Hide the "Your deSEC login credentials" block during the in-flight
register/verify steps — the credentials are still shown in the dedicated
"deSEC account credentials" section once the domain is registered.
Extract the deSEC domain info/dnsmasq-caution notice into a reusable include
and also show it at the top of the initial-install flow, directly above the
"download and start containers" explanation, while keeping it in the
Community Containers section where it already appeared.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
The email input was unstyled because input[type="email"] was missing from
the text/password input rules, and the deSEC form's inline-block inputs
flowed side by side. Add the email type to the input styling rules and lay
the deSEC modal form out as a vertical stack with full-width inputs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
Move the deSEC "register a free domain" flow out of the inline containers
page form and into a modal backed by a dedicated /desec view loaded in an
iframe. The multi-step register -> verify -> domain process now re-renders
inside the modal, so the user can adjust the details and complete email
verification without reloading the whole page each step. Only once the
domain is fully registered does the view reload the parent containers page.
- add /desec route + desec.twig standalone view
- add desec-modal.js (open/close, backdrop + Escape) and desec-done.js
(parent reload on completion)
- redirect register POST to the /desec view so steps stay in the modal
- drop the redundant <details> wrapper in desec-register.twig, add heading
- style the modal and let <button class="button"> pick up button styles
- drive the modal iframe in the Playwright specs and update the QA checklist
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
Mention and recommend the built-in deSEC free domain registration across the
readme, reverse-proxy and local-instance guides, and add a deSEC step to the
new-instance QA checklist.
Co-Authored-By: szaimen <42591237+szaimen@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
desec-api-version-watch.yml is a scheduled workflow that watches the public
desec-stack "API Versions and Roadmap" table (no calls to the live deSEC API, so
it respects their ToS) and fails if it changes, prompting a review of the mock
and DesecManager against any new API version.
Co-Authored-By: szaimen <42591237+szaimen@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
- desec-mock.mjs: a dependency-free Node mock of the deSEC API endpoints the code
uses, with the real status-code semantics (202 on account creation, 403 until
verified then 200 + token, 201/409 on domain creation) plus /__control hooks to
verify and reset state.
- desec-register.spec.js / desec-existing.spec.js drive the real AIO UI through
the register -> verify -> domain flow and the existing-account login flow;
desec-helpers.js holds the shared login helper. Each scenario ends by setting a
domain, so they run as separate CI steps with a re-seed in between.
- seed-desec-mock-config.php points desec_api_base / desec_update_url at the mock
(config key only, no env override, so production is unaffected) and seeds a
known master password, since seeding configuration.json makes AIO consider
itself already installed and /setup no longer shows a generated password.
- Both Playwright workflows start the mock, mount ./community-containers so the
caddy/dnsmasq definitions enabled by the flow are present, seed the config, and
run the two deSEC specs with a re-seed between them.
Co-Authored-By: szaimen <42591237+szaimen@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
- caddy.json: pass DESEC_TOKEN to the caddy container so it can solve the DNS-01
challenge for the registered dedyn.io domain.
- community-containers.twig: when the domain was registered via deSEC, explain
that caddy and dnsmasq were enabled automatically and link the required dnsmasq
router change, with a caution to disable dnsmasq on publicly reachable hosts.
- compose.yaml: mention the built-in deSEC free domain option alongside Tailscale
in the reverse-proxy hint.
Co-Authored-By: szaimen <42591237+szaimen@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
- includes/desec-register.twig renders the multi-step deSEC flow: enter email
(optionally an existing password), the awaiting-verification step, and the
account-registered step, with friendly messaging for the ambiguous "email
already registered" case (deSEC returns 202 either way to prevent enumeration).
- containers.twig includes the deSEC section under the domain-entry UI; index.php
passes the deSEC config/state (email, password, registered/awaiting flags) to
the view.
- Move the deSEC password reveal from an inline style to a CSS class (no inline
CSS/JS in templates) and bump the style.css cache-buster to v13 in layout.twig
and log.twig.
Co-Authored-By: szaimen <42591237+szaimen@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
Add the server-side deSEC (dedyn.io) free dynamic-DNS flow so users without a
domain can obtain one from the AIO interface.
- DesecManager drives the full flow against the deSEC API, matching its real
semantics: account creation returns HTTP 202 + email verification (no token),
a token is obtained via /auth/login/ only after the email is verified, domain
registration handles 201/409, and a wildcard CNAME rrset is created for new
accounts. Existing accounts can be used by supplying a password.
- The "awaiting verification" step is derived from the stored credentials (email
+ generated password but no token and no domain yet), not a separate flag.
register() returns false for that state so the controller can re-render the
awaiting-verification UI instead of surfacing it as an error.
- DesecController exposes POST /api/desec/register; DependencyInjection wires the
manager; account credentials (email, generated password, token) are stored in
the AIO configuration and DESEC_TOKEN is exposed to the caddy container.
- The dynamic-DNS record is refreshed with the current public IP on container
start (DockerController) and via the cron path (Cron/UpdateDesecIp, cron.sh).
- Fix an undefined-variable bug in the desecToken/desecPassword config setters
that prevented credentials from being persisted.
Co-Authored-By: szaimen <42591237+szaimen@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
* Fix: prevent nginx proxy read timeout from blocking AIO container startup
When AIO runs behind an nginx reverse proxy and a user clicks Start,
image pulls produce no streaming output for minutes at a time. nginx's
proxy_read_timeout fires, drops the upstream connection, and PHP then
aborts on the next write attempt (ignore_user_abort defaults to false),
leaving all containers after the first one never started.
Two fixes:
1. startStreamingResponse(): add ignore_user_abort(true) so PHP never
terminates if the connection is already gone.
2. PullImage(): stream the Docker NDJSON pull response and write a
"Pulling image" heartbeat at most once every 5 s, keeping the nginx
connection alive. Also surfaces Docker-level stream errors that the
old buffered call silently ignored, guards against malformed
newline-free responses with a 1 MB buffer limit, and unifies the
duplicate catch-block retry logic.
Agent-Logs-Url: https://github.com/nextcloud/all-in-one/sessions/4fd13605-63fb-4693-8a95-89ccec31f7d3
Co-authored-by: szaimen <42591237+szaimen@users.noreply.github.com>
* As heartbeat send a dot regularly
Rather than repeating the message, send a "magic" dot, which gets
appended to the previous line.
Previously the heartbeats weren't sent regulary because reading the data
into a buffer caused a lag.
Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
* Remove left-over constants
Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
* Reduce timeout to stay within nginx's default timeout of 5s
Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
* Fix duplicated library namespace inclusion
Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
* Deal with preg_replace possibly returning null
Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
* update the version tag
Signed-off-by: Simon L. <szaimen@e.mail.de>
---------
Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: szaimen <42591237+szaimen@users.noreply.github.com>
Co-authored-by: Pablo Zmdl <pablo@nextcloud.com>
Co-authored-by: Simon L. <szaimen@e.mail.de>
* Add AzuraCast community container
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* Update Caddy readme to mention AzuraCast
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: consolidate storage/* volumes into single storage volume
Replace seven granular mounts under /var/azuracast/storage with a single
nextcloud_aio_azuracast_storage volume, matching AzuraCast's official
docker-compose layout. Remove nextcloud_aio_azuracast_uploads from
backup_volumes (media files are captured via stations and AzuraCast's
own backup archives in /var/azuracast/backups).
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: change HTTP/HTTPS ports to 10080/10443, expose on host
Use ports recommended by AzuraCast docs for reverse proxy deployments.
Expose port 10080 (HTTP) with %APACHE_IP_BINDING% following the vaultwarden
pattern, and port 10443 (HTTPS) on all interfaces for direct access.
Update readme accordingly.
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: replace shared volume with %NEXTCLOUD_MOUNT%, document filesystem sharing
Replace the named volume nextcloud_aio_azuracast_shared with the AIO-native
%NEXTCLOUD_MOUNT% mechanism. The volume is silently skipped if NEXTCLOUD_MOUNT
is not configured in AIO.
Update readme.md:
- Document NEXTCLOUD_MOUNT as the advanced file sharing approach, with setup
instructions and a comparison to the SFTP approach
- Clarify default access behavior: files (mode 644) are world-readable by both
processes; some AzuraCast directories (mode 700) require intervention
- Document POSIX ACL commands for unlocking read-only or bidirectional access
on specific paths, with a note that they must be re-run after structural
changes by AzuraCast
- Minor wording and formatting improvements throughout
Tested on a live AzuraCast instance: rename and bidirectional move confirmed
working after ACL application; containers start correctly without UMASK override.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* Update community-containers/azuracast/azuracast.json
Do not expose internal HTTP port 10080 on host.
Co-authored-by: Simon L. <szaimen@e.mail.de>
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: add to community containers overview diagram
Add AzuraCast entry to the Media group of the mermaid overview
diagram in community-containers/readme.md, as requested by szaimen.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* fix the json
Signed-off-by: Simon L. <szaimen@e.mail.de>
* Apply suggestion from @szaimen
Signed-off-by: Simon L. <szaimen@e.mail.de>
* Apply suggestion from @szaimen
Signed-off-by: Simon L. <szaimen@e.mail.de>
---------
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
Signed-off-by: Simon L. <szaimen@e.mail.de>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Simon L. <szaimen@e.mail.de>