Secure Check and configuration advise

Iha ve done the security check, and I have received this message.
I donā€™t know ehat to do:
I have read documentation but I think is too much for my knlowledge.
ā€¦ORIGINALā€¦

Avvisi di sicurezza e di configurazione

ƈ importante per la sicurezza e le prestazioni della tua istanza che tutto sia configurato correttamente. Per aiutarti in questo senso, stiamo eseguendo alcuni controlli automatici. Vedi la documentazione collegata per ulteriori informazioni.

Sono presenti degli avvisi relativi alla tua configurazione.

  • La configurazione delle intestazioni del proxy inverso non ĆØ corretta, o stai effettuando lā€™accesso a Nextcloud da un proxy affidabile. In caso diverso, questo ĆØ un problema di sicurezza e puĆ² consentire a un attaccante di falsificare il suo indirizzo IP, rendendolo visibile a Nextcloud. Ulteriori informazioni sono disponibili nella documentazione.

  • La tua installazione non ha una regione telefonica predefinita impostata. CiĆ² ĆØ necessario per poter convalidare i numeri di telefono nelle impostazioni del profilo senza un codice nazionale. Per consentire i numeri senza un codice nazionale, aggiungi ā€œdefault_phone_regionā€ con il rispettivo codice ISO 3166-1 :arrow_upper_right: della regione desiderata al file di configurazione.

  • Su questa istanza mancano alcuni moduli PHP consigliati. Per prestazioni migliorate e migliore compatibilitĆ , ĆØ vivamente consigliato di installarli.
    imagick

Leggi attentamente le guide dā€™installazione :arrow_upper_right:, e controlla gli errori o gli avvisi nel log.

Controlla la sicurezza del tuo Nextcloud con la nostra scansione di sicurezza :arrow_upper_right:
ā€¦ GOOGLE TRANSLATEDā€¦

Security and Configuration Alerts It is important for the security and performance of your instance that everything is configured correctly. To help you in this regard, we are running some automatic checks. See the linked documentation for more information.

There are alerts about your configuration. *

  • The reverse proxy header configuration is incorrect, or you are logging into Nextcloud from a trusted proxy. If not, this is a security issue and can allow an attacker to spoof their IP address, making it visible to Nextcloud. More information can be found in the documentation.

  • Your installation does not have a default phone region set. This is necessary in order to be able to validate phone numbers in the profile settings without a country code. To allow numbers without a country code, add ā€œdefault_phone_regionā€ with the respective ISO 3166-1 code :arrow_upper_right: of the desired region to the configuration file.

  • Some recommended PHP modules are missing from this instance. For improved performance and better compatibility, it is highly recommended to install them. ā€˜imagickā€™

Someone can helpme?

thansk in advance

Many things are just tips, not really a security concern. What kind of setup do you have? You seem to use a proxy??

Default phone region is nice to be set, so Nextcloud can guess the country prefix for phone numbers. Regarding the php modules, check out the documentation for the required modules, some are recommended, without all the recommended ones, some functions are not available.

May I complain about unclear error message - see below. It would help if you indicate the name of the config-file and where it is normally located.
I added ā€˜default_phone_regionā€™ =>ā€˜SEā€™ to /var/www/nextcloud/config/config.php and the server stopped funtioning. I got the message
ā€œInternal Server Error
The server encountered an internal error and was unable to complete your request.
Please contact the server administrator if this error reappears multiple times, please include the technical details below in your report. More details can be found in the webserver log.ā€

Which config-file should be edited? give an example.

  • Your installation has no default phone region set. This is required to validate phone numbers in the profile settings without a country code. To allow numbers without a country code, please add ā€œdefault_phone_regionā€ with the respective ISO 3166-1 code of the region to your config file.

The texts are defined here:

You can submit bug reports and even a pull request (suggested fix) directly there.

The file is the right one, maybe you made a syntax mistake? If you show us what you did we can say more about it (but please erase personal data and passwords).

Sorry. I missed to add the trailing ā€œ,ā€
added ā€˜default_phone_regionā€™ =>ā€˜SEā€™,
Now it works
Roland