Skip to content

Commit 000611f

Browse files
docs: WebDAV behind nginx + diagnosis + Windows Explorer notes
Adds the nginx location block WebDAV needs (custom verbs, Authorization passthrough, unbuffered large PUTs), a curl PROPFIND to isolate server vs client, and the Windows WebClient gotchas (HTTPS, the service, BasicAuthLevel=2).
1 parent 862f8f2 commit 000611f

1 file changed

Lines changed: 47 additions & 0 deletions

File tree

‎docs/API.md‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -88,4 +88,51 @@ rclone copy ./photos ocl:Photos
8888

8989
Notes: vault (Zero-Knowledge) folders are not exposed; `COPY` (drag-duplicate) isn't implemented
9090
yet (`MOVE`/rename works); locking is accepted but advisory.
91+
92+
### Behind nginx
93+
94+
The reverse proxy must pass WebDAV's custom methods, the `Authorization` header, and large
95+
uploads through to the API. If the API is exposed under `/api`, mount WebDAV there:
96+
97+
```nginx
98+
# WebDAV needs custom verbs (PROPFIND, MKCOL, MOVE, LOCK…), auth passthrough and big bodies.
99+
location /api/ {
100+
proxy_pass http://127.0.0.1:4000/; # trailing slash strips /api → API sees /dav/
101+
proxy_set_header Host $host;
102+
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
103+
proxy_set_header X-Forwarded-Proto $scheme;
104+
proxy_set_header Authorization $http_authorization; # forward Basic creds
105+
proxy_pass_request_headers on;
106+
client_max_body_size 0; # no upload size cap at the proxy
107+
proxy_request_buffering off; # stream PUT bodies straight through
108+
proxy_buffering off;
109+
proxy_read_timeout 3600s;
110+
}
111+
```
112+
113+
The WebDAV URL is then `https://<host>/api/dav/` (exactly what the account page shows — copy it
114+
from there rather than typing it).
115+
116+
### Diagnosing a mount that won't connect
117+
118+
First prove the server side works, independent of any OS client:
119+
120+
```bash
121+
curl -u "me:ocl_YOUR_TOKEN" -X PROPFIND -H "Depth: 1" https://<host>/api/dav/
122+
```
123+
124+
- **207 Multi-Status with XML** → server + proxy are fine; the issue is the OS client (below).
125+
- **401 loop** → the token/Basic auth isn't reaching the API (check `Authorization` passthrough).
126+
- **404 / 405** → the path is wrong: the proxy isn't stripping `/api`, so the API never sees `/dav`.
127+
128+
### Windows Explorer
129+
130+
Windows' built-in WebDAV client is strict:
131+
132+
- Use **HTTPS** (you do) and make sure the **WebClient** service is running (`services.msc`).
133+
- Windows often refuses Basic auth even over HTTPS until you set, in
134+
`HKLM\SYSTEM\CurrentControlSet\Services\WebClient\Parameters`, the DWORD
135+
**`BasicAuthLevel = 2`**, then restart the WebClient service.
136+
- If it still won't map, test with **rclone**, **Cyberduck** or **WinSCP** first — if those work,
137+
it's a Windows-client limitation, not the server.
91138
</content>

0 commit comments

Comments
 (0)