Giter Site home page Giter Site logo

document-server-proxy's Introduction

ONLYOFFICE Document Server example configurations for proxy

Config Test Build Status

This reposotory contains the configuration files for the web-servers to proxy traffic to the ONLYOFFICE DocumentServer.

document-server-proxy's People

Contributors

agolybev avatar aknobloch avatar alexeybannov avatar danilapog avatar friedcircuits avatar konovalovsergey avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

document-server-proxy's Issues

Help for HAproxy virtual-path

I need the same config for HAproxy. I tried but my config do not work.

My haproxy.conf:

frontend cloud
bind *:80
mode http
acl is_oo path_beg /oo
option forwardfor header X-Real-IP
use_backend ooffice if is_oo
default_backend cloudnodes

backend cloudnodes
mode http
balance roundrobin
option forwardfor
http-request set-header X-Forwarded-Port %[dst_port]
cookie SERVERID insert indirect nocache
server own-01 1.2.3.40:80 check cookie own-01 check inter 1000 rise 1 fall 1
server own-02 1.2.3.41:80 check cookie own-02 check inter 1000 rise 1 fall 1

backend ooffice
mode http
option httpclose
option forwardfor header X-Real-IP
http-request set-header X-Forwarded-Port %[dst_port]
http-request add-header X-Forwarded-For %[src]
http-request set-header X-Client-IP %[src]
http-request set-header X-Forwarded-Proto http
http-request set-header Forwarded proto=http
http-request add-header Host %[src]
http-request add-header X-Forwarded-Host %[src]
http-request add-header X-Forwarded-Server %[src]
reqrep ^([^\ :])\ /oo(.) \1\ \2
server oo-01 1.2.3.4:80

It is working:

frontend default_port_80
mode http
bind :80
acl oo path_beg /oo
use_backend ooffice if oo
default_backend default_service

backend default_service
mode http
balance roundrobin
cookie SERVERID insert indirect nocache
server own-01 IP_ownc:80 check cookie own-01 check inter 1000 rise 1 fall 1

backend ooffice
mode http
acl existing-x-forwarded-host req.hdr(X-Forwarded-Host) -m found
http-request add-header X-Forwarded-Host %[req.hdr(Host)]/oo unless existing-x-forwarded-host
reqrep ^([^\ :])\ /oo/(.) \1\ /\2
server onlyoffice-documentserver IP_documentserver:80

ONLYOFFICE cannot be reached. Please contact admin

NextCloud and ONLYOFFICE can be used in the intranet behind a proxy, but cannot be connected to the Internet after a proxy.

I have two instances of Nextcloud on the same machine. I configured the connector of both cases to use the same settings. The configuring was successful - I saw the message with the green label:

Settings have been successfully updated (version 7.4.1.36)

However, one instance of Nextcloud opens files with ONLYOFFICE successfully whereas the other instance does not:

ONLYOFFICE cannot be reached. Please contact admin

NextCloud and ONLYOFFICE host ip:192.168.2.3
nginx ip:192.168.2.1

nextcloud config.php:

  array (
     "jwt_secret" => "xxxxxxx",
     "jwt_header" => "AuthorizationJwt",
     //'verify_peer_off' => TRUE,
  )

nginx:

upstream docservice {
  server xxx.xxx:9980;
}

map $http_host $this_host {
    "" $host;
    default $http_host;
}

map $http_x_forwarded_proto $the_scheme {
     default $http_x_forwarded_proto;
     "" $scheme;
}

map $http_x_forwarded_host $the_host {
    default $http_x_forwarded_host;
    "" $this_host;
}

map $http_upgrade $proxy_connection {
  default upgrade;
  "" close;
}

proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $proxy_connection;
proxy_set_header X-Forwarded-Host $the_host;
proxy_set_header X-Forwarded-Proto $the_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

server {
  listen 9980 ssl;
  server_name xxx.xxx;

  ssl_certificate /etc/nginx/conf.d/xxx.xxx.crt;
  ssl_certificate_key /etc/nginx/conf.d/xxx.xxx.key;

  ssl_verify_client off;

  ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";

  ssl_protocols  TLSv1 TLSv1.1 TLSv1.2;
  #ssl_session_cache  builtin:1000  shared:SSL:10m;

  ssl_prefer_server_ciphers   on;

  ## [Optional] Before enabling Strict-Transport-Security headers, ensure your server is properly configured for SSL.
  ## This directive informs the browser to always use HTTPS. For more info see:
  ## - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
  # add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
  # add_header X-Frame-Options SAMEORIGIN;
  add_header X-Content-Type-Options nosniff;

  ## [Optional] If your certficate has OCSP, enable OCSP stapling to reduce the overhead and latency of running SSL.
  ## Replace with your ssl_trusted_certificate. For more info see:
  ## - https://medium.com/devops-programming/4445f4862461
  ## - https://www.ruby-forum.com/topic/4419319
  ## - https://www.digitalocean.com/community/tutorials/how-to-configure-ocsp-stapling-on-apache-and-nginx
  # ssl_stapling on;
  # ssl_stapling_verify on;
  # ssl_trusted_certificate /etc/nginx/ssl/stapling.trusted.crt;
  # resolver 208.67.222.222 208.67.222.220 valid=300s; # Can change to your DNS resolver if desired
  # resolver_timeout 10s;

  ## [Optional] Generate a stronger DHE parameter:
  ##   cd /etc/ssl/certs
  ##   sudo openssl dhparam -out dhparam.pem 4096
  ##
  # ssl_dhparam /etc/ssl/certs/dhparam.pem;

  location / {
       proxy_pass http://192.168.2.3:9980;
       proxy_http_version 1.1;

  }
}

Nginx proxy manager

Anyone able to help with this issue?

Involves the following setup:
Nextcloud (docker).
OO Document Server (docker).
Nginx Proxy Manager (docker).

Nextcloud = https://cloud.domain.com
OO = https://office.domain.com

Visiting http://ip:port/example i am able to create a new document and edit it to my liking.
Visiting https://office.domain.com/example i am able to create a new document HOWEVER i am not able to edit it. Shows a blank screen.

The same is happening on nextcloud. Able to create document/spreadsheet, but it becomes blank/shows blank page.

I am assuming some issue with reverse proxy (using nginx proxy manager).

Thank you for all your input.

404 on nginx proxy_pass

This is my config. 10.0.0.121:3080 is my document servers ip/port.
It returns a 404 when I navigate to the url that the server is listening on and even adds the /welcome/ subdomain. This makes no sense. I have disabled all unnecessary options and even re wrote some of the parts verbatim from the example given as to rule out any errors. Any ideas? It is

This is the error given on the browser side:
Error loading this URI: Protocol error (unknownError): Could not load the source for https://office.pfaffe.me/welcome/. Error: Failed to fetch https://office.pfaffe.me/welcome/. Code 2153390067. Stack: onResponse@resource://devtools/shared/DevToolsUtils.js:544:16 onStopRequest@resource://gre/modules/NetUtil.jsm:123:17 Line: 544, column: 16

image

help for iis reverse proxy

step 1 .i have setup a nextcloud with onlyoffice docker.
step 2. i set a reverse proxy server with iis 10.
if i use local ip ,everything is fine.
but if i access from internet , nextcloud is all right (except some small problem like:
tim 20180313175054, online office documents can't open.

iis 10 config:
iis.zip

onlyoffice :
tim 20180313175424

What is backendserver-address?

I have a question about https://github.com/ONLYOFFICE/document-server-proxy/blob/master/nginx/proxy-https-to-http.conf

For me, docservice in
proxy_pass http://docservice;
is the local ip address
it looks like
proxy_pass http://xxx.xxx.xxx.xxx;

but I don't understand what should be backendserver-address in
upstream docservice {
server backendserver-address;
}

should it be the same IP adress
upstream docservice {
server xxx.xxx.xxx.xxx;
}

or docservice and backendserver-address are different?

Proxy with virtual path doesn't work

The document server's nginx conf has this settting:

#script caching protection
rewrite ^(\/web-apps\/apps\/(?!api\/).*)$ $the_scheme://$the_host/5.4.2-46/$1 redirect;

Because of above setting, a virtual path proxy will give 404

Caddy v2

Hi.
Could you please add Caddyfile example for Caddy v2 reverse proxy.

The Chinese font is selected and no Chinese is shown on the toolbar.

<img src="" />

Configuration does not account for cache invalidation on Document Server upgrades

When there's a Document Server upgrade, web browsers have to download newer versions of JavaScript files. In the .deb file that ONLYOFFICE distributes, they add a "redirect trick" in the web server (Nginx) to make sure that a request for those files will redirect to a URL that the browser has never seen before, thus ensuring that a fresh file is downloaded.

If someone doesn't use that .deb and serves directly from node.js (my case), and if they come to this repository for aid on how to configure a proxy, then they'll bump into that issue and the users will have trouble using their servers after an upgrade.

For example, this is what upstream distributes in the Nginx configuration in their .deb:

#script caching protection
rewrite ^(\/web-apps\/apps\/(?!api\/).*)$ $the_scheme://$the_host/5.4.0-21/$1 redirect;

#disable caching for api.js
location ~ ^(\/[\d]+\.[\d]+\.[\d]+[\.|-][\d]+)?\/(web-apps\/apps\/api\/documents\/api\.js)$ {
  expires -1;
  # gzip_static on;
  alias  /var/www/onlyoffice/documentserver/$2;
}

Shouldn't the proxy config in this repo account for that use case, and thus include whatever cache invalidation configs should be in place?

Loading Document and curl timeouts with NextCloud VPath solution

I was having a curl timeout on my NextCloud instance and upgraded to v7.3, updated the WS proxy settings for VPath under Apache and still had the same error.

I had to add the following line to my config RequestHeader setifempty X-Forwarded-Proto https. Along with RequestHeader setifempty X-Forwarded-Proto http. I have no clue why but this worked now as expected.

I'll open and close this issue just for having a record here.

issues setting up apache config for reverse proxy

I'm trying to set up a document server behind a apache reverse proxy and I'm really stuck. I've tried the configs that's here: https://helpcenter.onlyoffice.com/server/document/document-server-proxy.aspx but to no avail.
I'll just post my config here and maybe someone can point out what I'm doing wrong... all I'm getting when I'm accessing mysite.com/documents is the default page of nextcloud...

nextcloud is hosted on 192.168.0.100:9999 and onlyoffice is working when accessing it on 192.168.0.100:8888

help :(

<IfModule mod_ssl.c>
	<VirtualHost *:80>
		ServerName mysite.com
		ServerAdmin admin
		
		RewriteEngine On

		ProxyRequests     Off
		ProxyPreserveHost On

		ProxyPass "/" "http://127.0.0.1:9999/"
		ProxyPassReverse "/" "http://127.0.0.1:9999/"

		RewriteEngine On
		RewriteCond %{SERVER_PORT} !443
		#RewriteCond %{REQUEST_URI} !^\/login\/flow
		RewriteRule ^(/(.*))?$ https://%{HTTP_HOST}/$1 [R=301,L]
	</VirtualHost>

	<VirtualHost *:443>
		ServerName mysite.com
		ServerAdmin admin

		SSLCertificateFile /filepath/fullchain.pem
		SSLCertificateKeyFile /filepath/privkey.pem
		Include /etc/letsencrypt/options-ssl-apache.conf

		ProxyRequests     Off
		ProxyPreserveHost On

		ProxyPass "/" "http://127.0.0.1:9999/"
		ProxyPassReverse "/" "http://127.0.0.1:9999/"

		<Location /sabnzbd>
			order deny,allow
			deny from all
			allow from all
			ProxyPass http://localhost:8080/sabnzbd
			ProxyPassReverse http://localhost:8080/sabnzbd
		</Location>

		Define VPATH /documents
		Define DS_ADDRESS 192.168.0.100:8888

		<Location ${VPATH}>
			Require all granted
			SetEnvIf Host "^(.*)$" THE_HOST=$1
			RequestHeader setifempty X-Forwarded-Proto http
			RequestHeader edit X-Forwarded-Host (.*) $1${VPATH}
			ProxyAddHeaders Off
		</Location>

		ProxyPassMatch ^\${VPATH}(.*)(\/websocket)$ "ws://${DS_ADDRESS}/$1$2"
		ProxyPass ${VPATH} "http://${DS_ADDRESS}"
		ProxyPassReverse ${VPATH} "http://${DS_ADDRESS}"

	</VirtualHost>
</IfModule>

This setup makes my nextcloud instance unreachable

Hi,
someone please help me out here:
I have Ubuntu and apache, nextcloud running already via a nextcloud.conf containing this:
nextcloud.conf

Alias /nextcloud "/var/www/nextcloud/"

<Directory /var/www/nextcloud/>
  Require all granted
  AllowOverride All
  Options FollowSymLinks MultiViews

  <IfModule mod_dav.c>
    Dav off
  </IfModule>
</Directory>

But when adding this code given here into an onlyoffice.conf, I will get an "Internal Server Error" in Nextcloud, other sites are still working fine.
If I comment following lines, no error appears:

#  User daemon
#  Group daemon

Are these lines necessary? How can I go on?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.