nextcloud / nextcloud/nextcloudpi
deny access to apache using public IP
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 2.9k
- Forks
- 318
- PR merge metrics
- No merged PRs in 30d
Description
I found many unsolicited access attemps even in the NC admin interface log complaining about "secure domain" failures. These were requests using the external IP as domain.
Instead of having apache listening and NC block these request, maybe apached could be configured right away to only answer requests using IPs (instead of dns domain names) if they are local IPs.
Here is an example restricting request based on the source IP, which is another thing, but maybe the same ranges can be used to bypass a "apache secure domains configuration"
https://salsa.debian.org/freedombox-team/plinth/commit/21d6174ba052e22926f05b0a6806e3fa7f83c8f1
This is like in this question (however, the actual config for the solution there is at the duplicate question):
https://serverfault.com/questions/786809/block-direct-ip-connections-to-apache-web-server
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the Apache configuration behavior described in the issue and the linked ServerFault and Debian references. Determine how direct requests using the server's external IP should be handled without breaking local access, then verify that such requests no longer reach the Nextcloud admin interface and that normal domain-based access still works.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- apache
- Domain
- infrastructure, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100