in the same round. This is a workflow decision, not an electronic signature or a frozen legal snapshot.
Under Results, owners see the current state and traceable round history. When the corresponding apps are available, a due date can be added to a writable Nextcloud Calendar and the review can be created as a Deck card. These resources run with the current user’s permissions; Proofing Gallery stores no credentials or public link token. Context Agent can read this status and offers an experimental read-only integration for listing galleries, inspecting their details and readiness, and searching gallery filenames. Publishing and owner decisions remain in the Proofing Gallery interface.
Downloads and guest uploads
Depending on link policy, guests can have no downloads, download individual files, download a ZIP of a saved selection, or download the complete gallery. The complete-gallery option also includes individual and selection downloads. Individual and selection downloads offer the original or metadata-free 2048 px and 1600 px JPEGs, optionally with the gallery watermark; smaller images are never enlarged. A printable contact sheet contains previews, not originals. Administrator limits bound file counts and delivery size.
Event delivery applies this policy to the whole release wave. It still keeps each recipient inside their assigned folder scope, and a later wave with a more generous policy does not change already released links.
Guest uploads are resumable and enter a hidden moderation inbox. Owners or authorized managers accept an upload with a conflict-free filename or reject it. An upload does not appear publicly before acceptance.
Metadata and XMP
Folder galleries can index a bounded set of EXIF/IPTC fields. Owners can filter
by capture date, camera, lens, keywords, or rating and edit descriptive values
in an Adobe-compatible <basename>.xmp sidecar. The original is never changed.
Public metadata starts disabled. Owners may expose selected safe fields such as capture date, camera, lens, exposure, title, or copyright. GPS, private keywords, owner ratings, and workflow labels are never disclosed publicly.
Managers, archive, and recovery
Owners may grant Nextcloud users or groups scoped gallery roles. Viewers inspect overview and activity, editors also change permitted gallery settings, and owner-level managers can publish, revoke, manage access, archive, and restore. These roles do not grant unrelated access to the owner’s Files.
Archiving disables active delivery but does not delete source files or feedback. Restore the gallery from Archive. If a source folder is missing, select a replacement owned folder; the existing link and review history are retained only after the server validates the new source.
Privacy and troubleshooting
After identifying for collaboration, use Export my data to download your own review records or Delete my data to erase them and end the guest session. Owners can export complete app records. For archived galleries they can schedule app-data deletion with a 30-day cancellation period; the source folder and original Nextcloud files are not removed.
If a link may have leaked, revoke it first and create a new one. Do not send passwords in the same channel as links. Report unexpected access behavior to your administrator and security defects through the repository’s private security-reporting form, not a public issue.
When content is missing, verify the source still exists, you can read it, the link starts in the intended folder, media matches its rating/type filters, and background jobs have completed. Administrators can inspect the system-status section without exposing guest credentials or private paths.