How to configure the proxy allowlist
Nextcloud for MS Teams talks to your Nextcloud server through the Docker container you host. The add-in sends its requests to the container, and the container passes them on to Nextcloud. The proxy allowlist decides which servers the container may pass requests on to.
Without an allowlist, anyone who can reach your container could use it to send requests to any server, including servers on your internal network. We strongly recommend setting one.
The allowlist is available from Nextcloud for MS Teams version 3.0.0. You set it with the PROXY_ALLOWLIST environment variable. If you have not set up the container yet, start with How to set up a Docker container (beginner).
Which servers are allowed
The container checks two environment variables when it starts:
|
| Allowed servers |
|---|---|---|
Set | Set or not set | Only the servers in |
Not set | Set | Only the server in |
Not set | Not set | Any server (not recommended) |
Note: when you set PROXY_ALLOWLIST, the DEFAULT_NEXTCLOUD_URL server is not added automatically. If users sign in to that server, list it in PROXY_ALLOWLIST as well.
Set up the allowlist
1. Add the variable
Open your docker-compose.yml and add PROXY_ALLOWLIST under environment. List every Nextcloud server your users sign in to, separated by commas.
environment: - BASE_URL=https://msteams.sendent.dev - DEFAULT_NEXTCLOUD_URL=https://nextcloud.sendent.dev - PROXY_ALLOWLIST=nextcloud.sendent.dev,cloud.example.org
Save and close the file. In nano: Ctrl + X, Y and hit Enter.
You can also set PROXY_ALLOWLIST in docker-config/.env. If a variable is set in both places, the value in docker-compose.yml is used.
2. Restart the container
From the same directory, run:
docker compose up -d
The change takes effect as soon as the container is running again. You do not need to upload a new app package.
3. Check the log
docker compose logs sendent.msteams
Near the top, the container prints the servers it allows and where it got them from:
PROXY_ALLOWLIST: - nextcloud.sendent.dev - cloud.example.orgSource: PROXY_ALLOWLIST environment variable
How to write the entries
Use a hostname, such as
nextcloud.sendent.dev, or a full URL starting withhttps://orhttp://. Spaces around the commas are fine.Only the hostname is checked. The protocol, port and path are ignored, so
nextcloud.sendent.devallows that server on any port.The hostname must match exactly. Upper and lower case do not matter.
Wildcards are not supported.
*.sendent.devdoes not match anything, andsendent.devdoes not allownextcloud.sendent.dev. List each server separately.If an entry is not a valid hostname or URL, the container does not start. The log then shows
Invalid URLs in PROXY_ALLOWLIST:followed by the entry.
Updating from version 2.x
Before version 3.0.0, the container passed requests on to any server. After the update, only the servers from the table above are allowed. Check your setup before you update:
Only one Nextcloud server, set in
DEFAULT_NEXTCLOUD_URL: nothing to do.Users sign in to other or more servers: add all of them to
PROXY_ALLOWLIST, including theDEFAULT_NEXTCLOUD_URLserver.Neither variable is set: the container still works, but allows any server. Add
PROXY_ALLOWLISTto close this.
Troubleshooting
The default server stopped working after I set
PROXY_ALLOWLIST. TheDEFAULT_NEXTCLOUD_URLserver is not added automatically. Add it toPROXY_ALLOWLISTas well.The container does not start and the log shows "Invalid URLs in PROXY_ALLOWLIST". One of the entries is not a valid hostname or URL. Look for typos or spaces inside an entry.
The log shows "PROXY_ALLOWLIST: (none)". Neither
PROXY_ALLOWLISTnorDEFAULT_NEXTCLOUD_URLis set, so the container allows any server. SetPROXY_ALLOWLIST.