From a1d4bc16b309164fb80f36fcc72bbb445b0eca01 Mon Sep 17 00:00:00 2001 From: "srvproxy001.itguys.com.br" Date: Wed, 17 Sep 2025 16:26:01 -0300 Subject: [PATCH] =?UTF-8?q?[Auto-Sync]=20Atualiza=C3=A7=C3=A3o=20das=20con?= =?UTF-8?q?figura=C3=A7=C3=B5es=20em=20srvproxy001.itguys.com.br=20-=20202?= =?UTF-8?q?5-09-17=2016:26:01?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- nginx/modsecurity.conf | 3 +++ nginx/modsecurity/grafana-rule-exceptions.conf | 7 +++++++ 2 files changed, 10 insertions(+) create mode 100644 nginx/modsecurity/grafana-rule-exceptions.conf diff --git a/nginx/modsecurity.conf b/nginx/modsecurity.conf index e49068f..60062c0 100644 --- a/nginx/modsecurity.conf +++ b/nginx/modsecurity.conf @@ -299,3 +299,6 @@ Include /etc/nginx/modsecurity/zammad-rule-exceptions.conf # Carrega as nossas exceções personalizadas para o Gitea. Include /etc/nginx/modsecurity/gitea-rule-exceptions.conf + +# Carrega as nossas exceções personalizadas para o Grafana. +Include /etc/nginx/modsecurity/grafana-rule-exceptions.conf diff --git a/nginx/modsecurity/grafana-rule-exceptions.conf b/nginx/modsecurity/grafana-rule-exceptions.conf new file mode 100644 index 0000000..7e08f55 --- /dev/null +++ b/nginx/modsecurity/grafana-rule-exceptions.conf @@ -0,0 +1,7 @@ +# Ficheiro de Exceções do ModSecurity para o Grafana + +# Desativa a regra 9XXXXX (que estava a causar um falso positivo com o método DELETE) +# APENAS para as requisições que começam com /api/dashboards/. +# Isto mantém a regra ativa para o resto do site. +SecRule REQUEST_URI "@beginsWith /api/dashboards/" \ + "id:1007,phase:1,nolog,allow,ctl:ruleRemoveById=9XXXXX"