You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|`STORAGE_DRIVER`|`azure`| The storage driver to use for file storage. |
55
+
|`AZURE_STORAGE_ACCOUNT_NAME`|| Your Azure Storage account name. |
56
+
|`AZURE_STORAGE_ACCOUNT_KEY`|| Your Azure Storage account key. |
57
+
|`AZURE_STORAGE_CONTAINER`|| The name of your blob container. |
58
+
50
59
51
60
### Storage file upload limits
52
61
@@ -109,6 +118,21 @@ The default Draw.io embed url is `https://embed.diagrams.net`.
109
118
|`TYPESENSE_API_KEY`|`your_api_key_here`| Your Typesense API key with read/write permissions. Required when `SEARCH_DRIVER=typesense`. (Enterprise) |
110
119
|`TYPESENSE_LOCALE`|`en`| The locale for text analysis and search. Default is `en`. Examples: `en`, `es`, `fr`, `de`, `ja`, `zh`, `ko`, etc. See [Typesense supported languages](https://typesense.org/docs/latest/api/search.html#supported-languages) for full list. (Enterprise) |
111
120
121
+
## Security
122
+
123
+
### Iframe embedding
124
+
125
+
By default, Docmost blocks other origins from embedding your instance in an `<iframe>`. This protects users against clickjacking attacks where a malicious site loads Docmost in a hidden frame and tricks signed-in users into clicking destructive actions. Out of the box, Docmost responds with `X-Frame-Options: SAMEORIGIN`, so only pages served from your own Docmost origin can iframe Docmost content.
126
+
127
+
Public shared pages (`/share/...`) are exempt from this restriction and can always be embedded from any origin. Shares are public, read-only content with no authenticated actions, so they have no clickjacking surface.
128
+
129
+
If you legitimately need to embed the rest of Docmost (the app itself) inside another tool, for example an intranet portal or LMS, use the variables below.
|`IFRAME_EMBED_ALLOWED`|`false`| Master switch for external iframe embedding. Defaults to `false`, which emits `X-Frame-Options: SAMEORIGIN`. Set to `true` to permit external embedding. |
134
+
|`IFRAME_ALLOWED_ORIGINS`|`https://intranet.example.com,https://portal.example.com`| Optional comma-separated allowlist. Only consulted when `IFRAME_EMBED_ALLOWED=true`. When provided, Docmost emits `Content-Security-Policy: frame-ancestors 'self' <origins>` instead of `X-Frame-Options`. When empty, embedding is allowed from any origin. |
135
+
112
136
## Telemetry
113
137
We anonymously collect the active version, user count, page count, space and workspace count.
Copy file name to clipboardExpand all lines: docs/self-hosting/installation/index.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -121,7 +121,7 @@ Replace `STRONG_DB_PASSWORD` in the `POSTGRES_PASSWORD` environment variable wit
121
121
Update the `DATABASE_URL` default `STRONG_DB_PASSWORD` value with your chosen Postgres password.
122
122
123
123
To configure Emails or File storage driver, see the [Configuration](/self-hosting/configuration) doc.
124
-
The default File storage driver is `local storage`. You don't have to do anything unless you wish to use S3 storage.
124
+
The default File storage driver is `local storage`. You don't have to do anything unless you wish to use [S3](/self-hosting/configuration#using-s3-compatible-storage) or [Azure Blob Storage](/self-hosting/configuration#using-azure-blob-storage).
0 commit comments