Skip to content

Fix SAML validation behind reverse proxy with webroot - #1236

Open
rodo6502 wants to merge 3 commits into
nextcloud:masterfrom
rodo6502:fix/saml-webroot-behind-reverse-proxy
Open

rodo6502 wants to merge 3 commits into
nextcloud:masterfrom
rodo6502:fix/saml-webroot-behind-reverse-proxy

Conversation

@rodo6502

Copy link
Copy Markdown

Description

Fix SAML response validation when Nextcloud is exposed below a non-root path behind a reverse proxy.

For example, Nextcloud may be externally available at:

https://cloud.example.com/nextcloud

while the reverse proxy forwards the SAML ACS request internally without the /nextcloud prefix:

/apps/user_saml/saml/acs

php-saml derives the current SAML endpoint URL from PHP server variables during response validation. In this setup, the externally visible Nextcloud webroot is missing from those variables, which can cause the calculated URL to differ from the Destination in the SAML response.

Solution

Configure php-saml with Nextcloud's webroot before initializing the SAML authentication handler:

Utils::setBaseURLPath(\OC::$WEBROOT);

This makes php-saml take the external path prefix into account when constructing the routed SAML endpoint URL.

Example:

Internal request:
  /apps/user_saml/saml/acs

Nextcloud webroot:
  /nextcloud

Resulting routed URL:
  https://cloud.example.com/nextcloud/apps/user_saml/saml/acs

This uses php-saml's base URL path handling instead of modifying PHP request server variables.

Testing

Added a unit test verifying that assertionConsumerService() configures php-saml with Nextcloud's webroot before initializing the SAML authentication handler.

The relevant controller test suite passes:

Tests: 20, Assertions: 63

The behavior was also verified with php-saml 4.3.2: with /nextcloud configured as the base URL path, getSelfRoutedURLNoQuery() produces the externally visible ACS URL including the /nextcloud prefix.

Related to #189

php-saml derives the current SAML endpoint URL from PHP server
variables. When Nextcloud is exposed below a path prefix behind a
reverse proxy, the external webroot may not be present in those
variables.

This causes the calculated URL to differ from the Destination in the
SAML response and can make response validation fail.

Configure php-saml with Nextcloud's webroot before initializing the
SAML authentication handler so URL validation includes the external
path prefix.

Signed-off-by: Robert Dörfler <rodo@bloerp.de>
Signed-off-by: Robert Dörfler <rodo@bloerp.de>
Signed-off-by: Robert Dörfler <rodo@bloerp.de>
@rodo6502
rodo6502 force-pushed the fix/saml-webroot-behind-reverse-proxy branch from 3a040e9 to 0007fb8 Compare September 21, 2026 17:24
@github-actions

Copy link
Copy Markdown

Hello there,
Thank you so much for taking the time and effort to create a pull request to our Nextcloud project.

We hope that the review process is going smooth and is helpful for you. We want to ensure your pull request is reviewed to your satisfaction. If you have a moment, our community management team would very much appreciate your feedback on your experience with this PR review process.

Your feedback is valuable to us as we continuously strive to improve our community developer experience. Please take a moment to complete our short survey by clicking on the following link: https://cloud.nextcloud.com/apps/forms/s/i9Ago4EQRZ7TWxjfmeEpPkf6

Thank you for contributing to Nextcloud and we hope to hear from you soon!

(If you believe you should not receive this message, you can add yourself to the blocklist.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant