nextcloud / nextcloud/documentation
Improve 'Hardening and security guidance' section to include ModSecurity
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 628
- Forks
- 2.5k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 135
Description
ModSecurity is a widely known Apache2 module that acts as a web application firewall.
Providing official guidance on how to set up modsec to work properly with Nextcloud would further enhance Nextcloud's efforts and commitments to security.
The only thorough article I could find to set up Nextcloud with ModSecurity was posted three years ago by nextcloud/nextcloudpi's maintainer nachoparker here. However, the article is based on ModSecurity v2, while v3 has been released for a while now.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the existing “Hardening and security guidance” section and read the linked nextcloudpi ModSecurity article, noting that it covers ModSecurity v2. Research the differences relevant to ModSecurity v3 and Nextcloud setup. Done means the documentation includes clear, official guidance for configuring ModSecurity with Nextcloud.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- apache
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100