Configure rules to allow or deny access to resources without authentication
*
) that match any characters. Patterns and URLs are split into segments (using /
), and each segment is matched individually.
blog/posts
/blog/posts
.
blog/*
/blog
(e.g., /blog/travel
).
*/2023/*
/2023/
as a middle segment (e.g., /news/2023/summary
).
article*
/article-123
).
*admin*
/my-admin-panel
).
personal-*/*
personal-
and is followed by any segment (e.g., /personal-blog/post
).
/blog/journal/entry
becomes ["blog", "journal", "entry"]
, while /blog*
becomes ["blog*"]
.
/blog*
only matches the first segment, so URLs with extra segments require additional placeholders (e.g., /blog*/*
).
144.234.11.22/24
- Matches all 256 IPs from 192.168.1.0 to 192.168.1.25510.0.0.0/8
- Matches any IP starting with 10 (16.7 million addresses)2001:db8::/32
- Matches a range of IPv6 addresses0.0.0.0/0
- Matches all IPv4 addresses23.234.134.32
34.45.245.64
192.168.1.1
App | Required Bypass Rules |
---|---|
Media Management | |
Radarr | /api/* |
Sonarr | /api/* |
Lidarr | /api/* |
Media Servers | |
Jellyfin (iOS) | /system/info/public |
Jellyfin (Roku) | /System/Info/Public /Users/AuthenticateByName /Users/Public /QuickConnect/Initiate /QuickConnect/Connect /Users/AuthenticateWithQuickConnect |
Audiobookshelf (Android) | /api/* /login* /s/* /ping* /feed/* /socket* /status |
Management & Monitoring | |
Tautulli | /api/* |
Harbour | /api/* |
Hoarder App | /api/* |
Uptime Kuma Manager | /api/* /socket.io/* |
MeshCentral | /api/* /meshrelay.ashx /agent.ashx |
Security & Privacy | |
AdGuard Home | /api/* |
Ente Auth | *api* |
Vaultwarden/Bitwarden | /api/* /identity/* /wl/* Always Deny - Path - /admin/* |
Cloud & Sync | |
Nextcloud | / (Main interface)/index.php (Core handler)/remote.php (Remote access)/status.php (Status checks)/ocs (Collaboration Services API)/apps (Applications)/remote.php/webdav (WebDAV endpoint)/remote.php/dav (CalDAV/CardDAV)/remote.php/caldav (Calendar sync)/remote.php/carddav (Contacts sync)/ocs/v1.php (API endpoints)/ocs/v2.php (API v2 endpoints)/login (Authentication)/.well-known/* (Service discovery)/.well-known/webfinger (WebFinger protocol)/s/* (Shared files/folders) |
Onlyoffice | /cache/* */CommandService.ashx */converter/* */doc/* */downloadas/* /downloadfile/* */fonts/* /healthcheck /methodology/* */plugins.json */sdkjs/* */sdkjs-plugins/* */themes.json */web-apps/* |
Photo Management | |
Ente Photos | *api* |
Immich | /api/* /.well-known/immich |
File Management | |
Filebrowser | /static/* /share/* /api/public/dl/* /api/public/share/* |
Notes & Knowledge Management | |
Joplin Notes Server | /api/* /shares/* /css/* /images/* Always Deny - Path - /login/* (optional) |
Erugo | /api/* /shares/* /build/* /get-logo |
Memos | /api/* /assets/* /explore* /memos.api.v1.* /auth/callback* /auth /site.webmanifest /logo.webp /full-logo.webp /android-chrome-192x192.png |
Linkding | /api/* /bookmarks/* Always Deny - Path - /admin/* |
Communication | |
Matrix/Synapse (Clients) | /_matrix/* /_synapse/client/* |
Matrix/Synapse (Federation) | /_matrix/* |
Notifications | |
Gotify | /version /message /application /client /stream /plugin /health |
Home Automation | |
Home Assistant | /api/* /auth/* /frontend_latest/* /lovelace* /static/* /hacsfile/* /local/* |
n8n | /webhook-test/*/webhook /webhook/*/webhook |
Project Management | |
Jetbrains Youtrack | /api/* /hub/api/* |