// Engineering Log

File Transfer Protocols: Part 6 — WebDAV

Published on 2026-09-22

WebDAV (Web Distributed Authoring and Versioning) — an extension of the HTTP protocol that turns a web server into a network storage: files can not only be downloaded but also uploaded, renamed, moved, and locked while being edited. The main advantage of WebDAV is that it works over ordinary HTTPS, so it passes through firewalls and proxies where SMB or NFS are blocked.

How the protocol works

To the standard HTTP methods (GET, PUT, DELETE), WebDAV adds its own:

  • PROPFIND — get a file’s properties or a directory listing;
  • PROPPATCH — change properties;
  • MKCOL — create a directory (in WebDAV terms — a collection);
  • COPY and MOVE — copy and move;
  • LOCK and UNLOCK — lock a file so two users don’t overwrite each other’s changes.

A client that mounts WebDAV as a network drive constantly sends PROPFIND to show directory contents, and LOCK when an office application opens a document for writing. Therefore a server that understands only some methods will not work with most clients.

Server on Apache

In Apache, WebDAV is implemented by the mod_dav and mod_dav_fs modules. Example from the Apache documentation:

apache
DavLockDB "/usr/local/apache2/var/DavLock"

<Directory "/usr/local/apache2/htdocs/foo">
    Dav On

    AuthType Basic
    AuthName DAV
    AuthUserFile "user.passwd"

    <RequireAny>
        Require method GET POST OPTIONS
        Require user admin
    </RequireAny>
</Directory>

DavLockDB sets the lock database file — the directory must be writable by the Apache user. The documentation explicitly warns: do not enable WebDAV until the server is secured, otherwise anyone will be able to place files. Passwords for basic authentication are transmitted only over HTTPS. To protect against overload there are LimitXMLRequestBody and DavDepthInfinity (disabled by default).

Why nginx is not the best choice

The ngx_http_dav_module in nginx is not built by default and supports only PUT, DELETE, MKCOL, COPY, and MOVE. The nginx documentation notes that clients needing other WebDAV methods will not work with it. PROPFIND and LOCK are added by the third-party nginx-dav-ext-module, but that requires a separate build. For a full-featured WebDAV server it’s simpler to use Apache or a ready-made application.

Nextcloud and ready-made solutions

In practice WebDAV is most often provided together with a file cloud. Nextcloud exposes each user’s storage over WebDAV, so you can connect to it with a regular client or network drive, while Nextcloud itself handles access rights, shared folders, and the activity log. More details — in the article “Self-hosted cloud: Part 1 — File storage on Nextcloud”.

Clients

  • macOS — Finder → Connect to Server, an address like https://files.example.ru/remote.php/dav/files/user/.
  • Linux — GNOME and KDE file managers (protocols davs://), davfs2 for mounting into the system.
  • rclone — can work with WebDAV like any other storage: synchronize directories, mount, copy to S3 and back. Useful for backing up from a WebDAV store.
  • Windows — the built-in client (WebClient service, “Map network drive”) was declared deprecated by Microsoft in November 2023: the service does not start by default and is no longer being developed. On Windows it’s more reliable to use a third-party application (for example, the Nextcloud client) or rclone.

WebDAV, S3 or SMB

  • WebDAV — when you need access to files over the Internet via HTTPS, with locking and working “like a folder”, without a VPN.
  • S3 — for backups, archives, and media files that are written in whole; programmatic access is more convenient than a “network drive”.
  • SMB or NFS — for working on a local network where speed and many small files are important.

Common mistakes

  • WebDAV over HTTP without TLS. Passwords and files are sent in plain text.
  • Incomplete method support. The server accepts uploads but does not respond to PROPFIND or LOCK — clients do not show directories or cannot open documents for writing.
  • Large files through a reverse proxy. Request size limits and proxy timeouts interrupt uploads of large files; they need to be raised for the WebDAV endpoint.
  • Relying on the Windows client. The deprecated WebClient service behaves unreliably with large files and self-signed certificates; choose another client from the start.

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply