Nextcloud sharing link creates weird incorrect subdomain URL http://url5197.mydomain.com/ls/click?upn=u001

[details=“So i’ve been rocking nextcloud for years, almost same instance at least 5+ years, can’t remember from which version, maybe from 16 something :slight_smile:
→ now after 27.x > sharing link gives wrong link via email which HSTS rejects”]

So let’s say
URL = cloud.nextcloud.com for my instance
→ when I send link via nextcloud “sharing link” option → to smtp
→ I receive open link: http://url5197.mydomain.com/ls/click?upn=u001.UPGdtk4fqj9Ibbblqp7egdfXM82xRj8TcJT30eAkTEgijtObqfLlhe

What the damn url5197 subdomain is this? where could the error be?
The URL should be https://cloud.mydomain.com/anything
NOT url5197.mydomain.com/anything

What I already tried is to ease up HSTS config in apache2 and it didn’t seem to do anything… I don’t know how long this issue has persisted as I just realized it after sharing a link from 27.x Nextcloud to my friend… → started debugging → updated to 28.x and issue persists…

$grep -rl 5197 /var/www/cloud.xyz.com/ | cut -d’/’ -f1,2,3,5-
/var/www/apps/files_rightclick/appinfo/signature.json
/var/www/apps/files_pdfviewer/appinfo/signature.json
/var/www/apps/files_pdfviewer/js/pdfjs/web/compressed.tracemonkey-pldi-09.pdf
/var/www/apps/activity/appinfo/signature.json
/var/www/apps/activity/js/Activity-XWwZnDDc.mjs.map
/var/www/apps/provisioning_api/appinfo/signature.json
/var/www/apps/text/appinfo/signature.json
/var/www/apps/text/js/highlight/cal-js-js.js
/var/www/apps/text/js/vendors-node_modules_nextcloud_vue_dist_index_mjs.js.map
/var/www/apps/text/js/editor.js.map
/var/www/apps/text/js/editor.js
/var/www/apps/text/js/text-public.js.map
/var/www/apps/circles/appinfo/signature.json
/var/www/apps/sharebymail/appinfo/signature.json
/var/www/apps/contacts/js/contacts-main.js.map
/var/www/apps/files/appinfo/signature.json
/var/www/apps/privacy/appinfo/signature.json
/var/www/apps/privacy/js/privacy-vendors-node_modules_nextcloud_dialogs_dist_chunks_FilePicker-0bd54f66_mjs.js.map
/var/www/apps/viewer/js/viewer-main.js.map
/var/www/apps/federation/appinfo/signature.json
/var/www/apps/nextcloud_announcements/img/app.svg
/var/www/apps/nextcloud_announcements/img/app-dark.svg
/var/www/apps/settings/appinfo/signature.json
/var/www/apps/firstrunwizard/js/firstrunwizard-main.js.map
/var/www/apps/calendar/img/illustrations/conference_call.svg
/var/www/apps/calendar/appinfo/signature.json
/var/www/apps/password_policy/appinfo/signature.json
/var/www/apps/password_policy/js/password_policy-vendors-node_modules_nextcloud_dialogs_dist_chunks_FilePicker-cOp1W5mL_mjs.js.map
/var/www/apps/password_policy/lists/list-14.php
/var/www/apps/password_policy/lists/list-7.php
/var/www/apps/password_policy/lists/list-6.php
/var/www/apps/password_policy/lists/list-12.php
/var/www/apps/password_policy/lists/list-4.php
/var/www/apps/password_policy/lists/list-11.php
/var/www/apps/password_policy/lists/list-13.php
/var/www/apps/password_policy/lists/list-9.php
/var/www/apps/password_policy/lists/list-5.php
/var/www/apps/password_policy/lists/list-8.php
/var/www/apps/password_policy/lists/list-15.php
/var/www/apps/password_policy/lists/list-19.php
/var/www/apps/password_policy/lists/list-10.php
/var/www/apps/suspicious_login/vendor/rubix/tensor/tests/MatrixTest.php
/var/www/apps/suspicious_login/appinfo/signature.json
/var/www/apps/photos/appinfo/signature.json
/var/www/apps/photos/js/photos-public.js.map
/var/www/apps/photos/js/photos-main.js.map
/var/www/apps/contactsinteraction/appinfo/signature.json
/var/www/apps/files_external/appinfo/signature.json
/var/www/apps/notifications/js/notifications-vendors-node_modules_nextcloud_auth_dist_index_js-node_modules_nextcloud_vue_dist_Components_-304b96.js.map
/var/www/apps/encryption/appinfo/signature.json
/var/www/dist/core-common.js.map
/var/www/3rdparty/phpseclib/phpseclib/phpseclib/Crypt/Rijndael.php
/var/www/3rdparty/symfony/polyfill-intl-idn/Resources/unidata/mapped.php
/var/www/core/signature.json
/var/www/core/vendor/zxcvbn/dist/zxcvbn.js
/var/www/core/skeleton/Documents/Nextcloud flyer.pdf

Is there really “5197” in some of the files? Post examples.

I think that is just some irrelevant strings found in those files including that number. At least a few of them which I checked.

I’m not sure what I’m searching and from where?

Could this be some sort of url rewrite issue or something?

deletedmessage

Hey, I think this is some sort of sendgrid error which I use as smtp lately:
Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for url5197.mydomain.com. The certificate is only valid for the following names: *.sendgrid.net, sendgrid.net

Not yet sure how to add it to apache config.

So I figured this out, it was sendgrid ssl issue which was because of ssl link tracking which I do not need so I removed it from sendgrid settings:

This topic was automatically closed 8 days after the last reply. New replies are no longer allowed.