如何在ModSecurity中配置允许text/x-gwt-rpc类型的Content-Type?
允许text/x-gwt-rpc类型Content-Type的ModSecurity规则配置(适配Plesk+Comodo免费规则)
操作步骤
1. 创建不受覆盖的自定义规则文件
由于Plesk中Comodo规则更新会覆盖默认白名单文件,需在专属自定义规则目录创建规则文件:
touch /usr/local/psa/etc/modsecurity/custom/custom_content_type_whitelist.conf
2. 添加ModSecurity允许规则
编辑上述文件,添加以下任一规则即可:
方案一:直接允许该Content-Type并跳过对应拦截规则
# 匹配text/x-gwt-rpc类型请求,允许通过并跳过Comodo的Content-Type检查规则(ID 980130) SecRule REQUEST_HEADERS:Content-Type "@streq text/x-gwt-rpc" "id:1000001,phase:1,nolog,allow,ctl:ruleRemoveById=980130"
方案二:修改原有拦截规则,排除该Content-Type
# 让Comodo的980130规则忽略text/x-gwt-rpc类型的请求 SecRuleUpdateTargetById 980130 "!REQUEST_HEADERS:Content-Type text/x-gwt-rpc"
注:自定义规则ID(如1000001)需确保与现有规则不冲突,可通过
grep "id:" /usr/local/psa/etc/modsecurity/rules/ | sort -n查看已用ID范围。
3. 验证配置并重启服务
先检查Apache配置合法性:
apache2ctl configtest
若返回Syntax OK,重启Apache服务:
systemctl restart apache2
或通过Plesk命令重新配置所有站点:
plesk sbin httpdmng --reconfigure-all
4. 验证规则生效
用curl发送测试请求,确认未被拦截:
curl -H "Content-Type: text/x-gwt-rpc" -X POST https://你的域名/你的GWT接口路径
内容的提问来源于stack exchange,提问作者Gauthier
相关产品推荐
相关产品推荐

