# Seafile WOPI error in Collabora

**URL:** <https://forum.collaboraonline.com/t/seafile-wopi-error-in-collabora/3688>\
**Category:** Installation & Configuration\
**Created:** [May 16, 2025, 8:35pm UTC](https://forum.collaboraonline.com/t/seafile-wopi-error-in-collabora/3688 "2025-05-16T20:35:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![asem1989](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/asem1989/32/1704_2.png) [@asem1989](https://forum.collaboraonline.com/u/asem1989)\
**Post date:** [May 16, 2025, 8:35pm UTC](https://forum.collaboraonline.com/t/seafile-wopi-error-in-collabora/3688/1 "2025-05-16T20:35:25Z")

</div>

I am trying to integrate Collabora into Seafile. Everytime I try to open an Office file I get this error:

> Unauthorized WOPI host. Please try again later and report to your administrator if the issue persists.

I followed the Seafile Guid [here](https://manual.seafile.com/12.0/extension/libreoffice_online/) and the Collabora Documentations [here](https://sdk.collaboraonline.com/docs/installation/CODE_Docker_image.html) to find a way but still not working. In the Doher Log I get those errors when trying to open the office files

```auto
[websrv_poll] ERR #30: WOPI::CheckFileInfo failed for URI [https://seafile.domain.tld/api2/wopi/files/xxx?access_token=xxx&access_token_ttl=0]: 0 (Unknown) . Headers: Body: []| wsd/wopi/CheckFileInfo.cpp:103
[websrv_poll] ERR #30: Invalid URI or access denied to [https://seafile.domain.tld/api2/wopi/files/xxx?access_token=xxx&access_token_ttl=0]| wsd/wopi/CheckFileInfo.cpp:118

```

When the container starts it also reports some errors:

```auto
wsd-00001-00001 2025-05-16 20:16:04.603177 +0000 [coolwsd] ERR enterMountingNS, root mount failed: Permission denied| common/JailUtil.cpp:79
wsd-00001-00001 2025-05-16 20:16:04.603435 +0000 [coolwsd] ERR creating usernamespace for mount user failed.| wsd/COOLWSD.cpp:1229
wsd-00001-00001 2025-05-16 20:16:04.628437 +0000 [coolwsd] ERR Failed to bind-mount [/opt/cool/systemplate] -> [/opt/cool/child-roots/1-a7e2f2e1/cool_test_mount]| common/JailUtil.cpp:157
wsd-00001-00001 2025-05-16 20:16:04.628507 +0000 [coolwsd] ERR Bind-Mounting fails and will be disabled for this run. To disable permanently set mount_jail_tree config entry in coolwsd.xml to false.| common/JailUtil.cpp:454

...

kit-00035-00035 2025-05-16 20:16:25.618101 +0000 [kit_spare_001] ERR Failed to get the realpath of [/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template] (ENOENT: No such file or directory)| common/FileUtil-unix.cpp:63
kit-00035-00035 2025-05-16 20:16:25.618292 +0000 [kit_spare_001] ERR linkOrCopy: nftw() failed for '/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template'| kit/Kit.cpp:612
wsd-00001-00029 2025-05-16 20:16:25.661290 +0000 [prisoner_poll] TRC PrisonerRequestDispatcher| wsd/COOLWSD.cpp:2891
kit-00042-00042 2025-05-16 20:16:26.228852 +0000 [kit_spare_004] ERR Failed to get the realpath of [/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template] (ENOENT: No such file or directory)| common/FileUtil-unix.cpp:63
kit-00042-00042 2025-05-16 20:16:26.228989 +0000 [kit_spare_004] ERR linkOrCopy: nftw() failed for '/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template'| kit/Kit.cpp:612
kit-00041-00041 2025-05-16 20:16:26.242437 +0000 [kit_spare_003] ERR Failed to get the realpath of [/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template] (ENOENT: No such file or directory)| common/FileUtil-unix.cpp:63
kit-00041-00041 2025-05-16 20:16:26.242548 +0000 [kit_spare_003] ERR linkOrCopy: nftw() failed for '/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template'| kit/Kit.cpp:612
kit-00040-00040 2025-05-16 20:16:26.339427 +0000 [kit_spare_002] ERR Failed to get the realpath of [/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template] (ENOENT: No such file or directory)| common/FileUtil-unix.cpp:63
kit-00040-00040 2025-05-16 20:16:26.339625 +0000 [kit_spare_002] ERR linkOrCopy: nftw() failed for '/opt/cool/child-roots/1-a7e2f2e1/tmp/sharedpresets/template'| kit/Kit.cpp:612

```

Docker compose for Collabora:

```auto
services:
  seafile-collabora:
    image: collabora/code
    container_name: seafile-collabora
    restart: unless-stopped
    networks:
      - public
    cap_add:
     - MKNOD
    privileged: true
    tty: true
    security_opt:
      - seccomp:unconfined
    env_file: ./seafile-collabora.env
networks:
  public:
    external: true

```

content of `.env`

```auto
username=user
password=pass
domain=seafile\\.domain\\.tld
server_name=documentserver.domain.tld
aliasgroup1=https://.*:443
dictionaries=de_DE en_GB en_US es_ES
extra_params=--o:ssl.enable=false --o:ssl.termination=true --o:wopi.host=seafile.domain.tld

```

Added this to `seahub_settings.py`

```auto
OFFICE_SERVER_TYPE = 'CollaboraOffice'
ENABLE_ONLYOFFICE = False
ENABLE_OFFICE_WEB_APP = True
OFFICE_WEB_APP_BASE_URL = 'https://documentserver.domain.tld/hosting/discovery'
WOPI_ACCESS_TOKEN_EXPIRATION = 30 * 60
OFFICE_WEB_APP_FILE_EXTENSION = ('odp', 'ods', 'odt', 'xls', 'xlsb', 'xlsm', 'xlsx','ppsx', 'ppt', 'pptm', 'pptx', 'doc', 'docm', 'docx')
ENABLE_OFFICE_WEB_APP_EDIT = True
OFFICE_WEB_APP_EDIT_FILE_EXTENSION = ('odp', 'ods', 'odt', 'xls', 'xlsb', 'xlsm', 'xlsx','ppsx', 'ppt', 'pptm', 'pptx', 'doc', 'docm', 'docx')

```

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [May 20, 2025, 7:15am UTC](https://forum.collaboraonline.com/t/seafile-wopi-error-in-collabora/3688/2 "2025-05-20T07:15:59Z")

</div>

hii @asem1989 welcome to collabora online forum

### Integration Debug Checklist for Collabora + Seafile

#### 1. **Ensure `wopi.host` matches Seafile domain**

- Set `--o:wopi.host=seafile.domain.tld` exactly.
- If Seafile redirects internally to another domain or uses a proxy, use **that** host instead.

#### 2. **Set correct `aliasgroup1`**

- Avoid wildcards like `https://.*:443`. Instead, use:

- You can also explicitly pass via:

#### 3. **Disable sandboxing if needed**

- If you’re seeing:

#### 4. **Verify Collabora → Seafile connectivity**

- Inside the container, test DNS and HTTPS access:

#### 5. **Check Seafile logs for WOPI errors**

- It’s possible Seafile is **rejecting or misrouting WOPI requests**.

- Look in Seafile’s logs (usually in `seahub.log` or `gunicorn.log`) for issues like:

- Confirm that Seafile is **actually serving WOPI endpoints** at `/api2/wopi/...`

#### 6. **Check Seafile `seahub_settings.py`**

- Ensure all required settings are in place and correct, especially:

#### 7. **Check for proxy issues**

- If using Nginx, Apache, or Traefik in front of Seafile or Collabora, ensure:

Please check few topics from this forum which is realted to seafile issue. There might be already present solution that can help you with this

Thanks  
Darshan

---

<div class="post-metadata">

**Author:** ![asem1989](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/asem1989/32/1704_2.png) [@asem1989](https://forum.collaboraonline.com/u/asem1989)\
**Post date:** [May 20, 2025, 1:22pm UTC](https://forum.collaboraonline.com/t/seafile-wopi-error-in-collabora/3688/3 "2025-05-20T13:22:45Z")

</div>

Adding `--o:wopi.host=seafile.domain.tld` changed the type of message I get trying to open an office file:

> Failed to establish socket connection or socket connection closed unexpectedly. The reverse proxy might be misconfigured, please contact the administrator. For more info on proxy configuration please checkout [Proxy settings — SDK https://sdk.collaboraonline.com/ documentation](https://sdk.collaboraonline.com/docs/installation/Proxy_settings.html)

I am running Collabora behind NginX Proxy Manager. I tried the collowing custom configurations but it did not work:

```auto
# static files
location ^~ /browser {
  proxy_pass $forward_scheme://$server:$port;
  proxy_set_header Host $http_host;
}

# WOPI discovery URL
location ^~ /hosting/discovery {
  proxy_pass $forward_scheme://$server:$port;
  proxy_set_header Host $http_host;
}

# Capabilities
location ^~ /hosting/capabilities {
  proxy_pass $forward_scheme://$server:$port;
  proxy_set_header Host $http_host;

 }
# main websocket
location ~ ^/cool/(.*)/ws$ {
  proxy_pass $forward_scheme://$server:$port;
  proxy_set_header Upgrade $http_upgrade;
  proxy_set_header Connection "Upgrade";
  proxy_set_header Host $http_host;
  proxy_read_timeout 36000s;
}

# download, presentation and image upload
location ~ ^/(c|l)ool {
  proxy_pass $forward_scheme://$server:$port;
  proxy_set_header Host $http_host;
}

# Admin Console websocket
location ^~ /cool/adminws {
  proxy_pass $forward_scheme://$server:$port;
  proxy_set_header Upgrade $http_upgrade;
  proxy_set_header Connection "Upgrade";
  proxy_set_header Host $http_host;
  proxy_read_timeout 36000s;
}

```

The Docker log for Collabora container has this error:

> ERR #31: Rejecting WebSocket upgrade with: origin [[https://documentserver.domain.tld](https://documentserver.domain.tld)] expected [[https://documentserver.domain.tld:443](https://documentserver.domain.tld:443)] instead| net/WebSocketHandler.hpp:1035

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [May 20, 2025, 1:50pm UTC](https://forum.collaboraonline.com/t/seafile-wopi-error-in-collabora/3688/4 "2025-05-20T13:50:36Z")

</div>

This means:

- Collabora **expects the origin to include the port** (e.g., `:443`), but the request only sent the **host without the port**.

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [May 20, 2025, 3:23pm UTC](https://forum.collaboraonline.com/t/seafile-wopi-error-in-collabora/3688/5 "2025-05-20T15:23:36Z")

</div>


