git: ece21dfa4242 - 2026Q3 - www/onlyoffice-documentserver: Fix local.json, update securelink handling

From: Mikael Urankar <mikael_at_FreeBSD.org>
Date: Tue, 14 Jul 2026 09:28:39 UTC
The branch 2026Q3 has been updated by mikael:

URL: https://cgit.FreeBSD.org/ports/commit/?id=ece21dfa4242f8401d1343b12a3123aa83719be6

commit ece21dfa4242f8401d1343b12a3123aa83719be6
Author:     Matt Kempe <fsbruva@yahoo.com>
AuthorDate: 2026-07-11 19:33:08 +0000
Commit:     Mikael Urankar <mikael@FreeBSD.org>
CommitDate: 2026-07-14 09:28:23 +0000

    www/onlyoffice-documentserver: Fix local.json, update securelink handling
    
    - Fix invalid JSON in local.json.sample
    - Add storage.fs.secretString override to local.json.sample
    - Update documentserver-update-securelink.sh to synchronize both
      ds.conf and ds-ssl.conf
    - Update packaged Node runtime to 24.18.0
    
    PR:             296567
    (cherry picked from commit c534cc41965a350c3849cf78fe63c6a98aeb09c0)
---
 www/onlyoffice-documentserver/Makefile             |  5 +--
 www/onlyoffice-documentserver/distinfo             | 10 +++---
 .../files/local.json.sample                        | 19 ++++-------
 .../files/patch-build__tools_scripts_base.py       | 35 +++++++++++++++++---
 ...atch-build__tools_scripts_develop_dependence.py | 25 ++++++++++++++
 ...arty_v8__89_v8_tools_gen-postmortem-metadata.py | 38 ++++++++++++++++++++++
 ...rver_bin_documentserver-update-securelink.sh.m4 | 14 +++++---
 www/onlyoffice-documentserver/files/pkg-message.in | 18 ++++++++--
 8 files changed, 133 insertions(+), 31 deletions(-)

diff --git a/www/onlyoffice-documentserver/Makefile b/www/onlyoffice-documentserver/Makefile
index a7eb15024ce5..7a361838bc0c 100644
--- a/www/onlyoffice-documentserver/Makefile
+++ b/www/onlyoffice-documentserver/Makefile
@@ -1,6 +1,7 @@
 PORTNAME=	onlyoffice-documentserver
 DISTVERSIONPREFIX=	v
 DISTVERSION=	9.4.0
+PORTREVISION=	1
 CATEGORIES=	www
 MASTER_SITES+=	LOCAL/mikael/v8/:source1 \
 		https://nodejs.org/dist/v${_PKGFETCH_NODE_VERSION}/:source2 \
@@ -22,8 +23,8 @@ ONLY_FOR_ARCHS_REASON=	Upstream only supports amd64 and arm64
 # node version used with "npm install" inside ${WRKSRC}/yao-pkg
 # kept in sync with patch-build__tools_scripts_build__server.py and patch-document-server-package_Makefile
 _DS_BUILD=		129
-_PKGFETCH_NODE_VERSION=	24.15.0
-_NPM_CACHE_TAG=		${_DS_TAGNAME}-202606140107
+_PKGFETCH_NODE_VERSION=	24.18.0
+_NPM_CACHE_TAG=		${_DS_TAGNAME}-202607080141
 # end of cache build config
 
 _NODE_DISTFILE=		node-v${_PKGFETCH_NODE_VERSION}.tar.gz
diff --git a/www/onlyoffice-documentserver/distinfo b/www/onlyoffice-documentserver/distinfo
index abb77ec6b021..92447aca9450 100644
--- a/www/onlyoffice-documentserver/distinfo
+++ b/www/onlyoffice-documentserver/distinfo
@@ -1,10 +1,10 @@
-TIMESTAMP = 1781400012
+TIMESTAMP = 1783868045
 SHA256 (v8-8.9.255.25_all.tar.gz) = 54853ef93accc063a82a0dc29457b25c9b6d88315431d62e06ab1f84797c5f80
 SIZE (v8-8.9.255.25_all.tar.gz) = 72818814
-SHA256 (node-v24.15.0.tar.gz) = 729de494dd2872e5a3a6c32a1cd156a5413d4aca2772b2d873ee86bb5531bcd9
-SIZE (node-v24.15.0.tar.gz) = 113425441
-SHA256 (onlyoffice-DS-npm-cache-v9.4.0.129-202606140107.tar.gz) = 5232b6ef887832fd90b873bfbf284ae3f8e2a2769599b2fbbc5325a81f3c4381
-SIZE (onlyoffice-DS-npm-cache-v9.4.0.129-202606140107.tar.gz) = 109676613
+SHA256 (node-v24.18.0.tar.gz) = c8348067b41d8739ec69fd4da615cd8995ad6a76eb53e84a7fa7291c8a477eb7
+SIZE (node-v24.18.0.tar.gz) = 114348532
+SHA256 (onlyoffice-DS-npm-cache-v9.4.0.129-202607080141.tar.gz) = 88e54a323fa7fb415bdc40a3cc051889526440bc79d163afedab18aec632de74
+SIZE (onlyoffice-DS-npm-cache-v9.4.0.129-202607080141.tar.gz) = 109697632
 SHA256 (ONLYOFFICE-DocumentServer-v9.4.0_GH0.tar.gz) = 678401ead43a1c1325bc6a662bab95494c85c21546f38584cd76597bdeb743f9
 SIZE (ONLYOFFICE-DocumentServer-v9.4.0_GH0.tar.gz) = 985804
 SHA256 (ONLYOFFICE-build_tools-v9.4.0.129_GH0.tar.gz) = 8f65a62e000e7cc913dd0ee4db5d8dcf6256c16040633dd82f36c104dab52d46
diff --git a/www/onlyoffice-documentserver/files/local.json.sample b/www/onlyoffice-documentserver/files/local.json.sample
index 574f913266c6..b7fdf9841f36 100644
--- a/www/onlyoffice-documentserver/files/local.json.sample
+++ b/www/onlyoffice-documentserver/files/local.json.sample
@@ -1,14 +1,6 @@
 {
   "services": {
     "CoAuthoring": {
-      "sql": {
-        "type": "postgres",
-        "dbHost": "localhost",
-        "dbPort": "5432",
-        "dbName": "onlyoffice",
-        "dbUser": "onlyoffice",
-        "dbPass": "onlyoffice"
-      },
       "token": {
         "enable": {
           "request": {
@@ -41,7 +33,7 @@
     }
   },
   "openpgpjs": {
-    "_comment": "https://helpcenter.onlyoffice.com/docs/installation/docs-developer-configuring.aspx#openpgpprotocol_block"
+    "_comment": "https://helpcenter.onlyoffice.com/docs/installation/docs-developer-configuring.aspx#openpgpprotocol_block",
     "encrypt": {
       "passwords": ["PGPguardsecretstring"]
     },
@@ -50,10 +42,13 @@
     }
   },
   "aesEncrypt": {
-    "_comment": "https://helpcenter.onlyoffice.com/docs/installation/docs-developer-configuring.aspx#aes256gcmalgorithm_block"
+    "_comment": "https://helpcenter.onlyoffice.com/docs/installation/docs-developer-configuring.aspx#aes256gcmalgorithm_block",
     "secret": "docpasswordsecretstring"
   },
-  "rabbitmq": {
-    "url": "amqp://onlyoffice:password@localhost"
+  "storage": {
+    "name": "storage-fs",
+    "fs": {
+      "secretString": "verysecretstring"
+    }
   }
 }
diff --git a/www/onlyoffice-documentserver/files/patch-build__tools_scripts_base.py b/www/onlyoffice-documentserver/files/patch-build__tools_scripts_base.py
index ea9b055a6f24..b6dd395f6a70 100644
--- a/www/onlyoffice-documentserver/files/patch-build__tools_scripts_base.py
+++ b/www/onlyoffice-documentserver/files/patch-build__tools_scripts_base.py
@@ -1,6 +1,15 @@
---- build_tools/scripts/base.py.orig	2021-11-16 08:07:24 UTC
+--- build_tools/scripts/base.py.orig	2026-05-15 19:11:43 UTC
 +++ build_tools/scripts/base.py
-@@ -1375,9 +1376,15 @@ def support_old_versions_plugins(out_dir):
+@@ -1152,7 +1152,7 @@
+   return
+ 
+ def correct_bundle_identifier(bundle_identifier):
+-  return re.sub("[^a-zA-Z0-9\.\-]", "-", bundle_identifier)
++  return re.sub(r"[^a-zA-Z0-9\.\-]", "-", bundle_identifier)
+ 
+ def get_sdkjs_addons():
+   result = {}
+@@ -1590,9 +1590,15 @@
  def support_old_versions_plugins(out_dir):
    if is_file(out_dir + "/pluginBase.js"):
      return
@@ -19,8 +28,17 @@
    content_plugin_base = ""
    with open(get_path(out_dir + "/plugins.js"), "r") as file:
      content_plugin_base += file.read()
-@@ -1520,7 +1527,7 @@ def clone_marketplace_plugin(out_dir, is_name_as_guid=
- def clone_marketplace_plugin(out_dir, is_name_as_guid=False, is_replace_paths=False, is_delete_git_dir=True, git_owner=""):  
+@@ -1650,7 +1656,7 @@
+ def find_mac_sdk_version():
+   sdk_dir = run_command("xcode-select -print-path")['stdout']
+   sdk_dir = os.path.join(sdk_dir, "Platforms/MacOSX.platform/Developer/SDKs")
+-  sdks = [re.findall('^MacOSX(1\d\.\d+)\.sdk$', s) for s in os.listdir(sdk_dir)]
++  sdks = [re.findall(r'^MacOSX(1\d\.\d+)\.sdk$', s) for s in os.listdir(sdk_dir)]
+   sdks = [s[0] for s in sdks if s]
+   return sdks[0]
+ 
+@@ -1745,7 +1751,7 @@
+ def clone_marketplace_plugin(out_dir, is_name_as_guid=False, is_replace_paths=False, is_delete_git_dir=True, git_owner=""):
    old_cur = os.getcwd()
    os.chdir(out_dir)
 -  git_update("onlyoffice.github.io", False, True, git_owner)
@@ -28,3 +46,12 @@
    os.chdir(old_cur)
  
    dst_dir_name = "marketplace"
+@@ -1851,7 +1857,7 @@
+   if (-1 != old_path.find(origin)):
+     return
+   new_path = old_path
+-  new_path = new_path.replace("$ORIGIN", "\$ORIGIN")
++  new_path = new_path.replace("$ORIGIN", r"\$ORIGIN")
+   if ("" != new_path):
+     new_path += ":"
+   new_path += origin
diff --git a/www/onlyoffice-documentserver/files/patch-build__tools_scripts_develop_dependence.py b/www/onlyoffice-documentserver/files/patch-build__tools_scripts_develop_dependence.py
new file mode 100644
index 000000000000..10a387998df5
--- /dev/null
+++ b/www/onlyoffice-documentserver/files/patch-build__tools_scripts_develop_dependence.py
@@ -0,0 +1,25 @@
+--- build_tools/scripts/develop/dependence.py.orig	2026-05-15 19:11:43 UTC
++++ build_tools/scripts/develop/dependence.py
+@@ -687,7 +687,7 @@
+   connectionString = postgreLoginSrt + ' -c "SELECT setting FROM pg_settings WHERE name = ' + "'port'" + ';"'
+ 
+   if (host_platform == 'linux'):
+-    result = os.system(postgreLoginSrt + ' -c "\q"')
++    result = os.system(postgreLoginSrt + r' -c "\q"')
+     connectionResult = base.run_command(connectionString)
+     expected_port = config.option("db-port")
+ 
+@@ -744,11 +744,11 @@
+   creatdb_path = base.get_script_dir() + "/../../server/schema/postgresql/createdb.sql"
+ 
+   # Check if user exists
+-  user_check_result = base.run_command_in_dir(postgre_path_to_bin, postgreLoginRoot + ' -c "\du ' + dbUser + '"')
++  user_check_result = base.run_command_in_dir(postgre_path_to_bin, postgreLoginRoot + r' -c "\du ' + dbUser + '"')
+   
+   if (user_check_result['stdout'].find(dbUser) != -1):
+     # User exists, check password
+-    if (os.system(postgreLoginDbUser + '-c "\q"') != 0):
++    if (os.system(postgreLoginDbUser + r'-c "\q"') != 0):
+       print('Invalid user password, changing...')
+       result = change_userPass(dbUser, dbPass, postgre_path_to_bin) and result
+   else:
diff --git a/www/onlyoffice-documentserver/files/patch-core_Common_3dParty_v8__89_v8_tools_gen-postmortem-metadata.py b/www/onlyoffice-documentserver/files/patch-core_Common_3dParty_v8__89_v8_tools_gen-postmortem-metadata.py
new file mode 100644
index 000000000000..e607f9e2d437
--- /dev/null
+++ b/www/onlyoffice-documentserver/files/patch-core_Common_3dParty_v8__89_v8_tools_gen-postmortem-metadata.py
@@ -0,0 +1,38 @@
+--- core/Common/3dParty/v8_89/v8/tools/gen-postmortem-metadata.py.orig	2021-04-12 21:00:33 UTC
++++ core/Common/3dParty/v8_89/v8/tools/gen-postmortem-metadata.py
+@@ -470,7 +470,7 @@
+         #
+         entries = typestr.split(',');
+         for entry in entries:
+-                types[re.sub('\s*=.*', '', entry).lstrip()] = True;
++                types[re.sub(r'\s*=.*', '', entry).lstrip()] = True;
+         entries = torque_typestr.split('\\')
+         for entry in entries:
+                 types[re.sub(r' *V\(|\) *', '', entry)] = True
+@@ -481,7 +481,7 @@
+                     continue
+                 idx = entry.find('(');
+                 rest = entry[idx + 1: len(entry) - 1];
+-                args = re.split('\s*,\s*', rest);
++                args = re.split(r'\s*,\s*', rest);
+                 typename = args[0]
+                 typeconst = args[1]
+                 types[typeconst] = True
+@@ -584,7 +584,7 @@
+         idx = call.find('(');
+         kind = call[0:idx];
+         rest = call[idx + 1: len(call) - 1];
+-        args = re.split('\s*,\s*', rest);
++        args = re.split(r'\s*,\s*', rest);
+ 
+         consts = [];
+ 
+@@ -685,7 +685,7 @@
+ 
+         # Fix up overzealous parses.  This could be done inside the
+         # parsers but as there are several, it's easiest to do it here.
+-        ws = re.compile('\s+')
++        ws = re.compile(r'\s+')
+         for const in consts:
+                 name = ws.sub('', const['name'])
+                 value = ws.sub('', str(const['value']))  # Can be a number.
diff --git a/www/onlyoffice-documentserver/files/patch-document-server-package_common_documentserver_bin_documentserver-update-securelink.sh.m4 b/www/onlyoffice-documentserver/files/patch-document-server-package_common_documentserver_bin_documentserver-update-securelink.sh.m4
index 6d40dfa72b4c..f33d087eb0c7 100644
--- a/www/onlyoffice-documentserver/files/patch-document-server-package_common_documentserver_bin_documentserver-update-securelink.sh.m4
+++ b/www/onlyoffice-documentserver/files/patch-document-server-package_common_documentserver_bin_documentserver-update-securelink.sh.m4
@@ -1,4 +1,4 @@
---- document-server-package/common/documentserver/bin/documentserver-update-securelink.sh.m4.orig	2023-06-20 13:50:40 UTC
+--- document-server-package/common/documentserver/bin/documentserver-update-securelink.sh.m4.orig	2026-05-14 16:29:43 UTC
 +++ document-server-package/common/documentserver/bin/documentserver-update-securelink.sh.m4
 @@ -1,24 +1,24 @@
  #!/bin/sh
@@ -30,7 +30,7 @@
  			echo "  Usage $0 [PARAMETER] [[PARAMETER], ...]"
  			echo "    Parameters:"
  			echo "      -s, --secure_link_secret               setting for secret string "
-@@ -26,26 +26,21 @@ while [ "$1" != "" ]; do
+@@ -26,26 +26,26 @@
  			echo
  			exit 0
  		;;
@@ -42,7 +42,8 @@
 -NGINX_CONF=/etc/M4_DS_PREFIX/nginx/ds.conf
 -LOCAL_CONF=/etc/M4_DS_PREFIX/local.json
 -JSON="/var/www/M4_DS_PREFIX/npm/json -q -f ${LOCAL_CONF}"
-+NGINX_CONF=%%LOCALBASE%%/etc/M4_DS_PREFIX/nginx/ds.conf
++NGINX_HTTP_CONF=%%LOCALBASE%%/etc/M4_DS_PREFIX/nginx/ds.conf
++NGINX_SSL_CONF=%%LOCALBASE%%/etc/M4_DS_PREFIX/nginx/ds-ssl.conf
 +LOCAL_CONF=%%LOCALBASE%%/etc/M4_DS_PREFIX/local.json
 +JSON="%%LOCALBASE%%/www/M4_DS_PREFIX/npm/json -q -f ${LOCAL_CONF}"
  
@@ -51,7 +52,11 @@
  
 -sed "s,\(set \+\$secure_link_secret\).*,\1 "${SECURE_LINK_SECRET}";," -i ${NGINX_CONF}
 -${JSON} -I -e 'this.storage={fs: {secretString: "'${SECURE_LINK_SECRET}'" }}' && chown ds:ds $LOCAL_CONF
-+gsed "s,\(set \+\$secure_link_secret\).*,\1 ""${SECURE_LINK_SECRET}"";," -i ${NGINX_CONF}
++for conf in "${NGINX_HTTP_CONF}" "${NGINX_SSL_CONF}"; do
++  if [ -f "${conf}" ]; then
++    gsed "s,\(set \+\$secure_link_secret\).*,\1 ""${SECURE_LINK_SECRET}"";," -i "${conf}"
++  fi
++done
 +${JSON} -I -e 'this.storage={fs: {secretString: "'${SECURE_LINK_SECRET}'" }}' && chown onlyoffice:onlyoffice $LOCAL_CONF
  
  if [ "$RESTART_CONDITION" != "false" ]; then
@@ -62,5 +67,4 @@
 -  elif pgrep -x ""supervisord"" >/dev/null; then
 +  if pgrep -f "supervisord" >/dev/null; then
      supervisorctl restart ds:docservice
-     supervisorctl restart ds:converter
      service nginx reload
diff --git a/www/onlyoffice-documentserver/files/pkg-message.in b/www/onlyoffice-documentserver/files/pkg-message.in
index 4299eafdbc00..81dab26f7418 100644
--- a/www/onlyoffice-documentserver/files/pkg-message.in
+++ b/www/onlyoffice-documentserver/files/pkg-message.in
@@ -27,11 +27,23 @@ files = %%ETCDIR%%/documentserver/supervisor/*.conf
     # service supervisord start
 
 3. Set up nginx:
-  - For HTTP include the following in your %%PREFIX%%/etc/nginx/nginx.conf file:
-      include %%ETCDIR%%/documentserver/nginx/ds.conf;
+  - Include the configuration appropriate for your deployment within
+    your %%PREFIX%%/etc/nginx/nginx.conf file:
+
+     HTTP:
+       include %%ETCDIR%%/documentserver/nginx/ds.conf;
+
+     HTTPS:
+       include %%ETCDIR%%/documentserver/nginx/ds-ssl.conf;
+
+   Review and customize the supplied ds.conf or ds-ssl.conf nginx configuration
+   before use, including the listen directives, TLS configuration, and any site-
+   specific settings.
 
-NOTE: documentserver-update-securelink.sh will only update ./nginx/ds.conf and local.json under %%ETCDIR%%/documentserver/!
   - run documentserver-update-securelink.sh once for creating a verysecretstring
+Note: documentserver-update-securelink.sh updates only the packaged ds.conf, ds-ssl.conf,
+and local.json files in their default locations. If your nginx configuration uses custom
+copies or alternate paths, synchronize the secure_link_secret values manually.
 
   - start nginx:
     # service nginx start