What's New
Added
- ModSecurity WAF - Web Application Firewall with OWASP Core Rule Set
- New
setup_waf.sh script for easy installation
- Protection against SQL injection, XSS, command injection
- OWASP Top 10 attack prevention
- Custom exclusions for CodeHero (WebSocket, Terminal, Editor, API)
- WAF Setup in Package Manager - Install WAF from web UI
- WAF Documentation - New
docs/WAF_SETUP.md with full setup guide
Security
- ModSecurity 3.x with OWASP CRS 3.3.5 (~2,800 rules)
- Automatic blocking mode enabled
- Protects Admin Panel (9453), Projects (9867), phpMyAdmin (9454)
Install WAF
# Via script
sudo /opt/codehero/scripts/setup_waf.sh
# Or via Package Manager (Dashboard → Packages → WAF Security Setup)
Upgrade
cd /root
wget https://github.com/fotsakir/codehero/releases/latest/download/codehero-2.78.0.zip
unzip codehero-2.78.0.zip
cd codehero
sudo ./upgrade.sh