Hide ONLYOFFICE welcome and example endpoints

This commit is contained in:
Fabio Scotto di Santolo
2026-10-04 17:10:55 +02:00
parent 9f95e68190
commit bb67c406da
4 changed files with 34 additions and 0 deletions

View File

@@ -150,6 +150,15 @@
diff: false diff: false
register: atlas_nextcloud_private_configuration register: atlas_nextcloud_private_configuration
- name: Hide ONLYOFFICE welcome and example endpoints without changing editor routes
ansible.builtin.template:
src: atlas-onlyoffice-access.conf.j2
dest: "{{ atlas_nextcloud_private_dir }}/onlyoffice-access.conf"
owner: "{{ atlas_admin_username }}"
group: "{{ atlas_admin_group }}"
mode: "0644"
register: atlas_onlyoffice_access_configuration
- name: Download checksum-pinned compatible application releases - name: Download checksum-pinned compatible application releases
ansible.builtin.get_url: ansible.builtin.get_url:
url: "{{ item.url }}" url: "{{ item.url }}"
@@ -239,6 +248,7 @@
atlas_nextcloud_quadlets.results | atlas_nextcloud_quadlets.results |
selectattr('item', 'equalto', 'atlas-nextcloud.network') | selectattr('item', 'equalto', 'atlas-nextcloud.network') |
selectattr('changed') | list | length > 0 or selectattr('changed') | list | length > 0 or
(item == 'atlas-onlyoffice.service' and atlas_onlyoffice_access_configuration is changed) or
atlas_nextcloud_private_configuration is changed or atlas_nextcloud_private_configuration is changed or
atlas_nextcloud_secret_files is changed) else 'started' }} atlas_nextcloud_secret_files is changed) else 'started' }}
loop: "{{ atlas_nextcloud_services }}" loop: "{{ atlas_nextcloud_services }}"

View File

@@ -0,0 +1,8 @@
# Managed by Ansible; loaded inside the ONLYOFFICE Nginx server block.
# Return-only server rewrite rules run before the vendor welcome redirect.
if ($uri = /) {
return 404;
}
if ($uri ~* "^/([0-9]+\.[0-9]+\.[0-9]+[-.][A-Za-z0-9_-]+/)?(welcome|example)(/|$)") {
return 404;
}

View File

@@ -10,6 +10,8 @@ NetworkAlias=atlas-onlyoffice
PublishPort={{ ansible_host }}:{{ atlas_onlyoffice_http_port }}:80 PublishPort={{ ansible_host }}:{{ atlas_onlyoffice_http_port }}:80
PublishPort=127.0.0.1:{{ atlas_onlyoffice_http_port }}:80 PublishPort=127.0.0.1:{{ atlas_onlyoffice_http_port }}:80
EnvironmentFile={{ atlas_nextcloud_private_dir }}/onlyoffice.env EnvironmentFile={{ atlas_nextcloud_private_dir }}/onlyoffice.env
Environment=EXAMPLE_ENABLED=false
Volume={{ atlas_nextcloud_private_dir }}/onlyoffice-access.conf:/etc/nginx/includes/ds-atlas-access.conf:ro,Z
Volume={{ atlas_nextcloud_root }}/office/data:/var/www/onlyoffice/Data:Z Volume={{ atlas_nextcloud_root }}/office/data:/var/www/onlyoffice/Data:Z
Volume={{ atlas_nextcloud_root }}/office/lib:/var/lib/onlyoffice:Z Volume={{ atlas_nextcloud_root }}/office/lib:/var/lib/onlyoffice:Z
Volume={{ atlas_nextcloud_root }}/office/logs:/var/log/onlyoffice:Z Volume={{ atlas_nextcloud_root }}/office/logs:/var/log/onlyoffice:Z

View File

@@ -227,3 +227,17 @@ bind is read-only. Public Nextcloud HTTPS returned 200 and the pool was healthy.
The targeted second Ansible run for mount applicability, options and discovery The targeted second Ansible run for mount applicability, options and discovery
unit returned `changed=0`, with no failures. This is focused idempotency evidence, unit returned `changed=0`, with no failures. This is focused idempotency evidence,
not a claim about a full Atlas playbook run. not a claim about a full Atlas playbook run.
### ONLYOFFICE landing-page restriction
An Ansible-managed, read-only Nginx include inside the ONLYOFFICE container returns
404 for `/`, `/welcome` and `/example` (including their descendants and
version-prefixed variants). The vendor editor, API, conversion, callbacks and
WebSocket routes remain unchanged. `EXAMPLE_ENABLED=false` keeps the demo service
inactive. No NPM Proxy Host edits or global CSP changes are required.
On 2026-10-04 the targeted deployment restarted only ONLYOFFICE. Nginx syntax and
Nextcloud's document-server check passed. Public root, welcome and example
requests returned 404; `/healthcheck` remained 200. This check does not replace
an authenticated browser edit/save test.