diff --git a/ansible/roles/profile_atlas/tasks/nextcloud.yml b/ansible/roles/profile_atlas/tasks/nextcloud.yml index 4bb8f84..07a7305 100644 --- a/ansible/roles/profile_atlas/tasks/nextcloud.yml +++ b/ansible/roles/profile_atlas/tasks/nextcloud.yml @@ -150,6 +150,15 @@ diff: false register: atlas_nextcloud_private_configuration + - name: Hide ONLYOFFICE welcome and example endpoints without changing editor routes + ansible.builtin.template: + src: atlas-onlyoffice-access.conf.j2 + dest: "{{ atlas_nextcloud_private_dir }}/onlyoffice-access.conf" + owner: "{{ atlas_admin_username }}" + group: "{{ atlas_admin_group }}" + mode: "0644" + register: atlas_onlyoffice_access_configuration + - name: Download checksum-pinned compatible application releases ansible.builtin.get_url: url: "{{ item.url }}" @@ -239,6 +248,7 @@ atlas_nextcloud_quadlets.results | selectattr('item', 'equalto', 'atlas-nextcloud.network') | selectattr('changed') | list | length > 0 or + (item == 'atlas-onlyoffice.service' and atlas_onlyoffice_access_configuration is changed) or atlas_nextcloud_private_configuration is changed or atlas_nextcloud_secret_files is changed) else 'started' }} loop: "{{ atlas_nextcloud_services }}" diff --git a/ansible/roles/profile_atlas/templates/atlas-onlyoffice-access.conf.j2 b/ansible/roles/profile_atlas/templates/atlas-onlyoffice-access.conf.j2 new file mode 100644 index 0000000..2bcb8fc --- /dev/null +++ b/ansible/roles/profile_atlas/templates/atlas-onlyoffice-access.conf.j2 @@ -0,0 +1,8 @@ +# Managed by Ansible; loaded inside the ONLYOFFICE Nginx server block. +# Return-only server rewrite rules run before the vendor welcome redirect. +if ($uri = /) { + return 404; +} +if ($uri ~* "^/([0-9]+\.[0-9]+\.[0-9]+[-.][A-Za-z0-9_-]+/)?(welcome|example)(/|$)") { + return 404; +} diff --git a/ansible/roles/profile_atlas/templates/atlas-onlyoffice.container.j2 b/ansible/roles/profile_atlas/templates/atlas-onlyoffice.container.j2 index fb90d17..69d4150 100644 --- a/ansible/roles/profile_atlas/templates/atlas-onlyoffice.container.j2 +++ b/ansible/roles/profile_atlas/templates/atlas-onlyoffice.container.j2 @@ -10,6 +10,8 @@ NetworkAlias=atlas-onlyoffice PublishPort={{ ansible_host }}:{{ atlas_onlyoffice_http_port }}:80 PublishPort=127.0.0.1:{{ atlas_onlyoffice_http_port }}:80 EnvironmentFile={{ atlas_nextcloud_private_dir }}/onlyoffice.env +Environment=EXAMPLE_ENABLED=false +Volume={{ atlas_nextcloud_private_dir }}/onlyoffice-access.conf:/etc/nginx/includes/ds-atlas-access.conf:ro,Z Volume={{ atlas_nextcloud_root }}/office/data:/var/www/onlyoffice/Data:Z Volume={{ atlas_nextcloud_root }}/office/lib:/var/lib/onlyoffice:Z Volume={{ atlas_nextcloud_root }}/office/logs:/var/log/onlyoffice:Z diff --git a/docs/atlas-nextcloud.md b/docs/atlas-nextcloud.md index 6aee790..bb1f4d2 100644 --- a/docs/atlas-nextcloud.md +++ b/docs/atlas-nextcloud.md @@ -227,3 +227,17 @@ bind is read-only. Public Nextcloud HTTPS returned 200 and the pool was healthy. The targeted second Ansible run for mount applicability, options and discovery unit returned `changed=0`, with no failures. This is focused idempotency evidence, not a claim about a full Atlas playbook run. + + +### ONLYOFFICE landing-page restriction + +An Ansible-managed, read-only Nginx include inside the ONLYOFFICE container returns +404 for `/`, `/welcome` and `/example` (including their descendants and +version-prefixed variants). The vendor editor, API, conversion, callbacks and +WebSocket routes remain unchanged. `EXAMPLE_ENABLED=false` keeps the demo service +inactive. No NPM Proxy Host edits or global CSP changes are required. + +On 2026-10-04 the targeted deployment restarted only ONLYOFFICE. Nginx syntax and +Nextcloud's document-server check passed. Public root, welcome and example +requests returned 404; `/healthcheck` remained 200. This check does not replace +an authenticated browser edit/save test.