Login as admin user into your Nextcloud and access
http://example.com/index.php/settings/integrity/failed
paste the results here.
No errors have been found.
**List of activated apps:**
If you have access to your command line run e.g.:
sudo -u www-data php occ config:list system
from within your Nextcloud installation folder
or
Insert your config.php content here
Make sure to remove all sensitive content such as passwords. (e.g. database password, passwordsalt, secret, smtp password, …)
{
"system": {
"passwordsalt": "***REMOVED SENSITIVE VALUE***",
"secret": "***REMOVED SENSITIVE VALUE***",
"trusted_domains": [
"localhost",
"***REMOVED***"
],
"trusted_proxies": "***REMOVED SENSITIVE VALUE***",
"datadirectory": "***REMOVED SENSITIVE VALUE***",
"dbtype": "mysql",
"version": "34.0.3.2",
"overwrite.cli.url": "https:\/\/***REMOVED***",
"overwriteprotocol": "https",
"htaccess.RewriteBase": "\/",
"front_controller_active": true,
"forwarded_for_headers": [
"HTTP_X_FORWARDED_FOR"
],
"dbname": "***REMOVED SENSITIVE VALUE***",
"dbhost": "***REMOVED SENSITIVE VALUE***",
"dbtableprefix": "***REMOVED***",
"mysql.utf8mb4": true,
"dbuser": "***REMOVED SENSITIVE VALUE***",
"dbpassword": "***REMOVED SENSITIVE VALUE***",
"installed": true,
"instanceid": "***REMOVED SENSITIVE VALUE***",
"mail_smtpmode": "smtp",
"mail_smtpauth": true,
"mail_sendmailmode": "smtp",
"mail_smtpname": "***REMOVED SENSITIVE VALUE***",
"mail_smtppassword": "***REMOVED SENSITIVE VALUE***",
"mail_smtpsecure": "ssl",
"mail_smtpport": "465",
"mail_from_address": "***REMOVED SENSITIVE VALUE***",
"mail_domain": "***REMOVED SENSITIVE VALUE***",
"mail_smtphost": "***REMOVED SENSITIVE VALUE***",
"memcache.local": "\\OC\\Memcache\\APCu",
"memcache.distributed": "\\OC\\Memcache\\Redis",
"memcache.locking": "\\OC\\Memcache\\Redis",
"redis": {
"host": "***REMOVED SENSITIVE VALUE***",
"port": ***REMOVED***,
"password": "***REMOVED SENSITIVE VALUE***",
"dbindex":***REMOVED***,
"timeout": 1.5
},
"maintenance": false,
"theme": "",
"loglevel": 2,
"default_phone_region": "AT",
"maintenance_window_start": ***REMOVED***,
"twofactor_enforced": "true",
"twofactor_enforced_groups": [
"admin"
],
"twofactor_enforced_excluded_groups": [],
"app_install_overwrite": [
"ak_language_switcher"
],
"objectstore": {
"class": "\\OC\\Files\\ObjectStore\\S3",
"arguments": {
"bucket": "***REMOVED***",
"autocreate": false,
"key": "***REMOVED SENSITIVE VALUE***",
"secret": "***REMOVED SENSITIVE VALUE***",
"hostname": "***REMOVED***",
"port": 443,
"use_ssl": true,
"region": "de",
"use_path_style": false
}
},
"defaultapp": "teamhub,dashboard,files",
"skeletondirectory": ""
}
}
**Are you using an external user-backend, if yes which one:** LDAP/ActiveDirectory/Webdav/...
</details>
<details>
<summary>Logs</summary>
#### Nextcloud log (data/nextcloud.log)
Insert your browser log here, this could for example include:
nothing in addition with value to insert here
</details>
How to use GitHub
Describe the bug
Restoring a deleted card via the "Undo" button fails with an
HTTP 400 Bad Request. The Vue.js frontend (Axios) fails to include the mandatoryOCS-APIRequest: trueheader in thePUTrequest, causing strict web servers/PHP to reject the payload immediately.To Reproduce
Steps to reproduce the behavior:
Expected behavior
The frontend should dispatch a
PUTrequest to/ocs/v2.php/apps/deck/api/v1.0/cards/{id}that includes theOCS-APIRequest: trueheader to pass the OCS API CSRF protection, successfully restoring the card.**Actual behaviour
The Axios client fires the
PUTrequest but entirely omits theOCS-APIRequest: trueheader. Additionally, it sends a malformed duplicate header:X-Requested-With: XMLHttpRequest, XMLHttpRequest.Because the CSRF header is missing, the Nextcloud OCS API (and strict web servers like LiteSpeed) immediately drop the request with
HTTP 400 Bad RequestandContent-Length: 0. The card remains in the trash bin.Screenshots
Client details:
Browser: Firefox 157.0 (also affects other browsers)
Operating system: Windows 10
Server details
Operating system: AlmaLinux 10
**Web server: LiteSpeed 6.3.7(b2)
Database:
**PHP version: 8.4
Nextcloud version: Nextcloud Hub 26 Spring 34.0.3
**Where did you install Nextcloud from: via Plesk Extension
Signing status:
If you have access to your command line run e.g.:
sudo -u www-data php occ app:list
from within your Nextcloud installation folder
Enabled:
Disabled:
Nextcloud configuration:
Insert your Nextcloud log here
nothing in addition with value to insert here
Browser log