WOPI Documentation on security is a bit unclear to me

as you didn’t ask a clear question I try to rephrase

Nextcloud docs:

Wopi settings

It is highly recommended to restrict WOPI requests to the IP addresses of the Collabora servers that are expected to request files from the Nextcloud installation. This can be done by setting the Allow list for WOPI requests option from the Office admin settings.

Similarly, it is advised to configure Collabora’s WOPI host configuration to only serve IPs from expected hosts.

state you should restrict WOPI to known host using wopi_allowlist and refer to Collabora’s WOPI host configuration to adjust security on the COOL/CODE side. where do you struggle or what is unclear?

please review the Collabora integration guide to understand the WOPI protocol and the integration