Skip to content
This repository has been archived by the owner on May 14, 2020. It is now read-only.

Allow REPORT requests without Content-Type header in Nextcloud #1743

Merged
merged 1 commit into from
May 5, 2020
Merged

Allow REPORT requests without Content-Type header in Nextcloud #1743

merged 1 commit into from
May 5, 2020

Conversation

pyllyukko
Copy link
Contributor

Issue

When the file list in the iOS app is refreshed, it triggers Missing Content-Type Header with Request Body rule with a REPORT request to /remote.php/dav/files/<username>

Background

Sofware Version
CRS 3.2.0
ModSecurity 3.0.4
Nextcloud 18.0.3
Nextcloud iOS app 2.25.9.2

Fix

This PR disables rule 920340 with REPORT requests to /remote.php/dav/files/

@franbuehler
Copy link
Contributor

In the monthly chat meeting from May 4 we decided to merge this PR:
#1749 (comment)

@franbuehler franbuehler merged commit 3711365 into SpiderLabs:v3.3/dev May 5, 2020
@pyllyukko pyllyukko deleted the fix-nextcloud-report-request branch June 4, 2020 13:57
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants