# FAQ

We cover both frequently asked questions and special cases that would polute the documentation here.

## Installation

### Environments with SELinux

To make An Otter Wiki run in an environment with `SELINUX=enforcing` with the methods propose in the [[Installation]] document the bind mounts have to be adjusted. 

When podman gives you the error message
```
mkdir: cannot create directory '/app-data': Permission denied
```
please update your `compose.yaml` to
```yaml
services:
  otterwiki:
    image: redimp/otterwiki:2
    restart: unless-stopped
    ports:
      - 8080:80
    volumes:
      - ./app-data:/app-data:Z
```

For podman please see the [podman troubleshooting guide](https://github.com/containers/podman/blob/main/troubleshooting.md#2-cant-use-volume-mount-get-permission-denied) for more details and instructions. 

In our tests in `rocky:9 docker` configured the permissions even with setting the `:z` flag, please see the [docker documentation about bind mounts](https://docs.docker.com/engine/storage/bind-mounts/#configure-the-selinux-label) for more details.

#### Caddy as reverse proxy provisioning TLS certificates

In an environment with `SELINUX=enforcing` where Caddy is used as reverse proxy, it was observed that it is necessary to run
```bash
setsebool -P httpd_can_network_connect on
```
to enable Caddy to connect to the internet in order to provision proper TLS certificates. 

### The wiki cannot be served from a subfolder

An Otter Wiki requires a dedicated domain (e.g. `wiki.domain.tld`) and can not be mapped into a subfolder of a domain (e.g. `domain.tld/wiki`). See the requirements in [[Installation|Installation#requirements]].

## Errors

### 413 RequestEntityTooLarge

When An Otter Wiki raises the error 413 RequestEntityTooLarge please configure the variable `MAX_FORM_MEMORY_SIZE` which is in bytes and by default `1000000`, see [Configuration](/Configuration#content-and-editing-preferences).

### Listen queue size is greater than the system max net.core.somaxconn

This was reported to happen when using the `-slim` image on a Synology NAS, see [#342](https://github.com/redimp/otterwiki/issues/342). This can be fixed with increasing the value via sysctl or when using a `docker-compose.yaml` with

```yaml
services:
  otterwiki:
    image: redimp/otterwiki:2-slim
    restart: unless-stopped
    ports:
      - 8080:8080
    volumes:
      - ./app-data:/app-data
    sysctls:
      - net.core.somaxconn=1024
```

### Form submission fails after a tab was left open for a long time

Symptom: saving a page, logging in or submitting any other form fails after the tab had been open for a long time. Cause: the CSRF token expired. CSRF protection (from version **2.20.0**) is controlled by `WTF_CSRF_TIME_LIMIT`, which defaults to `86400` seconds (24 hours). If your users run into this regularly, raise the value, see [[Configuration|Configuration#security]]. Do not work around it by disabling `WTF_CSRF_ENABLED`, that turns off the CSRF protection entirely.

## Administration

### I locked myself out

Symptom: nobody can log into an admin account any more, for example a forgotten admin password, a deleted admin user, or a mail server that is down so the password reset email never arrives. Fix: use the [[command line interface|CLI]], which needs neither a browser nor a working login. Generate a fresh password for your admin user:

```
docker compose exec -u www-data otterwiki flask user password you@example.com --generate
```

The command prints a new password to log in with. If no admin user is left, create one first with `flask user create you@example.com "You" -p admin`. See the [[CLI]] page for running these commands from a source install and for the full command reference.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9