Help with Unauthorised WOPI host. (TrueNas Install + Remote Collabora Server)

Hello all,

New here and hoping you can help.

I have Nextcloud 30.0.3 installed on TrueNas Scale. I have recently installed Nextcloud Office (8.5.3) and set the configuration to use a demo server from Collabora for testing, prior to purchasing a subscription. The Collabora server shows sucessfully connected.

However I am getting the “Unauthorised WOPI host. Please try again later and report to your administrator if the issue persists.” error when trying to view a document.

I have browsed to the “Allow list for WOPI requests” section and entered in the standard rfc1918 address’s (192.168.0.0/16,172.16.0.0/12,10.0.0.0/8)

I know these are internal address’s, do I need to add to the allow list external IP addresses? My TrueNas server has all its trafic routed out over my VPN via Firewall rules and wonder if I need to account for this in the allow list?

It is worth noting that I access my Nextcloud instance via a HTTPS Domain and access is configured through Cloudflare Tunnels.

Any help would be greatly appreciated :slight_smile:

you must add the public IP of your Collabora server to the “Allow list for WOPI requests” (or maybe Cloudflare IPs as the request likely comes from their servers as reverse proxy)

1 Like

Thanks for your reply. I tried adding the Cloudflare Proxy IP’s as below that should cover for the fact that my sever hosting NextCloud is behind Cloudflare.

10.42.0.0/16
103.21.244.0/22
103.22.200.0/22
103.31.4.0/22
104.16.0.0/12
108.162.192.0/18
131.0.72.0/22
141.101.64.0/18
162.158.0.0/15
172.64.0.0/13
173.245.48.0/20
188.114.96.0/20
190.93.240.0/20
197.234.240.0/22
198.41.128.0/17
2400:cb00::/32
2606:4700::/32
2803:f800::/32
2405:b500::/32
2405:8100::/32
2c0f:f248::/32
2a06:98c0::/29

I also added in my VPN Public IP as well as my standard public IP for good measure.

Unfortunately I am still receiving the error. I assume I only need to add the IP address from my side that are making contact out to the WOPI endpoint? I am just making sure I am understanding the direction of communication.

Thanks,
P

After some additional research I can see that it is WOPI requests coming INTO my nextcloud server that I should be concerned with. As such, I looked at this again and entered in the CF Proxy IP’s as well as the Collabora server IP after running a DNS check on the hostname. Alas, still get the error.