How to Configure the Proxy Allowlist

Nextcloud for Outlook talks to your Nextcloud server through the Docker container you host. The add-in sends its requests to the container, and the container passes them on to Nextcloud. The proxy allowlist decides which servers the container may pass requests on to.

Without an allowlist, anyone who can reach your container could use it to send requests to any server, including servers on your internal network. We strongly recommend setting one.

The allowlist is available from Nextcloud for Outlook version 3.0.0. You set it with the PROXY_ALLOWLIST environment variable. If you have not set up the container yet, start with How to set up a Docker container (beginner).

Which servers are allowed

The container checks two environment variables when it starts:

PROXY_ALLOWLIST

DEFAULT_NEXTCLOUD_URL

Allowed servers

Set

Set or not set

Only the servers in PROXY_ALLOWLIST

Not set

Set

Only the server in DEFAULT_NEXTCLOUD_URL

Not set

Not set

Any server (not recommended)

Note: when you set PROXY_ALLOWLIST, the DEFAULT_NEXTCLOUD_URL server is not added automatically. If users sign in to that server, list it in PROXY_ALLOWLIST as well.

Set up the allowlist

1. Add the variable

Open your docker-compose.yml and add PROXY_ALLOWLIST under environment. List every Nextcloud server your users sign in to, separated by commas.

environment:
- BASE_URL=https://outlook.sendent.dev
- DEFAULT_NEXTCLOUD_URL=https://nextcloud.sendent.dev
- PROXY_ALLOWLIST=nextcloud.sendent.dev,cloud.example.org

Save and close the file. In nano: Ctrl + X, Y and hit Enter.

You can also set PROXY_ALLOWLIST in docker-config/.env. If a variable is set in both places, the value in docker-compose.yml is used.

2. Restart the container

From the same directory, run:

docker compose up -d

The change takes effect as soon as the container is running again. You do not need to update or re-upload the manifest.

3. Check the log

docker compose logs sendent.outlook

Near the top, the container prints the servers it allows and where it got them from:

PROXY_ALLOWLIST:
- nextcloud.sendent.dev
- cloud.example.org
Source: PROXY_ALLOWLIST environment variable

How to write the entries

  • Use a hostname, such as nextcloud.sendent.dev, or a full URL starting with https:// or http://. Spaces around the commas are fine.

  • Only the hostname is checked. The protocol, port and path are ignored, so nextcloud.sendent.dev allows that server on any port.

  • The hostname must match exactly. Upper and lower case do not matter.

  • Wildcards are not supported. *.sendent.dev does not match anything, and sendent.dev does not allow nextcloud.sendent.dev. List each server separately.

  • If an entry is not a valid hostname or URL, the container does not start. The log then shows Invalid URLs in PROXY_ALLOWLIST: followed by the entry.

Updating from version 2.x

Before version 3.0.0, the container passed requests on to any server. After the update, only the servers from the table above are allowed. Check your setup before you update:

  • Only one Nextcloud server, set in DEFAULT_NEXTCLOUD_URL: nothing to do.

  • Users sign in to other or more servers: add all of them to PROXY_ALLOWLIST, including the DEFAULT_NEXTCLOUD_URL server.

  • Neither variable is set: the container still works, but allows any server. Add PROXY_ALLOWLIST to close this.

Troubleshooting

  • Users see "Forbidden: Target URL is not in the allowlist" when they sign in. Their Nextcloud server is not on the allowlist. Add its hostname to PROXY_ALLOWLIST and run docker compose up -d. For every blocked request, the container log shows Proxy request rejected for hostname: followed by the hostname.

  • The default server stopped working after I set PROXY_ALLOWLIST. The DEFAULT_NEXTCLOUD_URL server is not added automatically. Add it to PROXY_ALLOWLIST as well.

  • The container does not start and the log shows "Invalid URLs in PROXY_ALLOWLIST". One of the entries is not a valid hostname or URL. Look for typos or spaces inside an entry.

  • The log shows "PROXY_ALLOWLIST: (none)". Neither PROXY_ALLOWLIST nor DEFAULT_NEXTCLOUD_URL is set, so the container allows any server. Set PROXY_ALLOWLIST.


Was this article helpful?