From 6bc7800bba8eddd874ca95ea9a70da4c299bd3d1 Mon Sep 17 00:00:00 2001
From: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Date: Mon, 5 Oct 2026 13:39:18 -0300
Subject: [PATCH] fix(xcat-core): deny the REST aliases when mod_rewrite is not
loaded
xcat-ws.conf sends /xcatws and /xcatwsv2 to https only when mod_rewrite is
loaded. Without that module the aliases run the REST CGI on any port.
An IfModule !mod_rewrite.c block now answers 403 for both aliases.
RedirectMatch comes from mod_alias, which the ScriptAlias lines of the
same file already require. Other paths, such as /install, are not changed.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
---
xCAT-server/xCAT-wsapi/xcat-ws.conf | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/xCAT-server/xCAT-wsapi/xcat-ws.conf b/xCAT-server/xCAT-wsapi/xcat-ws.conf
index aefeb45b6..64cc7612a 100644
--- a/xCAT-server/xCAT-wsapi/xcat-ws.conf
+++ b/xCAT-server/xCAT-wsapi/xcat-ws.conf
@@ -11,6 +11,10 @@ RewriteCond %{HTTPS} !=on
RewriteRule ^/?xcatws/(.*) https://%{SERVER_NAME}/xcatws/$1 [R,L]
RewriteRule ^/?xcatwsv2/(.*) https://%{SERVER_NAME}/xcatwsv2/$1 [R,L]
+# Without the redirect, deny the REST aliases.
+
+RedirectMatch 403 ^/xcatws(v2)?(/|$)
+
# Both spellings, so one file serves Apache 2.2 and 2.4.