2
0
mirror of https://github.com/xcat2/xcat-core.git synced 2026-10-08 02:23:01 +00:00

fix(xcat-core): deny the REST aliases when mod_rewrite is not loaded

xcat-ws.conf sends /xcatws and /xcatwsv2 to https only when mod_rewrite is
loaded. Without that module the aliases run the REST CGI on any port.

An IfModule !mod_rewrite.c block now answers 403 for both aliases.
RedirectMatch comes from mod_alias, which the ScriptAlias lines of the
same file already require. Other paths, such as /install, are not changed.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
This commit is contained in:
Daniel Hilst
2026-10-05 13:39:18 -03:00
parent 469e108ff4
commit 6bc7800bba
+4
View File
@@ -11,6 +11,10 @@ RewriteCond %{HTTPS} !=on
RewriteRule ^/?xcatws/(.*) https://%{SERVER_NAME}/xcatws/$1 [R,L]
RewriteRule ^/?xcatwsv2/(.*) https://%{SERVER_NAME}/xcatwsv2/$1 [R,L]
</IfModule>
# Without the redirect, deny the REST aliases.
<IfModule !mod_rewrite.c>
RedirectMatch 403 ^/xcatws(v2)?(/|$)
</IfModule>
<FilesMatch "^(xcatws.cgi|zvmxcatws.cgi)$">
# Both spellings, so one file serves Apache 2.2 and 2.4.