-
Notifications
You must be signed in to change notification settings - Fork 80
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
issue 11760 is missed on issues.joomla.org #871
Comments
Looks like we have a general bot issue? https://issues.joomla.org/tracker/joomla-cms/11694 Misses the last comments from |
I'm getting really tired of ModSec... |
😄 How did it work before? |
Odds are the old server didn't have ModSec on it. |
Ok. Hmm but there should be a way to consume github hooks in a secure way do we have a way to contact github? |
It's not GitHub, it's Rochen. |
I mean ask github to get a secure configuration of mod security they have maybe some expirience in that? Or Rochen ask github howto configure it secure? |
Can we do something like |
Supposedly Rochen whitelisted GitHub stuff based on the data I gave them. Apparently that's not happening. The problem is our issues commonly have SQL scripts, JavaScript snippets, and HTML inlined into them. Which triggers the rules long before our application runs. And that page is only good for application level security measures. It does nothing to address the web server stripping stuff. |
Hmm thanks for checking |
Hmm loks like that the cron synced it.. So we need to add our logic to the crons too? Like pending and labels? |
So #692 needs to be synced, tested, and merged is what you're saying. And the cron works fine because it initiates a request to GitHub's API and pulls the data as a response whereas the webhooks send the request to our server. ModSecurity only filters incoming HTTP traffic, unless someone REALLY screwed up a configuration it shouldn't filter data from a curl request inside a PHP app. |
i don't have admin rights on github repos. But also resending that would fail, correct? |
Correct. |
Per Rochen:
|
Steps to reproduce the issue
Issues.joomla.org
Expected result
See the entry there
Actual result
No entry for joomla/joomla-cms#11760
System information (as much as possible)
Additional comments
The text was updated successfully, but these errors were encountered: