@@ -88,4 +88,51 @@ rclone copy ./photos ocl:Photos
8888
8989Notes: vault (Zero-Knowledge) folders are not exposed; ` COPY ` (drag-duplicate) isn't implemented
9090yet (` MOVE ` /rename works); locking is accepted but advisory.
91+
92+ ### Behind nginx
93+
94+ The reverse proxy must pass WebDAV's custom methods, the ` Authorization ` header, and large
95+ uploads through to the API. If the API is exposed under ` /api ` , mount WebDAV there:
96+
97+ ``` nginx
98+ # WebDAV needs custom verbs (PROPFIND, MKCOL, MOVE, LOCK…), auth passthrough and big bodies.
99+ location /api/ {
100+ proxy_pass http://127.0.0.1:4000/; # trailing slash strips /api → API sees /dav/
101+ proxy_set_header Host $host;
102+ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
103+ proxy_set_header X-Forwarded-Proto $scheme;
104+ proxy_set_header Authorization $http_authorization; # forward Basic creds
105+ proxy_pass_request_headers on;
106+ client_max_body_size 0; # no upload size cap at the proxy
107+ proxy_request_buffering off; # stream PUT bodies straight through
108+ proxy_buffering off;
109+ proxy_read_timeout 3600s;
110+ }
111+ ```
112+
113+ The WebDAV URL is then ` https://<host>/api/dav/ ` (exactly what the account page shows — copy it
114+ from there rather than typing it).
115+
116+ ### Diagnosing a mount that won't connect
117+
118+ First prove the server side works, independent of any OS client:
119+
120+ ``` bash
121+ curl -u " me:ocl_YOUR_TOKEN" -X PROPFIND -H " Depth: 1" https://< host> /api/dav/
122+ ```
123+
124+ - ** 207 Multi-Status with XML** → server + proxy are fine; the issue is the OS client (below).
125+ - ** 401 loop** → the token/Basic auth isn't reaching the API (check ` Authorization ` passthrough).
126+ - ** 404 / 405** → the path is wrong: the proxy isn't stripping ` /api ` , so the API never sees ` /dav ` .
127+
128+ ### Windows Explorer
129+
130+ Windows' built-in WebDAV client is strict:
131+
132+ - Use ** HTTPS** (you do) and make sure the ** WebClient** service is running (` services.msc ` ).
133+ - Windows often refuses Basic auth even over HTTPS until you set, in
134+ ` HKLM\SYSTEM\CurrentControlSet\Services\WebClient\Parameters ` , the DWORD
135+ ** ` BasicAuthLevel = 2 ` ** , then restart the WebClient service.
136+ - If it still won't map, test with ** rclone** , ** Cyberduck** or ** WinSCP** first — if those work,
137+ it's a Windows-client limitation, not the server.
91138</content >
0 commit comments