nextcloud / nextcloud/documentation

Improve 'Hardening and security guidance' section to include ModSecurity

Open
#2,273 7 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

1. to develop enhancement feature: install and update security
Dominant language
JavaScript
Stars
628
Forks
2.5k
Avg merge
2d 11h
Merged PRs (30d)
135

Description

ModSecurity is a widely known Apache2 module that acts as a web application firewall.

Providing official guidance on how to set up modsec to work properly with Nextcloud would further enhance Nextcloud's efforts and commitments to security.

The only thorough article I could find to set up Nextcloud with ModSecurity was posted three years ago by nextcloud/nextcloudpi's maintainer nachoparker here. However, the article is based on ModSecurity v2, while v3 has been released for a while now.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the existing “Hardening and security guidance” section and read the linked nextcloudpi ModSecurity article, noting that it covers ModSecurity v2. Research the differences relevant to ModSecurity v3 and Nextcloud setup. Done means the documentation includes clear, official guidance for configuring ModSecurity with Nextcloud.

Written by the indexing model from the issue text.

Assessment

Tech stack
apache
Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.