• 0 Posts
  • 32 Comments
Joined 4 years ago
cake
Cake day: February 26th, 2021

help-circle



  • Yes Yes I did, sorry! Collabora CODE server configuration in Caddy.

    office.DOMAIN {
            @collabora {
                    path /browser
                    path /browser/*
                    path /hosting/discovery
                    path /hosting/capabilities
                    path /loleaflet/*
                    path /lool/*
                    path /cool/*
            }
            @local-ip {
                    remote_ip private_ranges
            }
            reverse_proxy @collabora https://nextcloud-office:9980/ {
                    transport http {
                            tls_insecure_skip_verify
                    }
            }
            reverse_proxy @local-ip nextcloud-office:9980 {
                    transport http {
                            tls_insecure_skip_verify
                    }
            }
    }
    

    Nextcloud section, may look different from yours I use the FPM image but it should be similar, enough. There are also some limitations on the urls based on local vs public access but that is an attempt at hardening rather than necessary configurations.

    nextcloud.DOMAIN {
            root * /var/www/html
    
            file_server
    
            php_fastcgi nextcloud:9000
    
            header {
                    Strict-Transport-Security max-age=31536000;
            }
    
            @phpFiles {
                    path_regexp phpfile ^/(remote|public|cron|core/ajax/update|status|ocs/v1|ocs/v2)\.php
            }
    
            rewrite @phpFiles {http.regexp.phpfile.0}
    
            redir /.well-known/carddav /remote.php/dav 301
            redir /.well-known/caldav /remote.php/dav 301
    
            @local-ip {
                    not remote_ip private_ranges
                    path /settings/admin
                    path /settings/admin/*
                    path /settings/users
                    path /settings/users/*
                    path /settings/apps
                    path /settings/apps/*
            }
            #respond @local-ip 404
    
            @forbidden {
                    path /.htaccess
                    path /data/*
                    path /config/*
                    path /db_structure
                    path /.xml
                    path /README
                    path /3rdparty/*
                    path /lib/*
                    path /templates/*
                    path /occ
                    path /console.php
            }
            respond @forbidden 404
    }
    

    Then in nextcloud you just point it to the CODE server domain above & you even have tls securing the communication layer.






  • Most cookies don’t store any data themselves. Instead it is a session/device token that tells googles servers what device is connecting and then they look up the data they have about you server side. Cookies can store more than that situationally but that is the most common use.

    To get what data Google has on you check out Google takeout and you can get a “full” export of what data has been gathered.



  • So I’ve been thinking about this a lot. Generally in places like, I dunno, the military which is under the DOD which is under the executive branch. There is instruction to disobey an illegal order from higher ups. But according to the definition of employee here & the requirement of item 7.

    I think that if the president ordered an illegal act (which he cannot be charged for from the supreme court) for the military to enact. Then as federal employees, these forms of recourse would no longer be applicable as everyone in the chain of command would be forced to use the presidents definition of legality until a court case could remove/block that authority.

    I hope that I’m missing something here but I think this gives him much more power than the rest of the order claims to be covering.


  • It is amazing! A couple years ago I played through the Metroid series (not every game original/remake counted) and it was one of my top games. It did have one issue IMO, once you get the screw attack there is an expectation that you are familiar with how to use it, which as a new player, took me a very long time to get past. But other than that I loved my time with it & didn’t have any complaints!


  • As someone in a similar environment, there are others who care. It just isn’t worth the risk to my job & professional relationships to talk about. Most people who don’t care I won’t sway anyways and anyone who does care doesn’t need to talk to me. So, for the betterment of my family, I stay quiet at work. Outside of work though I’ll talk to my friends & anyone who will listen about the risks of the current regime.