如何在RabbitMQ中禁用HTTP TRACE方法并返回405 Method Not Allowed?
Sure thing! Let's walk through how to block and disable the HTTP TRACE method in RabbitMQ so that it returns a 405 Method Not Allowed response when you run curl -v -X TRACE http://server-name:15672.
RabbitMQ's management UI relies on the Cowboy web server under the hood, so we can tweak Cowboy's configuration to explicitly restrict which HTTP methods are allowed—excluding TRACE entirely. Here's the step-by-step process:
1. Update RabbitMQ's Configuration File
The exact file you'll edit depends on your RabbitMQ version. Newer releases use a simplified rabbitmq.conf format, while older ones use Erlang-style rabbitmq.config.
For Newer RabbitMQ (using rabbitmq.conf)
Open your rabbitmq.conf (usually found at /etc/rabbitmq/rabbitmq.conf on Linux) and add these lines to define allowed HTTP methods (leaving out TRACE):
# For HTTP management port (15672) management.http.server_options.allowed_methods = GET, HEAD, POST, PUT, DELETE, OPTIONS # If you use the HTTPS management port (15671), add this too management.https.server_options.allowed_methods = GET, HEAD, POST, PUT, DELETE, OPTIONS
For Older RabbitMQ (using rabbitmq.config)
Open the Erlang-style config file (typically /etc/rabbitmq/rabbitmq.config) and update the rabbitmq_management section to include the allowed_methods directive:
[{rabbitmq_management, [ {http_server_options, [ {allowed_methods, ['GET', 'HEAD', 'POST', 'PUT', 'DELETE', 'OPTIONS']} ]}, % Add this if you use the HTTPS management port {https_server_options, [ {allowed_methods, ['GET', 'HEAD', 'POST', 'PUT', 'DELETE', 'OPTIONS']} ]} ]}].
2. Restart RabbitMQ to Apply Changes
Save your config file and restart the RabbitMQ service to make the changes take effect:
# On systemd-based systems (like Ubuntu 16.04+, CentOS 7+) sudo systemctl restart rabbitmq-server # On older init.d systems sudo service rabbitmq-server restart
3. Verify the Fix
Run your test curl command again to confirm TRACE is blocked:
curl -v -X TRACE http://server-name:15672
You should see a response line that looks like this:
HTTP/1.1 405 Method Not Allowed
That's all! The TRACE method is now disabled and will return the expected 405 status code for any requests.
内容的提问来源于stack exchange,提问作者Abhijit Patil

