mirror of
https://github.com/fscotto/infra.git
synced 2026-10-06 23:09:51 +00:00
Hide ONLYOFFICE welcome and example endpoints
This commit is contained in:
@@ -150,6 +150,15 @@
|
|||||||
diff: false
|
diff: false
|
||||||
register: atlas_nextcloud_private_configuration
|
register: atlas_nextcloud_private_configuration
|
||||||
|
|
||||||
|
- name: Hide ONLYOFFICE welcome and example endpoints without changing editor routes
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: atlas-onlyoffice-access.conf.j2
|
||||||
|
dest: "{{ atlas_nextcloud_private_dir }}/onlyoffice-access.conf"
|
||||||
|
owner: "{{ atlas_admin_username }}"
|
||||||
|
group: "{{ atlas_admin_group }}"
|
||||||
|
mode: "0644"
|
||||||
|
register: atlas_onlyoffice_access_configuration
|
||||||
|
|
||||||
- name: Download checksum-pinned compatible application releases
|
- name: Download checksum-pinned compatible application releases
|
||||||
ansible.builtin.get_url:
|
ansible.builtin.get_url:
|
||||||
url: "{{ item.url }}"
|
url: "{{ item.url }}"
|
||||||
@@ -239,6 +248,7 @@
|
|||||||
atlas_nextcloud_quadlets.results |
|
atlas_nextcloud_quadlets.results |
|
||||||
selectattr('item', 'equalto', 'atlas-nextcloud.network') |
|
selectattr('item', 'equalto', 'atlas-nextcloud.network') |
|
||||||
selectattr('changed') | list | length > 0 or
|
selectattr('changed') | list | length > 0 or
|
||||||
|
(item == 'atlas-onlyoffice.service' and atlas_onlyoffice_access_configuration is changed) or
|
||||||
atlas_nextcloud_private_configuration is changed or
|
atlas_nextcloud_private_configuration is changed or
|
||||||
atlas_nextcloud_secret_files is changed) else 'started' }}
|
atlas_nextcloud_secret_files is changed) else 'started' }}
|
||||||
loop: "{{ atlas_nextcloud_services }}"
|
loop: "{{ atlas_nextcloud_services }}"
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
# Managed by Ansible; loaded inside the ONLYOFFICE Nginx server block.
|
||||||
|
# Return-only server rewrite rules run before the vendor welcome redirect.
|
||||||
|
if ($uri = /) {
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
if ($uri ~* "^/([0-9]+\.[0-9]+\.[0-9]+[-.][A-Za-z0-9_-]+/)?(welcome|example)(/|$)") {
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
@@ -10,6 +10,8 @@ NetworkAlias=atlas-onlyoffice
|
|||||||
PublishPort={{ ansible_host }}:{{ atlas_onlyoffice_http_port }}:80
|
PublishPort={{ ansible_host }}:{{ atlas_onlyoffice_http_port }}:80
|
||||||
PublishPort=127.0.0.1:{{ atlas_onlyoffice_http_port }}:80
|
PublishPort=127.0.0.1:{{ atlas_onlyoffice_http_port }}:80
|
||||||
EnvironmentFile={{ atlas_nextcloud_private_dir }}/onlyoffice.env
|
EnvironmentFile={{ atlas_nextcloud_private_dir }}/onlyoffice.env
|
||||||
|
Environment=EXAMPLE_ENABLED=false
|
||||||
|
Volume={{ atlas_nextcloud_private_dir }}/onlyoffice-access.conf:/etc/nginx/includes/ds-atlas-access.conf:ro,Z
|
||||||
Volume={{ atlas_nextcloud_root }}/office/data:/var/www/onlyoffice/Data:Z
|
Volume={{ atlas_nextcloud_root }}/office/data:/var/www/onlyoffice/Data:Z
|
||||||
Volume={{ atlas_nextcloud_root }}/office/lib:/var/lib/onlyoffice:Z
|
Volume={{ atlas_nextcloud_root }}/office/lib:/var/lib/onlyoffice:Z
|
||||||
Volume={{ atlas_nextcloud_root }}/office/logs:/var/log/onlyoffice:Z
|
Volume={{ atlas_nextcloud_root }}/office/logs:/var/log/onlyoffice:Z
|
||||||
|
|||||||
@@ -227,3 +227,17 @@ bind is read-only. Public Nextcloud HTTPS returned 200 and the pool was healthy.
|
|||||||
The targeted second Ansible run for mount applicability, options and discovery
|
The targeted second Ansible run for mount applicability, options and discovery
|
||||||
unit returned `changed=0`, with no failures. This is focused idempotency evidence,
|
unit returned `changed=0`, with no failures. This is focused idempotency evidence,
|
||||||
not a claim about a full Atlas playbook run.
|
not a claim about a full Atlas playbook run.
|
||||||
|
|
||||||
|
|
||||||
|
### ONLYOFFICE landing-page restriction
|
||||||
|
|
||||||
|
An Ansible-managed, read-only Nginx include inside the ONLYOFFICE container returns
|
||||||
|
404 for `/`, `/welcome` and `/example` (including their descendants and
|
||||||
|
version-prefixed variants). The vendor editor, API, conversion, callbacks and
|
||||||
|
WebSocket routes remain unchanged. `EXAMPLE_ENABLED=false` keeps the demo service
|
||||||
|
inactive. No NPM Proxy Host edits or global CSP changes are required.
|
||||||
|
|
||||||
|
On 2026-10-04 the targeted deployment restarted only ONLYOFFICE. Nginx syntax and
|
||||||
|
Nextcloud's document-server check passed. Public root, welcome and example
|
||||||
|
requests returned 404; `/healthcheck` remained 200. This check does not replace
|
||||||
|
an authenticated browser edit/save test.
|
||||||
|
|||||||
Reference in New Issue
Block a user