From e528575abaa195772b069403b3b0bb238fe02fb0 Mon Sep 17 00:00:00 2001 From: "srvproxy001.itguys.com.br" Date: Mon, 22 Sep 2025 12:27:57 -0300 Subject: [PATCH] =?UTF-8?q?[Auto-Sync]=20Atualiza=C3=A7=C3=A3o=20das=20con?= =?UTF-8?q?figura=C3=A7=C3=B5es=20em=20srvproxy001.itguys.com.br=20-=20202?= =?UTF-8?q?5-09-22=2012:27:57?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- nginx/modsecurity/global-exceptions.conf | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/nginx/modsecurity/global-exceptions.conf b/nginx/modsecurity/global-exceptions.conf index 95f9d8f..ade00e7 100644 --- a/nginx/modsecurity/global-exceptions.conf +++ b/nginx/modsecurity/global-exceptions.conf @@ -57,6 +57,14 @@ SecRule REQUEST_URI "@beginsWith /api/dashboards/" "id:10009,phase:1,nolog,allow # Substitua '9XXXXX' pelo ID real encontrado no log de auditoria. SecRule REQUEST_URI "@beginsWith /index.php/core/preview" "id:10010,phase:1,nolog,pass,ctl:ruleRemoveById=9XXXXX +# -------------------------------------------------------------------------- +# Exceções para o Nextcloud Office Online +# -------------------------------------------------------------------------- +# Desliga completamente o motor de regras para as rotas de comunicação do +# Office Online, que geram muitos falsos positivos. +# As rotas são /hosting/discovery, /hosting/wopi/ e /op/. +SecRule REQUEST_URI "@rx ^/(hosting/discovery|hosting/wopi/|op/)" "id:10014,phase:1,nolog,pass,ctl:ruleEngine=Off" + # Exceções para a API do UniFi Controller # -------------------------------------------------------------------------- # Desativa a regra que bloqueia o método 'PUT' para a API.