Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/nextcloud/server.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2021-09-21Fix module name for PHP8+acsfer
2021-09-21Update .htaccess (PHP8 and mod_lsapi)acsfer
- Add `mod_lsapi` (Cloudlinux) authorization headers - Add `mod_php8` php_values - Reformating for better lisibilty
2021-07-07Cache images on browseracsfer
Fix #26851
2020-12-29Make sure we properly ass well-known paths to index.phpJulius Härtl
Signed-off-by: Julius Härtl <jus@bitgrid.net>
2020-12-16Add well known handlers APIChristoph Wurst
Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
2020-03-05Fix security header setting in .htaccess by adding 'onsuccess unset'zertrin
The headers might already be set by the system administrator at the http server level (apache or nginx) for some or all virtualhosts. Using "always set" in the .htaccess of Nextcloud leads to the situation where the headers might be set twice (once in the default 'onsuccess' table and once in the 'always' table)! Which leads to warnings in the admin area. Adding "onsuccess unset" solves the problem, and forces the header in the 'onsucess' table to be unset, and the header in the 'always' table to be set. NOTE: with this change, Nextcloud overrides whatever the system administrator might have already set See github issues #16893 #16476 #16938 #18017 and discussion in PR #19002 Signed-off-by: zertrin <zertrin@gmail.com>
2019-08-29+nodeinfo public serviceMaxence Lange
Signed-off-by: Maxence Lange <maxence@artificial-owl.com>
2019-08-11Remove duplicated spacesJ0WI
Signed-off-by: J0WI <J0WI@users.noreply.github.com>
2019-08-11Use "always" condition for security headersJ0WI
Signed-off-by: J0WI <J0WI@users.noreply.github.com>
2019-08-11Sort headersJ0WI
Signed-off-by: J0WI <J0WI@users.noreply.github.com>
2019-08-11Add X-Frame-Options header to .htaccessJ0WI
Signed-off-by: J0WI <J0WI@users.noreply.github.com>
2019-03-04Remove the upload and memory settingJoas Schilling
* Remove unneeded private method phpFileSize() * Bump autoloader * Remove setUploadLimit tests * Remove integrity check hacks for upload limit Signed-off-by: Joas Schilling <coding@schilljs.com> Signed-off-by: Morris Jobke <hey@morrisjobke.de>
2019-03-04Remove unused php5 config from .htaccessMorris Jobke
Signed-off-by: Morris Jobke <hey@morrisjobke.de>
2018-11-18Fix loading of .woff2 files in .htaccessJulius Härtl
Signed-off-by: Julius Härtl <jus@bitgrid.net>
2018-10-24Merge pull request #11396 from nextcloud/wellknown-webfingerMorris Jobke
adding .well-known/webfinger
2018-10-11Add "Referrer-Policy" to htaccess file, addresses issue #11099Patrik Kernstock
Signed-off-by: Patrik Kernstock <info@pkern.at>
2018-10-10adding .well-known/webfingerMaxence Lange
Signed-off-by: Maxence Lange <maxence@artificial-owl.com>
2018-03-06Merge pull request #7419 from Abijeet/feature-7175Morris Jobke
Fixes #7175 - Allow to search for email address in user management
2018-02-28Correct mistaken regex wildcard in .htaccessDan Callahan
Fixes #8578 Signed-off-by: Dan Callahan <dan.callahan@gmail.com>
2018-02-05Handle SSL certificate verifications for others than Let's EncryptRobert Scheck
Do no longer (wrongly) rewrite URLs like * http://example.net/.well-known/pki-validation/file.txt (Comodo) * http://example.net/.well-known/pki-validation/fileauth.txt (DigiCert, Thawte, GeoTrust) * http://example.net/.well-known/pki-validation/gsdv.txt (GlobalSign) * http://example.net/.well-known/pki-validation/starfield.htm (Starfield, GoDaddy) * http://example.net/.well-known/pki-validation/swisssign-check.txt (SwissSign) for automated SSL certificate verifications. All (common commercial) certificate authorities (CA) except Let's Encrypt (via ACME) seem to use "pki-validation" rather "acme-challenge" for their domain control validation (DCV). Signed-off-by: Robert Scheck <robert@fedoraproject.org>
2017-12-18Added newline to end of htaccess fileAbijeet
Signed-off-by: Abijeet <abijeetpatro@gmail.com>
2017-12-16Adds search by email function on the users screen.Abijeet
Fixes #7175. - Updated the query to fetch the users in users > everyone tab. - Updated the query to fetch the users in users > admin tab. - Tested to ensure that the disabled users are also being fetched. - Added test cases. Signed-off-by: Abijeet <abijeetpatro@gmail.com>
2017-03-26Move X-Frame-Options into PHPLukas Reschke
The public calendar view should be embeddable and we can't do that if the .htaccess sets a global X-Frame-Options. Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2017-02-04Fix for Win Clients sometimes not connectingFlole998
Fix for Win Clients sometimes not connecting
2016-11-14Cache js, css and woff files for a week (#26591)Jörn Friedrich Dreyer
increases the cache duration for css and js files from 2 hours to half a year. Should they change the versionhash changes as well and a new file is fetched. Half a year should be long enough for oc updates. Also allows caching woff files for 7 days. Currently, there is no versionhash available, but pressing F5 will also refresh the woff files.
2016-09-13Make sure memory limit is > post size and upload filesizeJoas Schilling
2016-08-08Also cache WOFF, SVG and GIFLukas Reschke
2016-06-03.htaccess update making two rules non-capturingMartin
2016-05-12Do not automatically try to enable index.php-less URLs (#24539)Lukas Reschke
The current logic for mod_rewrite relies on the fact that people have properly configured ownCloud, basically it reads from the `overwrite.cli.ur l` entry and then derives the `RewriteBase` from it. This usually works. However, since the ownCloud packages seem to install themselves at `/owncloud` (because subfolders are cool or so…) _a lot_ of people have just created a new Virtual Host for it or have simply symlinked the path etc. This means that `overwrite.cli.url` is wrong, which fails hard if it is used as RewriteBase since Apache does not know where it should serve files from. In the end the ownCloud instance will not be accessible anymore and users will be frustrated. Also some shared hosters like 1&1 (because using shared hosters is so awesome… ;-)) have somewhat dubious Apache configurations or use versions of mod_rewrite from the mediveal age. (because updating is money or so…) Anyhow. This makes this explicitly an opt-in configuration flag. If `htaccess.RewriteBase` is set then it will configure index.php-less URLs, if admins set that after installation and don't want to wait until the next ownCloud version they can run `occ maintenance:update:htaccess`. For ownCloud 9.0 we also have to add a repair step to make sure that instances that already have a RewriteBase configured continue to use it by copying it into the config file. That way all existing URLs stay valid. That one is not in this PR since this is unneccessary in master. Effectively this reduces another risk of breakage when updating from ownCloud 8 to ownCloud 9. Fixes https://github.com/owncloud/core/issues/24525, https://github.com/owncloud/core/issues/24426 and probably some more.
2016-03-17Use raw PATH_INFOLukas Reschke
PATH_INFO will be empty at this point and thus the logic in base.php did not catch this. Changing this to "getRawPathInfo" will ensure that the path info is properly read. Fixes https://github.com/owncloud/core/issues/23199
2016-03-15always_populate_raw_post_data has been removed with PHP 7.0Lukas Reschke
2016-03-15Duplicate block for PHP 7Lukas Reschke
2016-03-11Allow jpg files to be statically servedStephan Köninger
When using an background image in themes of type JPG, the current setting of owncloud's htaccess file does not allow to deliver these kinds of images as static content. Adding the file extensions as done in this commit, it works flawlessly.
2016-03-09Add base rewrite rule only when RewriteBase is definedLukas Reschke
In case Apache is configured with an `Alias` such as with the ownCloud packages the rewrite rules will fail when no valid RewriteBase is configured.
2016-02-25Exclude ocs-provider from rewrite ruleLukas Reschke
Otherwise `localhost/ocs-provider/` cannot be accessed if mod_rewrite is install ed. Only affects master.
2016-02-05Merge pull request #18194 from RealRancor/proxy_fcgiThomas Müller
Add mod_proxy_fcgi to .htaccess
2016-01-28Do not rewrite updater requestsVictor Dubiniuk
2016-01-12Add X-Download-Options and X-Permitted-Cross-Domain-PoliciesLukas Reschke
Two small security hardenings for our IE users and those with Adobe products. Aligns it more with https://github.com/twitter/secureheaders#secureheaders---
2016-01-08Remove CSP stuff from .htaccessLukas Reschke
:cry: Seems like Apache is inconsistent fun between versions. Let's remove it thus for now.
2016-01-08always check if the csp is emptyJörn Friedrich Dreyer
2016-01-08Use setifempty to please incompatible httpd versionsLukas Reschke
Some httpd versions have problem with the old logic leading to resourced served with multiple headers.
2016-01-07Merge pull request #20966 from knox/masterThomas Müller
Do not rewrite letsencrypt .well-known URI
2016-01-06Allow ico files to be served staticallyMorris Jobke
2015-12-30Merge branch 'master' into mastermbi
2015-12-11Merge pull request #20878 from ↵Thomas Müller
owncloud/proper-htaccess-support-in-code-signing-checker Also run .htaccess routine when installing on another system than Apache
2015-12-08Do not rewrite letsencrypt .well-known URImbi
2015-12-08Merge branch 'master' into mastermbi
2015-12-08Remove version check out of .htaccessLukas Reschke
This can now be achieved using the new code signing.
2015-12-08Add DirectorySlash to dynamic .htaccess writeLukas Reschke
When `DirectorySlash off` is set then Apache will not lookup folders anymore. This is required for example when we use the rewrite directives on an existing path such as `/core/search`. By default Apache would load `/core/search/` instead `/core/search` so the redirect would fail here. This leads however to the problem that URLs such as `localhost/owncloud` would not load anymore while `localhost/owncloud/` would. This has caused problems such as https://github.com/owncloud/core/pull/21015 With this change we add the `DirectorySlash off` directive only when the `.htaccess` is writable to the dynamic part of it. This would also make `localhost/owncloud` work again as it would trigger the 404 directive which triggers the redirect in base.php.
2015-12-07Allow .ico filesLukas Reschke
Makes `/core/img/favicon.ico` accessible again via web.