OpenCloud integration for admins
This guide covers installation and operation of the OpenCloud Web extension for SimpleDMS.
Supported versions
- OpenCloud: 7.2.4 and newer
- SimpleDMS: 1.17.0 and newer
Install
- Generate a strong password used only for this integration. It must satisfy OpenCloud's public-link password policy.
- Set the public OpenCloud origin and password as environment variables for SimpleDMS:
SIMPLEDMS_OPENCLOUD_ORIGIN=https://cloud.example.com
SIMPLEDMS_OPENCLOUD_PUBLIC_LINK_PASSWORD=<same-policy-compliant-password>
- Download the compiled extension
simpledms-integration.zipfrom the latest GitHub release. Do not use GitHub's automatically generated source-code archive. - Extract the ZIP into
$OC_DATA_DIR/web/assets/apps/simpledms-integration.manifest.jsonand thejs/directory must be directly inside this directory. - Add the following configuration to
$OC_CONFIG_DIR/apps.yaml. Use the same password as in SimpleDMS:
simpledms-integration:
config:
simpledmsBaseUrl: 'https://simpledms.example.com'
opencloudPublicLinkPassword: '<same-policy-compliant-password>'
- Restart SimpleDMS and OpenCloud. Recreate the SimpleDMS container if you pass the environment variables through Docker Compose. Then reload OpenCloud Web in your browser.
With opencloud-compose, place the extension in opencloud-compose/config/opencloud/apps/simpledms-integration. Its configuration belongs in opencloud-compose/config/opencloud/apps.yaml.
Admin configuration
SIMPLEDMS_OPENCLOUD_ORIGINcontains the public OpenCloud origin with its scheme, hostname, and port if needed, but without a path.simpledmsBaseUrlcontains the public SimpleDMS base URL.SIMPLEDMS_OPENCLOUD_PUBLIC_LINK_PASSWORDandopencloudPublicLinkPasswordmust match exactly.- Public links must be enabled in OpenCloud. The intended users need permission to create them.
- Both public URLs must use HTTPS. HTTP is accepted only for local loopback development, which requires SimpleDMS to run with
-dev. - The SimpleDMS backend must be able to reach the public OpenCloud origin and trust its TLS certificate.
- OpenCloud sends the application configuration to the browser. Use a dedicated integration password rather than an account password.
Verify the installation
- Sign in with a regular OpenCloud account that is allowed to create public links.
- Select a downloadable file. Export to SimpleDMS must appear in the context menu and the Actions tab.
- Start the export and complete the import in SimpleDMS.
- Confirm that the file is available in SimpleDMS and that OpenCloud removed the temporary public link.
Notes
- The extension creates a password-protected public
viewlink. SimpleDMS downloads the file through OpenCloud's public WebDAV endpoint. - The link is not a single-use token. The extension revokes it after the transfer. If revocation does not happen, the link expires at the end of the day.
- The original OpenCloud tab must remain open until the transfer finishes so the extension can revoke the link.
- The import URL does not contain the password, but it includes the share token and permission ID. Do not log or share complete import or download URLs.
- Inside a container,
localhostrefers to that container. For local installations, use an origin that the SimpleDMS backend can reach.
Troubleshooting
- Action missing: Check
simpledmsBaseUrl,opencloudPublicLinkPassword, and public-link permissions. The action appears only for one downloadable file. - Password requirements not met or HTTP 400: Use a password that satisfies OpenCloud's public-link policy in both systems.
- HTTP 401 during download: Ensure both configurations contain exactly the same password. Restart SimpleDMS after changing it.
- HTTP 403 during download: Check that OpenCloud created a downloadable
viewshare. - HTTP 404 or 410 during download: Start a new export. The link is missing, expired, or revoked.
- TLS or connection failure: Check DNS, certificate trust, and direct reachability from SimpleDMS to OpenCloud.
- Link remains after import: Keep the OpenCloud tab open and check the browser console for revocation errors. Otherwise, the link remains usable until expiration.