From 6bc7800bba8eddd874ca95ea9a70da4c299bd3d1 Mon Sep 17 00:00:00 2001 From: Daniel Hilst <392820+dhilst@users.noreply.github.com> Date: Mon, 5 Oct 2026 13:39:18 -0300 Subject: [PATCH] fix(xcat-core): deny the REST aliases when mod_rewrite is not loaded xcat-ws.conf sends /xcatws and /xcatwsv2 to https only when mod_rewrite is loaded. Without that module the aliases run the REST CGI on any port. An IfModule !mod_rewrite.c block now answers 403 for both aliases. RedirectMatch comes from mod_alias, which the ScriptAlias lines of the same file already require. Other paths, such as /install, are not changed. Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com> --- xCAT-server/xCAT-wsapi/xcat-ws.conf | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/xCAT-server/xCAT-wsapi/xcat-ws.conf b/xCAT-server/xCAT-wsapi/xcat-ws.conf index aefeb45b6..64cc7612a 100644 --- a/xCAT-server/xCAT-wsapi/xcat-ws.conf +++ b/xCAT-server/xCAT-wsapi/xcat-ws.conf @@ -11,6 +11,10 @@ RewriteCond %{HTTPS} !=on RewriteRule ^/?xcatws/(.*) https://%{SERVER_NAME}/xcatws/$1 [R,L] RewriteRule ^/?xcatwsv2/(.*) https://%{SERVER_NAME}/xcatwsv2/$1 [R,L] +# Without the redirect, deny the REST aliases. + +RedirectMatch 403 ^/xcatws(v2)?(/|$) + # Both spellings, so one file serves Apache 2.2 and 2.4.