View Issue Details

IDProjectCategoryView StatusLast Update
0005851Composrcorepublic2024-08-05 18:20
ReporterPatrick SchmalstigAssigned ToPatrick Schmalstig 
SeverityMinor-bug 
Status resolvedResolutionfixed 
Product Version11.beta1 
Fixed in Version 
Summary0005851: Apache now blocks spaces / control characters as part of mod_rewrite
DescriptionApache mod_rewrite will now throw a 403 forbidden if rewrite rules result in a space or control character being present in them.

We should examine this and potentially update how we process URL rewrites.
Additional InformationSee https://www.plesk.com/kb/support/domain-in-plesk-shows-error-403-rewritten-query-string-contains-control-characters-or-spaces/
TagsRoadmap: v10 submarine feature, Roadmap: v11
Time estimation (hours)
Sponsorship open

Activities

admin

2024-08-05 03:42

administrator   ~0009120

Automated message: This issue was created using the Report Issue Wizard on the Composr homesite.

admin

2024-08-05 18:20

administrator   ~0009121

Automated response: Apache now blocks spaces / control characters as part of mod_rewrite

Apache mod_rewrite will now throw a 403 forbidden if rewrite rules result in a space or control character being present in them.

This patch maps %20 to :space: and decodes back to a space internally to work around this.

admin

2024-08-05 18:20

administrator   ~0009122

Fixed in Git commit 2bf64af8b7 (https://gitlab.com/composr-foundation/composr/commit/2bf64af8b7 - link will become active once code pushed to GitLab)

hotfix-5851, 2024-08-05 6pm.tar (62,976 bytes)

admin

2024-08-05 18:20

administrator   ~0009123

A hotfix (a TAR of files to upload) has been uploaded to this issue. Only apply this hotfix if you absolutely need it and cannot wait until the next release of Composr (releases are more reliable and strictly tested). As of Composr version 11, the recommended way to apply a hotfix is by following the same steps as an upgrade (https://baseurl/upgrader.php, use the hotfix on the step “Transfer across new/updated files”). The upgrader will automatically skip files belonging to addons you do not have installed or that are newer on disk than in the hotfix. Otherwise, you can manually extract and replace these files (do not replace if your on-disk file is newer than the one in the hotfix). Always take backups of your site or at least files you are replacing before applying a hotfix. Not sure how to extract TAR files to your Windows computer? Try 7-zip (http://www.7-zip.org/).

Issue History

Date Modified Username Field Change
2024-08-05 03:42 Patrick Schmalstig Tag Attached: Roadmap: v11
2024-08-05 03:42 Patrick Schmalstig Tag Attached: Roadmap: v10 submarine feature