It has been suggested that a WebDAV back-end would be useful (WebDAV implementations range from self-hosted to internet-scale providers). There were many reasons why remoteStorage was written as a separate protocol, not least the variations in what features various implementations of WebDAV support, and their colorful variety of bugs, which often have gone years without fixes.
However, is there a lowest common denominator of WebDAV features that could be relied on? Is there a problematic impedance mismatch?
A partial answer, for one implementation: I tested Nextcloud 34 and 35 WebDAV against what remoteStorage.js sync needs. Full report: REPORT.md. Everything is reproducible with the harness.
What you can rely on (on Nextcloud):
- Folder ETags change when anything below them changes.
- ETags match between PROPFIND, GET and PUT.
If-Match and If-None-Match work on writes.
- Depth-1 PROPFIND gives usable listings.
The mismatches:
- No CORS on stock. Preflights get 401 and no
Access-Control-* headers are sent, so browsers can’t call it at all. The WebAppPassword app fixes this for allow-listed origins. The core PR (nextcloud/server#40537) is stale and doesn’t run as written.
- No good browser connect flow. Login Flow v2 can’t be started from another origin. WebAppPassword’s popup flow works, but its tokens expire after 24 hours with no refresh. Pasting an app password works, but those can’t be limited to a folder.
- Content-Type isn’t stored. It’s guessed from the file name.
- Same-second ETag collisions. File ETags use whole-second mtimes, so two same-size writes within one second share an ETag and
If-Match misses the second one.
- Compression changes ETags. Apache appends
-gzip and nginx makes them weak, so the next If-Match after a compressed GET fails.
- Missing parents and folders. A PUT into a missing folder gets 409 instead of creating it, and a missing folder gets 404 instead of an empty listing.
So a WebDAV backend for Nextcloud is feasible with WebAppPassword, but the connect step and the ETag edge cases make it fragile.
Nextcloud is one implementation with a fairly uniform deployment, so I went the other way: fix the mismatches on the server instead of in every client. nextcloud-remotestorage is a small Nextcloud app (public APIs only, no core patches) that adds WebFinger, an OAuth consent page with scoped tokens and CORS. It corrects each mismatch above for remoteStorage requests, while files stay ordinary Nextcloud files. Unmodified remoteStorage.js syncs against it, and the api-test-suite passes 52 of 53 tests; the one failure is a false positive. Report: REPORT-app.md. Testers are welcome.
I haven’t tested other WebDAV servers, so I can’t say what’s common to all of them. Judging by Nextcloud, though, a generic WebDAV backend would have to work around server quirks like these one server at a time.