Skip to content

improve documentation for nextcloud security#572

Merged
nemchik merged 2 commits intolinuxserver:masterfrom
BlockListed:documenting_nextcloud_security
May 10, 2023
Merged

improve documentation for nextcloud security#572
nemchik merged 2 commits intolinuxserver:masterfrom
BlockListed:documenting_nextcloud_security

Conversation

@BlockListed
Copy link
Copy Markdown
Contributor

linuxserver.io


  • I have read the contributing guideline and understand that I have made the correct modifications

Description

The default configuration does not pass security checks. A change to ssl.conf is required for secure operation. This behaviour can be very confusing to new users. Documenting this should help make it easier for
new nextcloud users to have a secure experience.

Benefits of this PR and context

The default behavior was very confusing and the correct solution is very non-obvious (change ssl.conf).
A user may simply remove the proxy_hide_header directive, which will cause unintended consequences in the future.
closes #569

Source / References

#569

The default configuration does not pass security checks.
A change to ssl.conf is required for secure operation.
This behaviour can be very confusing to new users.
Documenting this should help make it easier for
new nextcloud users to have a secure experience.
@nemchik nemchik merged commit 193da49 into linuxserver:master May 10, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

[BUG] handling of nextcloud X-Frame-Options header outdated?

2 participants