Okay, this is my weak point, so I got some assistance getting this info. I may be a Linux admin, but web dev stuff is outside of my skill set. I hope the bellow information is helpful.
As for the NPM, I have the Cache Assests set to off as per the instructions I found.
POST to /login
REQ HEADERS: (Cook values hidden)
POST /login HTTP/2
Host: cloud.venohm.duckdns.org
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br, zstd
Referer: https://cloud.venohm.duckdns.org/login
Content-Type: application/x-www-form-urlencoded
Content-Length: 199
Origin: https://cloud.venohm.duckdns.org
Sec-GPC: 1
Connection: keep-alive
Cookie: oc4blc84tose=xxxx; oc_sessionPassphrase=xxxxxx; __Host-nc_sameSiteCookielax=true; __Host-nc_sameSiteCookiestrict=true
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Priority: u=0, i
Pragma: no-cache
Cache-Control: no-cache
TE: trailers
RESPONSE HEADERS:
HTTP/2 303
server: openresty
date: Sat, 28 Jun 2025 19:15:45 GMT
content-type: text/html; charset=UTF-8
content-length: 0
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-robots-tag: noindex, nofollow
x-xss-protection: 1; mode=block
referrer-policy: no-referrer
x-powered-by: PHP/8.3.22
content-security-policy: default-src 'none';base-uri 'none';manifest-src 'self';frame-ancestors 'none'
set-cookie: nc_username=deleted; expires=Thu, 01 Jan 1970 00:00:01 GMT; Max-Age=0; secure; HttpOnly
set-cookie: nc_token=deleted; expires=Thu, 01 Jan 1970 00:00:01 GMT; Max-Age=0; secure; HttpOnly
set-cookie: nc_session_id=deleted; expires=Thu, 01 Jan 1970 00:00:01 GMT; Max-Age=0; secure; HttpOnly
set-cookie: nc_username=deleted; expires=Thu, 01 Jan 1970 00:00:01 GMT; Max-Age=0; path=/; secure; HttpOnly
set-cookie: nc_token=deleted; expires=Thu, 01 Jan 1970 00:00:01 GMT; Max-Age=0; path=/; secure; HttpOnly
set-cookie: nc_session_id=deleted; expires=Thu, 01 Jan 1970 00:00:01 GMT; Max-Age=0; path=/; secure; HttpOnly
x-request-id: edhpkI0Fp7b5BR54Di9V
cache-control: no-cache, no-store, must-revalidate
feature-policy: autoplay 'none';camera 'none';fullscreen 'none';geolocation 'none';microphone 'none';payment 'none'
location: /login?direct=1&user=venohm
x-nextcloud-bruteforce-throttled: 200ms
x-served-by: cloud.venohm.duckdns.org
X-Firefox-Spdy: h2
the url goes from /login to /login?direct=1&user=USERNAME and the loop continues endlessly, no 404 errors or any 500 errors, just a 303 back to login with the added variables
repeated retries gets the website logo to load up but then redirected back to login again