Coreruleset: Kindly, consider adding support for Wordpress Gutenberg editor.

Created on 13 May 2020  路  11Comments  路  Source: coreruleset/coreruleset

_Issue originally created by user Shubham-Panwar on date 2018-11-06 19:01:38.
Link to original issue: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1232._

Kindly, consider adding support for Wordpress Gutenberg editor, Which is going to be the default editor from 5.0 release of Wordpress.

currently all of Gutenberg functions gives 403 errors.

Owasp rules are currently blocking WP Gutenberg autosaves, uploading pictures , saving post , etc.

Default Wordpress Exclusions ruleset is enabled, But there are no rules for Gutenberg in the Default WP Exclusion ruleset.

Till Support is added for Gutenberg editor, is their any temporary solution ?

Need more info

All 11 comments

_User dune73 commented on date 2018-11-06 19:19:46:_

Thanks for reporting Shubham-Panwar. We would definitely add support if somebody were to write the
necessary rule exclusions. We can lend a hand with that, but it takes somebody who uses Gutenberg to push this. Interested?

_User lifeforms commented on date 2018-11-07 16:30:47:_

I can take on this project.

It's too late for inclusion in CRS 3.1, but it would be a good feature for the next release.

Shubham-Panwar Are you able to help us with testing, by cloning the development branch of the CRS and checking if it works correctly? That would be awesome.

_User Shubham-Panwar commented on date 2018-11-07 16:54:00:_

Yes, sure

_User JeffCleverley commented on date 2019-02-16 07:54:50:_

We are very keen on helping here. Would need a bit of guidance too.

It's not just Gutenberg, any plugins that use the Rest API endpoints are hitting the firewall.

This is more and more of the newer plugins, and soon it will be central to most WordPress development.

We run a WordPress specific VPS Control SaaS that is incorporating ModSec into our Server deployments. (WordPress GridPane)

I was just about to look at modifying rules for post/pages when I found this, but also we have had test users submitting issues with a couple of different plugins that rely on internal use of the API.

I will poll our users and see about writing exclusions for specific popular plugins they use, I believe there will be quite a few and would be good to include in the ruleset exclusions.

Yoast SEO for one uses it for internal linking (most of the internal linking plugins use it now).

I have looked at the rules, seen the other merge, I should be able to get a handle on this.

_User fgsch commented on date 2019-03-07 17:40:44:_

1298 has been merged. Is there any outstanding work here?

_User lifeforms commented on date 2019-03-08 15:50:51:_

Yep, basic Gutenberg support is now in. There's an additional request but that's in a separate issue and I will get to that. Thanks for reporting and commenting!

_User smerriman commented on date 2019-04-24 01:12:44:_

Very sorry for posting here, since this probably isn't meant to be a support forum.

But I'm having all of the OWASP rules triggered for the REST API endpoints when attempting to save a post in Gutenberg, implying these exceptions aren't happening.

I see this was only resolved relatively recently; is it possible Cloudflare haven't integrated the new ruleset yet?

Can provide more details if necessary.

_User lifeforms commented on date 2019-04-24 09:28:24:_

Hi smerriman, this change is not yet in an official CRS release. It will certainly be in the next release CRS 3.2 but this does not have a timetable yet. We are not aware of how/when Cloudflare picks up our releases, I think they likely use their own internal fork and integrate changes on their own pace.

_User smerriman commented on date 2019-04-24 21:17:17:_

OK, thanks for the reply. Hopefully the release is very soon, since otherwise it appears there is basically no option other than to disable OWASP rules entirely for any site running WordPress.

_User JeffCleverley commented on date 2019-04-25 04:36:04:_

It is possible to write a whitelist rule for the api endpoints... that what I did

_User davemosk commented on date 2019-06-27 20:37:12:_

Hey JeffCleverley would it be possible for you to share your whitelist rule here? Thanks!

Was this page helpful?
0 / 5 - 0 ratings

Related issues

CRS-migration-bot picture CRS-migration-bot  路  6Comments

CRS-migration-bot picture CRS-migration-bot  路  8Comments

CRS-migration-bot picture CRS-migration-bot  路  12Comments

CRS-migration-bot picture CRS-migration-bot  路  10Comments

CRS-migration-bot picture CRS-migration-bot  路  13Comments