diff --git a/deployments/templates/ingress.yml b/deployments/templates/ingress.yml index bda9ae50..ada8a3db 100644 --- a/deployments/templates/ingress.yml +++ b/deployments/templates/ingress.yml @@ -8,7 +8,11 @@ metadata: nginx.ingress.kubernetes.io/enable-modsecurity: "true" nginx.ingress.kubernetes.io/modsecurity-snippet: | SecRuleEngine On + + # Rule to resolve issues with urls containing '.profile' being blocked by rule 930130 + # See ticket https://github.com/ministryofjustice/find-moj-data/issues/982 SecRule REQUEST_URI "@contains .profile" "id:1005,phase:1,t:lowercase,ctl:ruleRemoveById=930130" + SecDefaultAction "phase:2,pass,log,tag:github_team=data-catalogue" SecDefaultAction "phase:4,pass,log,tag:github_team=data-catalogue" spec: