openapi: 3.2.0 info: title: Cpanel Mod Security API version: 11.137.9999.106 contact: email: cs@cpanel.net name: WebPros International, LLC url: https://cpanel.net/support/ license: name: cPanel License url: https://cpanel.net/legal-notices/ termsOfService: https://cpanel.net/legal-notices/ x-api-evangelist-provenance: 'Harvested verbatim from cPanel''s developer portal on 2026-09-05 via the MCP tool get-full-api-description at https://api.docs.cpanel.net/mcp. ONE mechanical change was made before storage: example values containing PEM private-key or certificate blocks, and AWS-access-key-shaped example strings, were replaced with REDACTED_* placeholders so the file can be stored in a public git repository without tripping secret scanning. No path, operation, parameter, schema or description was altered, added or removed.' description: 'Operations tagged ModSecurity across 2 of this provider''s published API definitions: cpanel-uapi-openapi.yml, cpanel-whm-api-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - description: A server running cPanel. url: https://{host}:{port}/execute variables: host: default: cpanel-server.tld description: The hostname of a server running cPanel. port: default: '2083' description: The cPanel port. - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. security: - BasicAuth: [] tags: - description: The ModSecurity module for UAPI. name: ModSecurity paths: /ModSecurity/disable_all_domains: get: x-readonly: false x-rollback: none description: 'This function disables ModSecurity™ on a cPanel account''s domains. **Important:** When you disable the WebServer role, the system **disables** this function.' operationId: ModSecurity-disable_all_domains parameters: [] responses: '200': content: application/json: schema: properties: apiversion: description: The version of the API. example: 3 type: integer func: description: The name of the method called. example: disable_all_domains type: string module: description: The name of the module called. example: ModSecurity type: string result: properties: data: example: - dependencies: - dallas.com domain: dallas.example.com enabled: 0 searchhint: dallas.com type: sub - dependencies: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com domain: example.com enabled: 0 searchhint: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: main - dependencies: - galveston.com domain: galveston.example.com enabled: 0 searchhint: galveston.com type: sub - dependencies: - houston.com domain: houston.example.com enabled: 0 searchhint: houston.com type: sub - dependencies: - neworleans.com domain: neworleans.example.com enabled: 0 searchhint: neworleans.com type: sub - dependencies: - sanantonio.com domain: sanantonio.example.com enabled: 0 searchhint: sanantonio.com type: sub items: properties: dependencies: description: An array of domains that your changes to a selected domain affect. example: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com items: format: domain type: string type: array domain: description: The cPanel account's domain. example: example.com format: domain type: string enabled: description: 'Whether ModSecurity is enabled on the account. * `1` - Enabled. * `0` - Disabled.' enum: - 0 - 1 example: 0 type: integer exception: description: An exception error message. The function only returns this value if an error occurs. example: An error occurred during the userdata update for domain “example.com”. type: string searchhint: description: A comma-separated list of domain-related search terms. example: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: string type: description: 'The domain type. * `main` - A main domain. * `sub` - A subdomain.' enum: - main - sub example: main type: string type: object type: array errors: description: List of errors if the API failed. example: null items: type: string type: - array - 'null' messages: description: List of messages generated by the API. example: null items: type: string type: - array - 'null' metadata: properties: transformed: description: Post-processing may have transformed the data. enum: - 1 example: 1 type: integer status: description: '- 1 - Success - 0 - Failed: Check the errors field for more details.' enum: - 0 - 1 example: 1 type: integer warnings: description: List of warnings generated by the API. Warnings describe non-critical failures or other problematic conditions noted while running a API. example: null items: type: string type: - array - 'null' type: object type: object description: HTTP Request was successful. summary: Disable ModSecurity for all domains tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "uapi --output=jsonpretty \\\n --user=username \\\n ModSecurity \\\n disable_all_domains\n" - label: URL lang: HTTP source: https://hostname.example.com:2083/cpsess##########/execute/ModSecurity/disable_all_domains - label: LiveAPI Perl lang: Perl source: "#--------------------------------------------------------------------------------------\n# Instructions:\n#--------------------------------------------------------------------------------------\n# is the theme assigned to cPanel account.\n# 1) cd /usr/local/cpanel/base/frontend/\n# 2) mkdir api_examples\n# 3) cd api_examples\n# 4) create a file ModSecurity_disable_all_domains.live.pl and put this code into that file.\n# 5) In your browser login to a cPanel account.\n# 6) Manually change the url from: .../frontend/\n# to .../frontend//api_examples/ModSecurity_disable_all_domains.live.pl\n#--------------------------------------------------------------------------------------\n\nuse strict;\n\nuse Cpanel::LiveAPI ();\n\nmy $cpanel = Cpanel::LiveAPI->new(); # Connect to cPanel - only do this once.\n\n# Print the header\nprint \"Content-type: text/plain\\r\\n\\r\\n\";\n\n# Call the API\nmy $response = $cpanel->uapi(\n q/ModSecurity/,\n q/disable_all_domains/\n);\n\n# Handle the response\nif ($response->{cpanelresult}{result}{status}) {\n my $data = $response->{cpanelresult}{result}{data};\n foreach my $item (@{$data}) {\n # Do something with the $item\n }\n\n # So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n # Report errors:\n print to_json($response->{cpanelresult}{result}{errors});\n}\n\n# Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n#--------------------------------------------------------------------------------------\n# Helper function to convert a perl object to html printable json\n#--------------------------------------------------------------------------------------\nsub to_json {\n require JSON;\n my $str = JSON->new->pretty->encode($_[0]);\n return $str;\n}\n" - label: LiveAPI PHP lang: PHP source: " is the theme assigned to cPanel account.\n// 1) cd /usr/local/cpanel/base/frontend/\n// 2) mkdir api_examples\n// 3) cd api_examples\n// 4) create a file ModSecurity_disable_all_domains.live.php and put this code into that file.\n// 5) In your browser login to a cPanel account.\n// 6) Manually change the url from: .../frontend/\n// to .../frontend//api_examples/ModSecurity_disable_all_domains.live.php\n//--------------------------------------------------------------------------------------\n\n// Instantiate the CPANEL object.\nrequire_once \"/usr/local/cpanel/php/cpanel.php\";\n\n// Print the header\nheader('Content-Type: text/plain');\n\n// Connect to cPanel - only do this once.\n$cpanel = new CPANEL();\n\n// Call the API\n$response = $cpanel->uapi(\n 'ModSecurity',\n 'disable_all_domains'\n);\n\n// Handle the response\nif ($response['cpanelresult']['result']['status']) {\n $data = $response['cpanelresult']['result']['data'];\n foreach ($data as $item) {\n // Do something with the $item\n }\n\n // So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n // Report errors:\n print to_json($response['cpanelresult']['result']['errors']);\n}\n\n// Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n//--------------------------------------------------------------------------------------\n// Helper function to convert a PHP value to html printable json\n//--------------------------------------------------------------------------------------\nfunction to_json($data) {\n return json_encode($data, JSON_PRETTY_PRINT);\n}" x-cpanel-api-version: UAPI x-cpanel-available-version: cPanel 11.46 servers: - description: A server running cPanel. url: https://{host}:{port}/execute variables: host: default: cpanel-server.tld description: The hostname of a server running cPanel. port: default: '2083' description: The cPanel port. /ModSecurity/disable_domains: get: x-readonly: false x-rollback: none description: 'This function disables ModSecurity™ on specified domains. **Important:** When you disable the WebServer role, the system **disables** this function.' operationId: ModSecurity-disable_domains parameters: - description: 'A comma-separated list of domains that the cPanel account owns. **Important:** The authenticated cPanel account **must** own these domains.' in: query name: domains required: true schema: example: example.com,dallas.example.com,galveston.example.com type: string responses: '200': content: application/json: schema: properties: apiversion: description: The version of the API. example: 3 type: integer func: description: The name of the method called. example: disable_domains type: string module: description: The name of the module called. example: ModSecurity type: string result: properties: data: oneOf: - example: - dependencies: - dallas.com domain: dallas.example.com enabled: 0 searchhint: dallas.com type: sub - dependencies: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com domain: example.com enabled: 0 searchhint: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: main - dependencies: - galveston.com domain: galveston.example.com enabled: 0 searchhint: galveston.com type: sub items: properties: dependencies: description: An array of domains that your changes to a selected domain affect. example: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com items: format: domain type: string type: array domain: description: The cPanel account's domain. example: example.com format: domain type: string enabled: description: 'Whether ModSecurity is enabled on the domain. * `1` - Enabled. * `0` - Disabled.' enum: - 0 - 1 example: 1 type: integer exception: description: An exception error message. The function only returns this value if an error occurs. example: An error occurred during the userdata update for domain “example.com”. type: string searchhint: description: A comma-separated list of domain-related search terms. example: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: string type: description: 'The domain type. * `main` - A main domain. * `sub` - A subdomain.' enum: - main - sub example: main type: string type: object type: array - properties: no_domains_provided: description: Indicates caller error on API call. enum: - 1 example: 1 type: integer type: object - properties: invalid_domains: description: List of invalid domains provided by caller. example: - example.invalid items: type: string type: array invalid_domains_provided: description: Indicates caller error on API call. enum: - 1 example: 1 type: integer type: object errors: description: List of errors if the API failed. example: null items: type: string type: - array - 'null' messages: description: List of messages generated by the API. example: null items: type: string type: - array - 'null' metadata: properties: transformed: description: Post-processing may have transformed the data. enum: - 1 example: 1 type: integer status: description: '- 1 - Success - 0 - Failed: Check the errors field for more details.' enum: - 0 - 1 example: 1 type: integer warnings: description: List of warnings generated by the API. Warnings describe non-critical failures or other problematic conditions noted while running a API. example: null items: type: string type: - array - 'null' type: object type: object description: HTTP Request was successful. summary: Disable ModSecurity for selected domains tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "uapi --output=jsonpretty \\\n --user=username \\\n ModSecurity \\\n disable_domains \\\n domains='example.com,dallas.example.com,galveston.example.com'\n" - label: URL lang: HTTP source: https://hostname.example.com:2083/cpsess##########/execute/ModSecurity/disable_domains?domains=example.com%2cdallas.example.com%2cgalveston.example.com - label: LiveAPI Perl lang: Perl source: "#--------------------------------------------------------------------------------------\n# Instructions:\n#--------------------------------------------------------------------------------------\n# is the theme assigned to cPanel account.\n# 1) cd /usr/local/cpanel/base/frontend/\n# 2) mkdir api_examples\n# 3) cd api_examples\n# 4) create a file ModSecurity_disable_domains.live.pl and put this code into that file.\n# 5) In your browser login to a cPanel account.\n# 6) Manually change the url from: .../frontend/\n# to .../frontend//api_examples/ModSecurity_disable_domains.live.pl\n#--------------------------------------------------------------------------------------\n\nuse strict;\n\nuse Cpanel::LiveAPI ();\n\nmy $cpanel = Cpanel::LiveAPI->new(); # Connect to cPanel - only do this once.\n\n# Print the header\nprint \"Content-type: text/plain\\r\\n\\r\\n\";\n\n# Call the API\nmy $response = $cpanel->uapi(\n q/ModSecurity/,\n q/disable_domains/,\n {\n 'domains' => 'example.com,dallas.example.com,galveston.example.com',\n }\n);\n\n# Handle the response\nif ($response->{cpanelresult}{result}{status}) {\n my $data = $response->{cpanelresult}{result}{data};\n # Do something with the $data\n # So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n # Report errors:\n print to_json($response->{cpanelresult}{result}{errors});\n}\n\n# Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n#--------------------------------------------------------------------------------------\n# Helper function to convert a perl object to html printable json\n#--------------------------------------------------------------------------------------\nsub to_json {\n require JSON;\n my $str = JSON->new->pretty->encode($_[0]);\n return $str;\n}\n" - label: LiveAPI PHP lang: PHP source: " is the theme assigned to cPanel account.\n// 1) cd /usr/local/cpanel/base/frontend/\n// 2) mkdir api_examples\n// 3) cd api_examples\n// 4) create a file ModSecurity_disable_domains.live.php and put this code into that file.\n// 5) In your browser login to a cPanel account.\n// 6) Manually change the url from: .../frontend/\n// to .../frontend//api_examples/ModSecurity_disable_domains.live.php\n//--------------------------------------------------------------------------------------\n\n// Instantiate the CPANEL object.\nrequire_once \"/usr/local/cpanel/php/cpanel.php\";\n\n// Print the header\nheader('Content-Type: text/plain');\n\n// Connect to cPanel - only do this once.\n$cpanel = new CPANEL();\n\n// Call the API\n$response = $cpanel->uapi(\n 'ModSecurity',\n 'disable_domains',\n array (\n 'domains' => 'example.com,dallas.example.com,galveston.example.com',\n )\n);\n\n// Handle the response\nif ($response['cpanelresult']['result']['status']) {\n $data = $response['cpanelresult']['result']['data'];\n // Do something with the $data\n // So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n // Report errors:\n print to_json($response['cpanelresult']['result']['errors']);\n}\n\n// Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n//--------------------------------------------------------------------------------------\n// Helper function to convert a PHP value to html printable json\n//--------------------------------------------------------------------------------------\nfunction to_json($data) {\n return json_encode($data, JSON_PRETTY_PRINT);\n}" x-cpanel-api-version: UAPI x-cpanel-available-version: cPanel 11.46 servers: - description: A server running cPanel. url: https://{host}:{port}/execute variables: host: default: cpanel-server.tld description: The hostname of a server running cPanel. port: default: '2083' description: The cPanel port. /ModSecurity/enable_all_domains: get: x-readonly: false x-rollback: none description: 'This function enables ModSecurity™ on a cPanel account''s domains. **Important:** When you disable the WebServer role, the system **disables** this function' operationId: ModSecurity-enable_all_domains parameters: [] responses: '200': content: application/json: schema: properties: apiversion: description: The version of the API. example: 3 type: integer func: description: The name of the method called. example: enable_all_domains type: string module: description: The name of the module called. example: ModSecurity type: string result: properties: data: example: - dependencies: - dallas.com domain: dallas.example.com enabled: 1 searchhint: dallas.com type: sub - dependencies: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com domain: example.com enabled: 1 searchhint: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: main - dependencies: - galveston.com domain: galveston.example.com enabled: 1 searchhint: galveston.com type: sub - dependencies: - houston.com domain: houston.example.com enabled: 1 searchhint: houston.com type: sub - dependencies: - neworleans.com domain: neworleans.example.com enabled: 1 searchhint: neworleans.com type: sub - dependencies: - sanantonio.com domain: sanantonio.example.com enabled: 1 searchhint: sanantonio.com type: sub items: properties: dependencies: description: An array of domains that your changes to a selected domain affect. example: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com items: format: domain type: string type: array domain: description: The cPanel account's domain. example: example.com format: domain type: string enabled: description: 'Whether ModSecurity is enabled on the account. * `1` - Enabled. * `0` - Disabled.' enum: - 0 - 1 example: 0 type: integer exception: description: An exception error message. The function only returns this value if an error occurs. example: An error occurred during the userdata update for domain “example.com”. type: string searchhint: description: A comma-separated list of domain-related search terms. example: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: string type: description: 'The domain type. * `main` - A main domain. * `sub` - A subdomain.' enum: - main - sub example: main type: string type: object type: array errors: description: List of errors if the API failed. example: null items: type: string type: - array - 'null' messages: description: List of messages generated by the API. example: null items: type: string type: - array - 'null' metadata: properties: transformed: description: Post-processing may have transformed the data. enum: - 1 example: 1 type: integer status: description: '- 1 - Success - 0 - Failed: Check the errors field for more details.' enum: - 0 - 1 example: 1 type: integer warnings: description: List of warnings generated by the API. Warnings describe non-critical failures or other problematic conditions noted while running a API. example: null items: type: string type: - array - 'null' type: object type: object description: HTTP Request was successful. summary: Enable ModSecurity for all domains tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "uapi --output=jsonpretty \\\n --user=username \\\n ModSecurity \\\n enable_all_domains\n" - label: URL lang: HTTP source: https://hostname.example.com:2083/cpsess##########/execute/ModSecurity/enable_all_domains - label: LiveAPI Perl lang: Perl source: "#--------------------------------------------------------------------------------------\n# Instructions:\n#--------------------------------------------------------------------------------------\n# is the theme assigned to cPanel account.\n# 1) cd /usr/local/cpanel/base/frontend/\n# 2) mkdir api_examples\n# 3) cd api_examples\n# 4) create a file ModSecurity_enable_all_domains.live.pl and put this code into that file.\n# 5) In your browser login to a cPanel account.\n# 6) Manually change the url from: .../frontend/\n# to .../frontend//api_examples/ModSecurity_enable_all_domains.live.pl\n#--------------------------------------------------------------------------------------\n\nuse strict;\n\nuse Cpanel::LiveAPI ();\n\nmy $cpanel = Cpanel::LiveAPI->new(); # Connect to cPanel - only do this once.\n\n# Print the header\nprint \"Content-type: text/plain\\r\\n\\r\\n\";\n\n# Call the API\nmy $response = $cpanel->uapi(\n q/ModSecurity/,\n q/enable_all_domains/\n);\n\n# Handle the response\nif ($response->{cpanelresult}{result}{status}) {\n my $data = $response->{cpanelresult}{result}{data};\n foreach my $item (@{$data}) {\n # Do something with the $item\n }\n\n # So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n # Report errors:\n print to_json($response->{cpanelresult}{result}{errors});\n}\n\n# Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n#--------------------------------------------------------------------------------------\n# Helper function to convert a perl object to html printable json\n#--------------------------------------------------------------------------------------\nsub to_json {\n require JSON;\n my $str = JSON->new->pretty->encode($_[0]);\n return $str;\n}\n" - label: LiveAPI PHP lang: PHP source: " is the theme assigned to cPanel account.\n// 1) cd /usr/local/cpanel/base/frontend/\n// 2) mkdir api_examples\n// 3) cd api_examples\n// 4) create a file ModSecurity_enable_all_domains.live.php and put this code into that file.\n// 5) In your browser login to a cPanel account.\n// 6) Manually change the url from: .../frontend/\n// to .../frontend//api_examples/ModSecurity_enable_all_domains.live.php\n//--------------------------------------------------------------------------------------\n\n// Instantiate the CPANEL object.\nrequire_once \"/usr/local/cpanel/php/cpanel.php\";\n\n// Print the header\nheader('Content-Type: text/plain');\n\n// Connect to cPanel - only do this once.\n$cpanel = new CPANEL();\n\n// Call the API\n$response = $cpanel->uapi(\n 'ModSecurity',\n 'enable_all_domains'\n);\n\n// Handle the response\nif ($response['cpanelresult']['result']['status']) {\n $data = $response['cpanelresult']['result']['data'];\n foreach ($data as $item) {\n // Do something with the $item\n }\n\n // So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n // Report errors:\n print to_json($response['cpanelresult']['result']['errors']);\n}\n\n// Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n//--------------------------------------------------------------------------------------\n// Helper function to convert a PHP value to html printable json\n//--------------------------------------------------------------------------------------\nfunction to_json($data) {\n return json_encode($data, JSON_PRETTY_PRINT);\n}" x-cpanel-api-version: UAPI x-cpanel-available-version: cPanel 11.46 servers: - description: A server running cPanel. url: https://{host}:{port}/execute variables: host: default: cpanel-server.tld description: The hostname of a server running cPanel. port: default: '2083' description: The cPanel port. /ModSecurity/enable_domains: get: x-readonly: false x-rollback: none description: 'This function enables ModSecurity™ for specified domains. **Important:** When you disable the WebServer role, the system **disables** this function.' operationId: ModSecurity-enable_domains parameters: - description: 'A comma-separated list of domains for which to enable ModSecurity. **Important:** The authenticated cPanel account **must** own these domains.' in: query name: domains required: true schema: example: example.com,dallas.example.com,galveston.example.com type: string responses: '200': content: application/json: schema: properties: apiversion: description: The version of the API. example: 3 type: integer func: description: The name of the method called. example: enable_domains type: string module: description: The name of the module called. example: ModSecurity type: string result: properties: data: oneOf: - example: - dependencies: - dallas.com domain: dallas.example.com enabled: 1 searchhint: dallas.com type: sub - dependencies: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com domain: example.com enabled: 1 searchhint: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: main - dependencies: - galveston.com domain: galveston.example.com enabled: 1 searchhint: galveston.com type: sub items: properties: dependencies: description: An array of domains that your changes to a selected domain affect. example: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com items: format: domain type: string type: array domain: description: The cPanel account's domain. example: example.com format: domain type: string enabled: description: 'Whether ModSecurity is enabled on the domain. * `1` - Enabled. * `0` - Disabled.' enum: - 0 - 1 example: 1 type: integer exception: description: An exception error message. The function only returns this value if an error occurs. example: An error occurred during the userdata update for domain “example.com”. type: string searchhint: description: A comma-separated list of domain-related search terms. example: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: string type: description: 'The domain type. * `main` - A main domain. * `sub` - A subdomain.' enum: - main - sub example: main type: string type: object type: array - properties: no_domains_provided: description: Indicates caller error on API call. enum: - 1 example: 1 type: integer type: object - properties: invalid_domains: description: List of invalid domains provided by caller. example: - example.invalid items: type: string type: array invalid_domains_provided: description: Indicates caller error on API call. enum: - 1 example: 1 type: integer type: object errors: description: List of errors if the API failed. example: null items: type: string type: - array - 'null' messages: description: List of messages generated by the API. example: null items: type: string type: - array - 'null' metadata: properties: transformed: description: Post-processing may have transformed the data. enum: - 1 example: 1 type: integer status: description: '- 1 - Success - 0 - Failed: Check the errors field for more details.' enum: - 0 - 1 example: 1 type: integer warnings: description: List of warnings generated by the API. Warnings describe non-critical failures or other problematic conditions noted while running a API. example: null items: type: string type: - array - 'null' type: object type: object description: HTTP Request was successful. summary: Enable ModSecurity for selected domains tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "uapi --output=jsonpretty \\\n --user=username \\\n ModSecurity \\\n enable_domains \\\n domains='example.com,dallas.example.com,galveston.example.com'\n" - label: URL lang: HTTP source: https://hostname.example.com:2083/cpsess##########/execute/ModSecurity/enable_domains?domains=example.com%2cdallas.example.com%2cgalveston.example.com - label: LiveAPI Perl lang: Perl source: "#--------------------------------------------------------------------------------------\n# Instructions:\n#--------------------------------------------------------------------------------------\n# is the theme assigned to cPanel account.\n# 1) cd /usr/local/cpanel/base/frontend/\n# 2) mkdir api_examples\n# 3) cd api_examples\n# 4) create a file ModSecurity_enable_domains.live.pl and put this code into that file.\n# 5) In your browser login to a cPanel account.\n# 6) Manually change the url from: .../frontend/\n# to .../frontend//api_examples/ModSecurity_enable_domains.live.pl\n#--------------------------------------------------------------------------------------\n\nuse strict;\n\nuse Cpanel::LiveAPI ();\n\nmy $cpanel = Cpanel::LiveAPI->new(); # Connect to cPanel - only do this once.\n\n# Print the header\nprint \"Content-type: text/plain\\r\\n\\r\\n\";\n\n# Call the API\nmy $response = $cpanel->uapi(\n q/ModSecurity/,\n q/enable_domains/,\n {\n 'domains' => 'example.com,dallas.example.com,galveston.example.com',\n }\n);\n\n# Handle the response\nif ($response->{cpanelresult}{result}{status}) {\n my $data = $response->{cpanelresult}{result}{data};\n # Do something with the $data\n # So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n # Report errors:\n print to_json($response->{cpanelresult}{result}{errors});\n}\n\n# Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n#--------------------------------------------------------------------------------------\n# Helper function to convert a perl object to html printable json\n#--------------------------------------------------------------------------------------\nsub to_json {\n require JSON;\n my $str = JSON->new->pretty->encode($_[0]);\n return $str;\n}\n" - label: LiveAPI PHP lang: PHP source: " is the theme assigned to cPanel account.\n// 1) cd /usr/local/cpanel/base/frontend/\n// 2) mkdir api_examples\n// 3) cd api_examples\n// 4) create a file ModSecurity_enable_domains.live.php and put this code into that file.\n// 5) In your browser login to a cPanel account.\n// 6) Manually change the url from: .../frontend/\n// to .../frontend//api_examples/ModSecurity_enable_domains.live.php\n//--------------------------------------------------------------------------------------\n\n// Instantiate the CPANEL object.\nrequire_once \"/usr/local/cpanel/php/cpanel.php\";\n\n// Print the header\nheader('Content-Type: text/plain');\n\n// Connect to cPanel - only do this once.\n$cpanel = new CPANEL();\n\n// Call the API\n$response = $cpanel->uapi(\n 'ModSecurity',\n 'enable_domains',\n array (\n 'domains' => 'example.com,dallas.example.com,galveston.example.com',\n )\n);\n\n// Handle the response\nif ($response['cpanelresult']['result']['status']) {\n $data = $response['cpanelresult']['result']['data'];\n // Do something with the $data\n // So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n // Report errors:\n print to_json($response['cpanelresult']['result']['errors']);\n}\n\n// Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n//--------------------------------------------------------------------------------------\n// Helper function to convert a PHP value to html printable json\n//--------------------------------------------------------------------------------------\nfunction to_json($data) {\n return json_encode($data, JSON_PRETTY_PRINT);\n}" x-cpanel-api-version: UAPI x-cpanel-available-version: cPanel 11.46 servers: - description: A server running cPanel. url: https://{host}:{port}/execute variables: host: default: cpanel-server.tld description: The hostname of a server running cPanel. port: default: '2083' description: The cPanel port. /ModSecurity/has_modsecurity_installed: get: x-readonly: true description: 'This function checks whether ModSecurity™ is installed on a server. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-has_modsecurity_installed parameters: [] responses: '200': content: application/json: schema: properties: apiversion: description: The version of the API. example: 3 type: integer func: description: The name of the method called. example: has_modsecurity_installed type: string module: description: The name of the module called. example: ModSecurity type: string result: properties: data: properties: installed: description: 'Whether ModSecurity is installed on the server. * `1` - Installed. * `0` - Not installed.' enum: - 0 - 1 example: 1 type: integer type: object errors: description: List of errors if the API failed. example: null items: type: string type: - array - 'null' messages: description: List of messages generated by the API. example: null items: type: string type: - array - 'null' metadata: properties: {} status: description: '- 1 - Success - 0 - Failed: Check the errors field for more details.' enum: - 0 - 1 example: 1 type: integer warnings: description: List of warnings generated by the API. Warnings describe non-critical failures or other problematic conditions noted while running a API. example: null items: type: string type: - array - 'null' type: object type: object description: HTTP Request was successful. summary: Return ModSecurity installation status tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "uapi --output=jsonpretty \\\n --user=username \\\n ModSecurity \\\n has_modsecurity_installed\n" - label: URL lang: HTTP source: https://hostname.example.com:2083/cpsess##########/execute/ModSecurity/has_modsecurity_installed - label: LiveAPI Perl lang: Perl source: "#--------------------------------------------------------------------------------------\n# Instructions:\n#--------------------------------------------------------------------------------------\n# is the theme assigned to cPanel account.\n# 1) cd /usr/local/cpanel/base/frontend/\n# 2) mkdir api_examples\n# 3) cd api_examples\n# 4) create a file ModSecurity_has_modsecurity_installed.live.pl and put this code into that file.\n# 5) In your browser login to a cPanel account.\n# 6) Manually change the url from: .../frontend/\n# to .../frontend//api_examples/ModSecurity_has_modsecurity_installed.live.pl\n#--------------------------------------------------------------------------------------\n\nuse strict;\n\nuse Cpanel::LiveAPI ();\n\nmy $cpanel = Cpanel::LiveAPI->new(); # Connect to cPanel - only do this once.\n\n# Print the header\nprint \"Content-type: text/plain\\r\\n\\r\\n\";\n\n# Call the API\nmy $response = $cpanel->uapi(\n q/ModSecurity/,\n q/has_modsecurity_installed/\n);\n\n# Handle the response\nif ($response->{cpanelresult}{result}{status}) {\n my $data = $response->{cpanelresult}{result}{data};\n # Do something with the $data\n # So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n # Report errors:\n print to_json($response->{cpanelresult}{result}{errors});\n}\n\n# Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n#--------------------------------------------------------------------------------------\n# Helper function to convert a perl object to html printable json\n#--------------------------------------------------------------------------------------\nsub to_json {\n require JSON;\n my $str = JSON->new->pretty->encode($_[0]);\n return $str;\n}\n" - label: LiveAPI PHP lang: PHP source: " is the theme assigned to cPanel account.\n// 1) cd /usr/local/cpanel/base/frontend/\n// 2) mkdir api_examples\n// 3) cd api_examples\n// 4) create a file ModSecurity_has_modsecurity_installed.live.php and put this code into that file.\n// 5) In your browser login to a cPanel account.\n// 6) Manually change the url from: .../frontend/\n// to .../frontend//api_examples/ModSecurity_has_modsecurity_installed.live.php\n//--------------------------------------------------------------------------------------\n\n// Instantiate the CPANEL object.\nrequire_once \"/usr/local/cpanel/php/cpanel.php\";\n\n// Print the header\nheader('Content-Type: text/plain');\n\n// Connect to cPanel - only do this once.\n$cpanel = new CPANEL();\n\n// Call the API\n$response = $cpanel->uapi(\n 'ModSecurity',\n 'has_modsecurity_installed'\n);\n\n// Handle the response\nif ($response['cpanelresult']['result']['status']) {\n $data = $response['cpanelresult']['result']['data'];\n // Do something with the $data\n // So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n // Report errors:\n print to_json($response['cpanelresult']['result']['errors']);\n}\n\n// Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n//--------------------------------------------------------------------------------------\n// Helper function to convert a PHP value to html printable json\n//--------------------------------------------------------------------------------------\nfunction to_json($data) {\n return json_encode($data, JSON_PRETTY_PRINT);\n}" x-cpanel-api-version: UAPI x-cpanel-available-version: cPanel 11.46 servers: - description: A server running cPanel. url: https://{host}:{port}/execute variables: host: default: cpanel-server.tld description: The hostname of a server running cPanel. port: default: '2083' description: The cPanel port. /ModSecurity/list_domains: get: x-readonly: true description: 'This function returns ModSecurity''s™ status for a cPanel account''s domains. **Important:** When you disable the WebServer role, the system **disables** this function.' operationId: ModSecurity-list_domains parameters: [] responses: '200': content: application/json: schema: properties: apiversion: description: The version of the API. example: 3 type: integer func: description: The name of the method called. example: list_domains type: string module: description: The name of the module called. example: ModSecurity type: string result: properties: data: example: - dependencies: - dallas.com domain: dallas.example.com enabled: 1 searchhint: dallas.com type: sub - dependencies: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com domain: example.com enabled: 1 searchhint: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: main - dependencies: - galveston.com domain: galveston.example.com enabled: 1 searchhint: galveston.com type: sub - dependencies: - houston.com domain: houston.example.com enabled: 0 searchhint: houston.com type: sub - dependencies: - neworleans.com domain: neworleans.example.com enabled: 0 searchhint: neworleans.com type: sub - dependencies: - sanantonio.com domain: sanantonio.example.com enabled: 0 searchhint: sanantonio.com type: sub items: properties: dependencies: description: An array of domains that your changes to a selected domain affect. example: - arkansas.com - kansas.com - nevada.com - newmexico.com - texas.com items: format: domain type: string type: array domain: description: The cPanel account's domain. example: example.com format: domain type: string enabled: description: 'Whether ModSecurity is enabled for the account. * `1` - Enabled. * `0` - Disabled.' enum: - 0 - 1 example: 1 type: integer searchhint: description: A comma-separated list of domain-related search terms. example: arkansas.com,kansas.com,nevada.com,newmexico.com,texas.com type: string type: description: 'The domain type. * `main` - A main domain. * `sub` - A subdomain.' enum: - main - sub example: main type: string type: object type: array errors: description: List of errors if the API failed. example: null items: type: string type: - array - 'null' messages: description: List of messages generated by the API. example: null items: type: string type: - array - 'null' metadata: properties: modsec: properties: total_disabled: description: The total number of disabled entries. example: 3 type: integer total_enabled: description: The total number of enabled entries. example: 3 type: integer transformed: description: Post-processing may have transformed the data. enum: - 1 example: 1 type: integer status: description: '- 1 - Success - 0 - Failed: Check the errors field for more details.' enum: - 0 - 1 example: 1 type: integer warnings: description: List of warnings generated by the API. Warnings describe non-critical failures or other problematic conditions noted while running a API. example: null items: type: string type: - array - 'null' type: object type: object description: HTTP Request was successful. summary: Return ModSecurity domains' status tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "uapi --output=jsonpretty \\\n --user=username \\\n ModSecurity \\\n list_domains\n" - label: URL lang: HTTP source: https://hostname.example.com:2083/cpsess##########/execute/ModSecurity/list_domains - label: LiveAPI Perl lang: Perl source: "#--------------------------------------------------------------------------------------\n# Instructions:\n#--------------------------------------------------------------------------------------\n# is the theme assigned to cPanel account.\n# 1) cd /usr/local/cpanel/base/frontend/\n# 2) mkdir api_examples\n# 3) cd api_examples\n# 4) create a file ModSecurity_list_domains.live.pl and put this code into that file.\n# 5) In your browser login to a cPanel account.\n# 6) Manually change the url from: .../frontend/\n# to .../frontend//api_examples/ModSecurity_list_domains.live.pl\n#--------------------------------------------------------------------------------------\n\nuse strict;\n\nuse Cpanel::LiveAPI ();\n\nmy $cpanel = Cpanel::LiveAPI->new(); # Connect to cPanel - only do this once.\n\n# Print the header\nprint \"Content-type: text/plain\\r\\n\\r\\n\";\n\n# Call the API\nmy $response = $cpanel->uapi(\n q/ModSecurity/,\n q/list_domains/\n);\n\n# Handle the response\nif ($response->{cpanelresult}{result}{status}) {\n my $data = $response->{cpanelresult}{result}{data};\n foreach my $item (@{$data}) {\n # Do something with the $item\n }\n\n # So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n # Report errors:\n print to_json($response->{cpanelresult}{result}{errors});\n}\n\n# Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n#--------------------------------------------------------------------------------------\n# Helper function to convert a perl object to html printable json\n#--------------------------------------------------------------------------------------\nsub to_json {\n require JSON;\n my $str = JSON->new->pretty->encode($_[0]);\n return $str;\n}\n" - label: LiveAPI PHP lang: PHP source: " is the theme assigned to cPanel account.\n// 1) cd /usr/local/cpanel/base/frontend/\n// 2) mkdir api_examples\n// 3) cd api_examples\n// 4) create a file ModSecurity_list_domains.live.php and put this code into that file.\n// 5) In your browser login to a cPanel account.\n// 6) Manually change the url from: .../frontend/\n// to .../frontend//api_examples/ModSecurity_list_domains.live.php\n//--------------------------------------------------------------------------------------\n\n// Instantiate the CPANEL object.\nrequire_once \"/usr/local/cpanel/php/cpanel.php\";\n\n// Print the header\nheader('Content-Type: text/plain');\n\n// Connect to cPanel - only do this once.\n$cpanel = new CPANEL();\n\n// Call the API\n$response = $cpanel->uapi(\n 'ModSecurity',\n 'list_domains'\n);\n\n// Handle the response\nif ($response['cpanelresult']['result']['status']) {\n $data = $response['cpanelresult']['result']['data'];\n foreach ($data as $item) {\n // Do something with the $item\n }\n\n // So you can see the data shape we print it here.\n print to_json($data);\n}\nelse {\n // Report errors:\n print to_json($response['cpanelresult']['result']['errors']);\n}\n\n// Disconnect from cPanel - only do this once.\n$cpanel->end();\n\n//--------------------------------------------------------------------------------------\n// Helper function to convert a PHP value to html printable json\n//--------------------------------------------------------------------------------------\nfunction to_json($data) {\n return json_encode($data, JSON_PRETTY_PRINT);\n}" x-cpanel-api-version: UAPI x-cpanel-available-version: cPanel 11.46 servers: - description: A server running cPanel. url: https://{host}:{port}/execute variables: host: default: cpanel-server.tld description: The hostname of a server running cPanel. port: default: '2083' description: The cPanel port. /modsec_add_rule: get: description: 'This function adds a new rule to a ModSecurity™ configuration staging file. For example, if you choose to add a rule for the example.conf file, the function stages the rule in the example.conf. STAGE file. **Important:** This function does not actually deploy the rule. To deploy the rule, use the WHM API 1 Functions - modsec_deploy_all_rule_changes function. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_add_rule parameters: - description: The ModSecurity configuration file. in: query name: config required: true schema: example: modsec2.user.conf type: string - description: The rule's text. in: query name: rule required: true schema: example: SecAction "phase:1,id:168,nolog,pass,setvar:tx.REMOTE_ADDR=/%{REMOTE_ADDR}/" type: string responses: '200': content: application/json: schema: properties: data: properties: rule: description: hash that contains information about the new ModSecurity rule. This hash includes the id , rule , disabled , meta_msg , and duplicate returns. properties: config: {} config_active: {} disabled: description: 'Whether the rule is disabled. - 1 Disabled. - 0 Enabled.' enum: - 0 - 1 example: 0 type: integer duplicate: description: 'Whether the rule already exists in the ModSecurity configuration staging file. - 1 Exists. - 0 Does not exist.' enum: - 0 - 1 example: 0 type: integer id: description: The ModSecurity rule's ID. A valid ModSecurity rule ID. example: 168 type: integer meta_msg: description: The ModSecurity rule's description. A valid string. example: Example rule message type: string rule: description: The ModSecurity rule's text. A valid ModSecurity rule. example: SecAction \"phase:1,id:168,nolog,pass,setvar:tx.REMOTE_ADDR=/%{REMOTE_ADDR}/\" type: string staged: {} vendor_active: {} vendor_id: {} type: object type: object metadata: properties: command: description: The method name called. example: modsec_add_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is 0. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` - Success * `0` - Failed: Check the reason field for more details.' enum: - 0 - 1 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Add staged ModSecurity rule tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_add_rule \\\n config='modsec2.user.conf' \\\n rule='SecAction \"phase:1,id:168,nolog,pass,setvar:tx.REMOTE_ADDR=/%{REMOTE_ADDR}/\"'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_add_rule?api.version=1&config=modsec2.user.conf&rule=SecAction%20%22phase%3a1%2cid%3a168%2cnolog%2cpass%2csetvar%3atx.REMOTE_ADDR%3d%2f%25%7bREMOTE_ADDR%7d%2f%22 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_add_vendor: get: description: 'This function adds a new ModSecurity™ vendor rule set to the server. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_add_vendor parameters: - description: The YAML metadata that describes the vendor and how to obtain its rules. in: query name: url required: true schema: example: https://example.com/update/meta_MyVendor.yaml format: url type: string - description: 'Whether to enable the vendor. * `1` — Enabled. * `0` — Disabled.' in: query name: enabled required: false schema: default: 1 enum: - 1 - 0 example: 1 type: integer responses: '200': content: application/json: schema: properties: data: properties: archive_url: description: 'The URL to the vendor''s rule set archive. **Note:** The system will download a set of rules that is compatible with your version of ModSecurity.' example: http://example.com/update/MyVendor.zip format: url type: string cpanel_provided: description: 'Whether WebPros International, LLC provided the vendor. * `1` — cPanel-provided. * `0` — **Not** cPanel-provided.' enum: - 1 - 0 example: 0 type: integer description: description: The vendor's description. example: This is an example of a custom vendor set (updated) type: string dist_md5: description: The download's [MD5](https://en.wikipedia.org/wiki/MD5) checksum value. example: 307cb5320441ebd712e5581d12100dc9 format: md5 type: string dist_sha512: description: The download's [sha512](https://en.wikipedia.org/wiki/SHA-2) hash. example: b55c09bb1835ed4209f0f3ea4a70d099665363f23d3819c0369be429438d675ba2c749dcefdb85cee682ee0bf485558e67d0b0965fe4799865529d943e8e14cb format: sha512 type: string enabled: description: 'Whether the function enabled the vendor. * `1` — Enabled. * `0` — **Not** enabled.' enum: - 1 - 0 example: 1 type: integer inst_dist: description: The rule set's unique identifier. example: MyVendor-2 type: string installed: description: 'Whether the function installed the vendor. * `1` — Installed. * `0` — **Not** installed.' enum: - 1 - 0 example: 1 type: integer installed_from: description: The vendor's metadata file URL. example: https://example.com/update/meta_MyVendor.yaml format: url type: string name: description: The vendor's name. example: My Vendor type: string path: description: The absolute path to the directory that contains the vendor's configuration files. example: /usr/local/apache/conf/modsec_vendor_configs/MyVendor format: path type: string report_url: description: The URL to which the system will send reports. example: https://waf.example.com/api/cpanel_feedback?source=1&rule_set=1.229 format: url type: string supported_versions: description: A list of the ModSecurity versions that the vendor supports. example: - 2.7.5 - 2.7.7 - 2.8.0 - 2.9.0 - 2.9.1 - 2.9.2 - 2.9.3 items: type: string type: array vendor_id: description: The vendor's unique short name. example: MyVendor type: string vendor_url: description: The vendor's website URL. example: http://www.example.com format: url type: string type: object metadata: properties: command: description: The method name called. example: modsec_add_vendor type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Add ModSecurity vendor rules tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_add_vendor \\\n url='https://example.com/update/meta_MyVendor.yaml'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_add_vendor?api.version=1&url=https%3a%2f%2fexample.com%2fupdate%2fmeta_MyVendor.yaml x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_assemble_config_text: get: description: 'This function adds text to a ModSecurity™ configuration file. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_assemble_config_text parameters: - description: The ModSecurity™ configuration filename and file path, relative to the `/etc/apache2/conf/` directory. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string - description: 'Whether to deploy the new text to the system. * `1` — Deploy. * `0` — Do **not** deploy.' in: query name: deploy required: false schema: default: 0 enum: - 1 - 0 example: 1 type: integer - description: 'Whether to add the text as the final upload to the configuration file. * `1` — Final upload. * `0` — **Not** the final upload. **Note:** * You **must** use this parameter if you wish to add the text as the final change to the configuration file. * You **must** use the `init` parameter with this parameter if you wish to only make one change to the configuration file.' in: query name: final required: false schema: default: 0 enum: - 1 - 0 example: 1 type: integer - description: 'Whether to add the text as the initial upload to the configuration file. * `1` — Initial upload. * `0` — **Not** the initial upload. **Note:** * You **must** use this parameter if you wish to add the text as the initial change to the configuration file. * You **must** use the `final` parameter with this parameter if you wish to only make one change to the configuration file.' in: query name: init required: false schema: default: 0 enum: - 1 - 0 example: 1 type: integer - description: The text to add to the configuration file. in: query name: text required: false schema: default: '' example: newtext type: string responses: '200': content: application/json: schema: properties: metadata: properties: command: description: The method name called. example: modsec_assemble_config_text type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Add ModSecurity configuration file text tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_assemble_config_text \\\n config='modsec_vendor_configs/example.conf'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_assemble_config_text?api.version=1&config=modsec_vendor_configs%2fexample.conf x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_batch_settings: get: description: 'This function adds, updates, and removes global ModSecurity™ configuration directives. The function modifies these directives in the `/usr/local/apache/conf/modsec2.cpanel.conf` file. **Important:** When you disable the Web Server role, the system **disables** this function. This function **only** supports the following ModSecurity™ configuration directives: setting_idDocumentation 0SecAuditEngine 1SecConnEngine 2SecRuleEngine 3SecDisableBackendCompression 4SecGeoLookupDb 5SecGsbLookupDb 6SecGuardianLog 7SecHttpBlKey 8SecPcreMatchLimit 9SecPcreMatchLimitRecursion' operationId: ModSecurity-modsec_batch_settings parameters: - description: 'The configuration setting''s ID. **Note:** To configure multiple IDs, increment the parameter name. For example, `setting_id1`, `setting_id2`, and `setting_id3`.' examples: multiple: summary: 'Set or update multiple configuration settings, in this case: SecConnEngine, SecRuleEngine, and SecDisableBackendCompression.' value: setting_id1=1 setting_id2=2 setting_id3=3 single: summary: Set or update a single configuration setting, in this case for SecConnEngine. value: 1 in: query name: setting_id required: true schema: maximum: 9 minimum: 0 type: integer - description: 'The configuration setting''s current state. * `On` * `Off` Some settings accept additional values for this parameter. See the references above for more inforamation. **Note:** * To configure multiple settings, increment the parameter name. For example, `state1`, `state2`, and `state3`. * `state` is ignored if `remove` is set to `1` for the setting.' examples: multiple: summary: Set the state of multiple configuration settings. value: state1=On state2=On state3=Off single: summary: Set the state of a single configuration setting. value: 'On' in: query name: state required: true schema: anyOf: - enum: - 'On' - 'Off' type: string - enum: - 'On' - 'Off' - DetectionOnly type: string - enum: - 'On' - 'Off' - RelevantOnly type: string - type: string - type: integer - description: 'Whether to add or remove the configuration setting in the `/usr/local/apache/conf/modsec2.cpanel.conf` file. * `1` — Remove the configuration setting. * `0` — Add or update the configuration setting. * To remove multiple settings, increment the parameter name. For example, `remove1`, `remove2`, and `remove3`.' examples: multiple: summary: Remove some settings when updating or setting multiple configuration settings. This example removes the second setting indicated in `setting_id2` and updates the other two settings. value: remove1=0 remove2=1 remove3=0 single: summary: Remove a single configuration setting requested in the `setting_id` value: 1 in: query name: remove required: false schema: default: 0 enum: - 1 - 0 example: 0 type: integer responses: '200': content: application/json: schema: properties: data: properties: updated_settings: description: An array of objects that contains the configuration setting's information. items: properties: default: description: 'The setting''s default value. **Note:** The `modsec2.cpanel.conf` file defines this value.' example: 1500 minimum: 1 type: integer description: description: The setting's description. example: define the match limit of the PCRE library. type: string directive: description: The setting's Apache configuration directive. example: SecAuditEngine type: string engine: description: 'Whether the setting is an engine directive. * `1` — Engine directive. * `0` — Normal directive.' enum: - 1 - 0 example: 1 type: integer name: description: The setting's name. example: Audit Log Level type: string radio_options: description: An array of objects that contain the setting's options display information. items: properties: name: description: The option's display name. example: Log all transactions. type: string option: description: The option. example: 'On' type: string type: object type: array setting_id: description: The setting ID. example: 1 minimum: 1 type: integer state: description: The setting's current state, as set by the `state` parameter's input value. example: 'On' type: string type: description: 'The form element that the WHM interface uses to display this setting. * `text` — WHM users modify this setting via a text box. * `radio` — WHM users modify this setting via a radio button. * `number` — WHM users modify this setting via a text box that **only** allows numeric values.' example: radio type: string url: description: The URL of the setting's entry in the ModSecurity reference manual. example: https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#secpcrematchlimit type: string type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_batch_settings type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Run ModSecurity batch settings tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_batch_settings \\\n setting_id='1' \\\n state='On'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_batch_settings?api.version=1&setting_id=1&state=On x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_check_rule: get: description: 'This function checks a ModSecurity™ rule''s validity. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_check_rule parameters: - description: The ModSecurity rule to check. in: query name: rule required: true schema: example: SecAction "pass,id:1234567" type: string responses: '200': content: application/json: schema: properties: data: properties: problem: description: 'A string that describes any errors with the ModSecurity rule. **Note:** The function only returns this value if an error occurred.' example: 'The rule is invalid. Apache returned the following error: AH00526: Syntax error on line 1 of /var/tmp/15500._USR_LOCAL_CPANEL_WHOSTMGR_BIN_XML_API__.gl2t8wZ1.tmp/validate.conf: Invalid command ''''OWASP'''', perhaps misspelled or defined by a module not included in the server configuration ''' type: string valid: description: 'Whether the rule is valid. * `1` — Valid rule. * `0` — Invalid rule.' enum: - 1 - 0 example: 0 type: integer type: object metadata: properties: command: description: The method name called. example: modsec_check_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK Invalid Rule type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Validate ModSecurity rule tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_check_rule \\\n rule='SecAction \"pass,id:1234567\"'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_check_rule?api.version=1&rule=SecAction%20%22pass%2cid%3a1234567%22 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_clone_rule: get: description: 'This function copies a ModSecurity™ rule with a new rule ID. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_clone_rule parameters: - description: The rule's ModSecurity configuration file. in: query name: config required: true schema: example: modsec2.user.conf type: string - description: The existing rule's ID. in: query name: id required: true schema: example: 123456789 minimum: 1 type: integer responses: '200': content: application/json: schema: properties: data: properties: rule: description: A list of information about the cloned ModSecurity rule. properties: config: description: The rule's ModSecurity configuration file. example: modsec2.user.conf type: string config_active: description: 'Whether the configuration file is active. * `1` — Active. * `0` — **Not** active.' enum: - 1 - 0 example: 1 type: integer disabled: description: 'Whether the rule is disabled. * `1` — Disabled. * `0` — Enabled.' enum: - 1 - 0 example: 0 type: integer id: description: The rule's ID number. example: 123456789 minimum: 1 type: integer meta_msg: description: The rule's description. example: Rejected request type: string rule: description: The rule's text that includes the new rule ID. example: SecRule REQUEST_URI "/rejected.php" "deny,auditlog,msg:'Rejected request',id:'1'" type: string staged: description: 'Whether the rule is staged. * `1` — Staged. * `0` — **Not** staged.' enum: - 1 - 0 example: 1 type: integer vendor_active: description: 'Whether the vendor is active. * `1` — Active. * `0` — **Not** active.' enum: - 1 - 0 example: 0 type: integer vendor_id: description: 'The vendor''s unique short name. **Note:** Any rule that does not belong to a vendor rule set will **not** return a value.' example: YourVendor type: string type: object type: object metadata: properties: command: description: The method name called. example: modsec_clone_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Save ModSecurity rule copy tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_clone_rule \\\n config='modsec2.user.conf' \\\n id='123456789'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_clone_rule?api.version=1&config=modsec2.user.conf&id=123456789 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_deploy_all_rule_changes: get: description: 'This function deploys the staged changes for all of the ModSecurity™ configuration files into the live configuration files. After the function deploys the configuration files, it restarts Apache. If the new configuration is invalid, the system restores the original configuration and preserves the staged changes. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_deploy_all_rule_changes parameters: [] responses: '200': content: application/json: schema: properties: data: properties: failed: description: 'The list of configuration files that the system could not deploy. **Note:** The function **only** returns this value if an error occurs.' items: example: modsec_vendor_configs/MyVendor/one.conf type: string type: array outcomes: description: An array of objects containing information about the configuration deployment. items: properties: config: description: 'The file path to the configuration file. * EasyApache 4 — A valid path, relative to the `/etc/apache2/conf.d/modsec/` directory.' example: modsec_vendor_configs/MyVendor/one.conf type: string exception: description: 'The error message for a failed deployment. **Note:** The function only returns this output if an error occurs.' example: 'The system could not deploy changes for modsec_vendor_configs/MyVendor/one.conf: The system could not validate the new Apache configuration, because httpd exited with a nonzero value. Apache produced the following error: httpd: Syntax error on line 37 of /usr/local/apache/conf/httpd.conf: Syntax error on line 26 of /usr/local/apache/conf/modsec2.conf: Syntax error on line 27 of /usr/local/apache/conf/modsec2.cpanel.conf: Could not open configuration file /usr/local/apache/conf/modsec_vendor_configs/MyVendor/one.conf: No such file or directory ' type: string ok: description: 'Whether the rule change deployment succeeded. * `1` — Successful deployment. * `0` — Unsuccessful deployment.' enum: - 1 - 0 example: 0 type: integer type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_deploy_all_rule_changes type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Enable all staged ModSecurity rule changes tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_deploy_all_rule_changes\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_deploy_all_rule_changes?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_deploy_rule_changes: get: description: 'This function deploys staged changes to the ModSecurity™ configuration file and restarts Apache. **Note:** If the new configuration is invalid, the system will restore the original configuration and maintain the staged changes. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_deploy_rule_changes parameters: - description: The ModSecurity configuration file's path and name, relative to the `/usr/local/apache/conf/` directory. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_deploy_rule_changes type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Enable staged ModSecurity rule changes tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_deploy_rule_changes \\\n config='modsec_vendor_configs/example.conf'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_deploy_rule_changes?api.version=1&config=modsec_vendor_configs%2fexample.conf x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_deploy_settings_changes: get: description: 'This function deploys the staged changes to your `modsec2.cpanel.conf` file and attempts to restart Apache. If the new settings fail validation, the system restores the `/etc/apache2/conf.d/modsec/modsec2.cpanel.conf` file. **Note:** Call the WHM API 1 `modsec_set_setting` function to prepare your changes for the `modsec2.cpanel.conf` file. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_deploy_settings_changes parameters: [] responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_deploy_settings_changes type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Enable staged ModSecurity configuration files tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_deploy_settings_changes\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_deploy_settings_changes?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_disable_rule: get: description: 'This function disables a ModSecurity™ rule. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_disable_rule parameters: - description: The ModSecurity configuration file, relative to the `/etc/apache2/conf.d` directory. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string - description: The ModSecurity rule's ID. in: query name: id required: true schema: example: '1234567890' type: string responses: '200': content: application/json: schema: properties: metadata: properties: command: description: The method name called. example: modsec_disable_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Disable ModSecurity rule tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_disable_rule \\\n config='modsec_vendor_configs/example.conf' \\\n id='1234567890'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_disable_rule?api.version=1&config=modsec_vendor_configs%2fexample.conf&id=1234567890 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_disable_vendor: get: description: 'This function disables a ModSecurity™ vendor rule set. **Note:** This function will **not** disable vendor configuration files that you have individually enabled. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_disable_vendor parameters: - description: The vendor's unique short name. in: query name: vendor_id required: true schema: example: SomeVendor type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_disable_vendor type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Disable ModSecurity vendor rules tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_disable_vendor \\\n vendor_id='SomeVendor'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_disable_vendor?api.version=1&vendor_id=SomeVendor x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_disable_vendor_configs: get: description: 'This function disables a ModSecurity™ vendor''s configuration files. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_disable_vendor_configs parameters: - description: The vendor's unique short name. in: query name: vendor_id required: true schema: example: SomeVendor type: string responses: '200': content: application/json: schema: properties: data: properties: outcomes: description: An array of objects containing elements that represent the outcome of each attempt to disable an operation. items: properties: active: description: 'Whether the configuration file is active. * `1` — Active. * `0` — **Not** active.' enum: - 1 - 0 example: 1 type: integer config: description: The configuration file path, relative to the `/usr/local/apache/conf/` directory. example: modsec_vendor_configs/SomeVendor/example.conf type: string exception: description: 'If the function fails to disable the configuration file, this return contains the error message. **Note:** This function only returns a value if an error occurred.' example: This is an error message. type: string ok: description: 'Whether the function successfully disabled the configuration file. * `1` — Disabled. * `0` — Enabled.' enum: - 1 - 0 example: 0 type: integer type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_disable_vendor_configs type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Disable ModSecurity vendor configuration files tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_disable_vendor_configs \\\n vendor_id='SomeVendor'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_disable_vendor_configs?api.version=1&vendor_id=SomeVendor x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_disable_vendor_updates: get: description: 'This function disables automatic updates for a ModSecurity™ vendor. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_disable_vendor_updates parameters: - description: The vendor's unique short name. in: query name: vendor_id required: true schema: example: example type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_disable_vendor_updates type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Disable ModSecurity vendor updates tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_disable_vendor_updates \\\n vendor_id='example'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_disable_vendor_updates?api.version=1&vendor_id=example x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_discard_all_rule_changes: get: description: 'This function discards the staged ModSecurity™ rule changes, if present, for all of the configuration files. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_discard_all_rule_changes parameters: [] responses: '200': content: application/json: schema: properties: data: properties: failed: description: 'The list of configuration files that contain changes that the system could not discard. **Note:** The function **only** returns this value if an error occurs.' items: example: modsec_vendor_configs/MyVendor/one.conf format: path type: string type: array outcomes: description: An array of objects containing information about the discarded configuration changes. items: properties: config: description: 'The file path to the configuration file. * EasyApache 4 — A valid path, relative to the `/etc/apache2/conf.d/modsec/` directory.' example: modsec_vendor_configs/MyVendor/one.conf type: string exception: description: "The error message for a failed discard.\n\n**Note:**\n\n The function only returns this value if an error occurs. The reason for failure." example: 'The system could not remove the file /usr/local/apache/conf/modsec_vendor_configs/MyVendor/one.conf.STAGE: Invalid argument ' type: string ok: description: 'Whether the system successfully discarded the rule change. * `1` — Success. * `0` — Failure.' enum: - 1 - 0 example: 0 type: integer type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_discard_all_rule_changes type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Remove all staged ModSecurity rule changes tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_discard_all_rule_changes\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_discard_all_rule_changes?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_discard_rule_changes: get: description: 'This function discards staged rule changes for a ModSecurity™ configuration file. Staged rule changes reside in a `.STAGE` file (for example, the staged changes for the `example.conf` file exist in the `example.conf.STAGE` file). This function deletes the `.STAGE` file that corresponds to the configuration file that you specify. **Note:** To stage rule changes, call WHM API 1''s `modsec_add_rule` function. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_discard_rule_changes parameters: - description: The ModSecurity configuration file in the `/usr/local/cpanel/apache/conf/` directory. in: query name: config required: true schema: example: modsec2.example.conf type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_discard_rule_changes type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Remove staged ModSecurity rule changes tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_discard_rule_changes \\\n config='modsec2.example.conf'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_discard_rule_changes?api.version=1&config=modsec2.example.conf x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_edit_rule: get: description: 'This function stages edits to a ModSecurity™ rule. The system does **not** save changes directly to the configuration file. Instead, it stages the changes to the configuration file''s `.STAGE` file (for example, for the `example.conf` file, the system stages changes in the `example.conf.STAGE` file). **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_edit_rule parameters: - description: The ModSecurity configuration file, relative to the `/usr/local/apache/conf/` directory. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string - description: The ModSecurity rule's ID. in: query name: id required: true schema: example: 1234567 type: integer - description: The new ModSecurity rule. in: query name: rule required: true schema: example: SecAction "pass,id:1234567" type: string responses: '200': content: application/json: schema: properties: data: properties: rule: description: A list of information about the new ModSecurity rule. properties: disabled: description: 'Whether the ModSecurity rule is disabled. * `1` — Disabled. * `0` — Enabled.' enum: - 1 - 0 example: 0 type: integer id: description: The ModSecurity rule's ID. example: 1234567 minimum: 1 type: integer meta_msg: description: The ModSecurity rule's description, if one exists. example: '' type: string rule: description: The ModSecurity rule's text. example: SecAction "pass,id:1234567" type: string type: object type: object metadata: properties: command: description: The method name called. example: modsec_edit_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Update staged ModSecurity rule tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_edit_rule \\\n config='modsec_vendor_configs/example.conf' \\\n id='1234567' \\\n rule='SecAction \"pass,id:1234567\"'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_edit_rule?api.version=1&config=modsec_vendor_configs%2fexample.conf&id=1234567&rule=SecAction%20%22pass%2cid%3a1234567%22 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_enable_vendor: get: description: 'This function enables a ModSecurity™ vendor rule set. **Note:** This function will **not** enable vendor configuration files that you individually disable. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_enable_vendor parameters: - description: The vendor's unique short name. in: query name: vendor_id required: true schema: example: SomeVendor type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_enable_vendor type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Enable ModSecurity vendor rules tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_enable_vendor \\\n vendor_id='SomeVendor'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_enable_vendor?api.version=1&vendor_id=SomeVendor x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_enable_vendor_configs: get: description: 'This function enables a ModSecurity™ vendor''s configuration files. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_enable_vendor_configs parameters: - description: The vendor's unique short name. in: query name: vendor_id required: true schema: example: SomeVendor type: string responses: '200': content: application/json: schema: properties: data: properties: outcomes: description: An array of objects containing elements that represent the outcome of each attempt to enable operation. items: properties: active: description: 'Whether the configuration file is active. * `1` — Active. * `0` — **Not** active.' enum: - 1 - 0 example: 1 type: integer config: description: The configuration file path, relative to the `/usr/local/apache/conf/` directory. example: modsec_vendor_configs/SomeVendor/example.conf type: string exception: description: 'If the function fails to enable the configuration file, this return contains the error message. **Note:** The function **only** returns a value if an error occurred.' example: This is an error message. type: string ok: description: 'Whether the function successfully enabled the configuration file. * `1` — Enabled. * `0` — Disabled.' enum: - 1 - 0 example: 1 type: integer type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_enable_vendor_configs type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Enable ModSecurity vendor configuration files tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_enable_vendor_configs \\\n vendor_id='SomeVendor'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_enable_vendor_configs?api.version=1&vendor_id=SomeVendor x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_enable_vendor_updates: get: description: 'This function enables automatic updates for a ModSecurity™ vendor. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_enable_vendor_updates parameters: - description: The vendor's unique short name. in: query name: vendor_id required: true schema: example: example type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_enable_vendor_updates type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Enable ModSecurity vendor updates tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_enable_vendor_updates \\\n vendor_id='example'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_enable_vendor_updates?api.version=1&vendor_id=example x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_get_config_text: get: description: 'This function retrieves a ModSecurity™ configuration file''s contents. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_get_config_text parameters: - description: The ModSecurity configuration file's name. in: query name: config required: true schema: example: modsec2.example.conf type: string responses: '200': content: application/json: schema: properties: data: properties: text: description: The ModSecurity configuration file's contents. example: SecRule REQUEST_URI "example" "deny:id:123456789" SecAction "pass:auditlog:id:444444444" type: string type: object metadata: properties: command: description: The method name called. example: modsec_get_config_text type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return ModSecurity configuration file tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_get_config_text \\\n config='modsec2.example.conf'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_get_config_text?api.version=1&config=modsec2.example.conf x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_get_configs: get: description: 'This function lists ModSecurity™ configuration files. The system stores the configuration files in the `/usr/local/apache/conf/modsec_vendor_configs` directory. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_get_configs parameters: [] responses: '200': content: application/json: schema: properties: data: properties: configs: description: An array of objects containing information about ModSecurity configuration files. items: properties: active: description: 'Whether the configuration file is active. * `1` — Active. * `0` — **Not** active. **Note:** The file is active if an include for the configuration file appears in the `modsec2.cpanel.conf` file.' enum: - 1 - 0 example: 1 type: integer config: description: The configuration file's location, relative to the `/usr/local/apache/conf` directory. example: modsec_vendor_configs/MyVendor/one.conf type: string vendor_id: description: The vendor's unique short name. example: MyVendor type: string type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_get_configs type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return all ModSecurity configuration files tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_get_configs\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_get_configs?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_get_configs_with_changes_pending: get: description: 'This function lists the ModSecurity™ configuration files that have staged changes. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_get_configs_with_changes_pending parameters: [] responses: '200': content: application/json: schema: properties: data: properties: configs: description: An array of strings containing one or more ModSecurity configuration files. example: - modsec2.user.conf - modsec2.user1.conf - modsec2.user2.conf items: type: string type: array type: object metadata: properties: command: description: The method name called. example: modsec_get_configs_with_changes_pending type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return staged ModSecurity configuration files tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_get_configs_with_changes_pending\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_get_configs_with_changes_pending?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_get_log: get: description: 'This function retrieves ModSecurity™ log entries from the modsec MySQL® database. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_get_log parameters: [] responses: '200': content: application/json: schema: properties: data: description: An array of objects that contains information about the log entry. items: properties: action_desc: description: The web server's response to the client. example: Access denied with code 406 (phase 1). type: string file_exists: description: 'Whether the file in the `meta_file` return exists. * `1` — The file exists. * `0` — The files does **not** exist.' enum: - 1 - 0 example: 1 type: integer handler: description: This parameter **only** returns the `null` value. example: null type: - string - 'null' host: description: The virtual host's (vhost) domain name. example: server.example.com type: string http_method: description: 'The [HTTP method](http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html) that the client used to generate the hit.' example: GET type: string http_status: description: 'The [HTTP status code](http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html) that the web server returned.' example: 406 type: integer http_version: description: The HTTP version number. example: HTTP/1.1 type: string id: description: The line number from the `modsec` database. example: 28 minimum: 1 type: integer ip: description: The client's IP address. example: 10.1.14.77 format: ipv4 type: string justification: description: The specific criteria from the ModSecurity rule that generated the hit. example: Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. type: string meta_file: description: The ModSecurity configuration file with the rule that triggered the log entry. example: /usr/local/apache/conf/modsec_vendor_configs/OWASP/base_rules/modsecurity_crs_30_http_policy.conf type: string meta_id: description: The ID of the ModSecurity rule that triggered the log entry. example: 960032 type: integer meta_line: description: The ModSecurity rule's line number that triggered the log entry. example: 31 minimum: 1 type: integer meta_logdata: description: The transaction data fragment from the ModSecurity rule's logdata action. example: GET type: - string - 'null' meta_msg: description: The human-readable message from the ModSecurity rule's `msg` action. example: Method is not allowed by policy type: string meta_offset: description: 'The byte offset at which a match occurred within the target data. **Note:** This data is not always available.' example: 0 type: integer meta_rev: description: The revision number from the ModSecurity rule's `rev` action. example: 2 type: - integer - 'null' meta_severity: description: The hit severity level from the ModSecurity rule's `severity` action. example: CRITICAL type: - string - 'null' meta_uri: description: 'The client-requested URI. **Note:** This data is not always available.' example: null format: uri type: - string - 'null' path: description: The accessed file's absolute path and filename. example: /favicon.ico type: string reportable: description: 'Whether the system can report the rule to the vendor. * `1` — Report the rule to the vendor. * `0` — Do **not** report the rule to the vendor. **Note:** The vendor **must** have configured a report URL in order to report a rule.' enum: - 1 - 0 example: 1 type: integer timestamp: description: 'When the system recorded the log entry, in `YYYY-MM-DD HH:mm:SS` format. **Note:** This value uses the server''s configured time zone.' example: '2019-10-13T07:58:04.000Z' format: ISO-8601 Date Time type: string timezone: description: The server's configured timezone, in minutes difference UTC/GMT format. example: -300 type: integer type: object type: array metadata: properties: command: description: The method name called. example: modsec_get_log type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return ModSecurity logs tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_get_log\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_get_log?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_get_rules: get: description: 'This function retrieves the ModSecurity™ rules from one or more ModSecurity configuration files. **Important:** * When you disable the Web Server role, the system disables this function. * You **must** include either the `vendor_id` **or** the `config` parameters.' operationId: ModSecurity-modsec_get_rules parameters: - description: 'The file path to the configuration file, relative to the `/usr/local/apache/conf` directory. **Note:** You can use a comma-delimited list for multiple configuration files.' examples: multiple: summary: Call multiple configuration files. value: modsec_vendor_configs/SomeVendor/config.conf,modsec_vendor_configs/AnotherVendor/config.conf single: summary: Call a single configuration file. value: modsec_vendor_configs/SomeVendor/config.conf in: query name: config required: false schema: type: string - description: 'Whether to exclude comments that are not associated with any directives. * `1` — Exclude. * `0` — Do **not** exclude.' in: query name: exclude_bare_comments required: false schema: default: 1 enum: - 1 - 0 example: 1 type: integer - description: 'Whether the function only returns the `SecRule` and `SecAction` directives from the configuration file, and comments that are not associated with a rule. * `1` — Only return the `SecRule` and `SecAction` directives and comments **not** associated with a rule. * `0` — Return **all** directives and comments.' in: query name: exclude_other_directives required: false schema: default: 1 enum: - 1 - 0 example: 1 type: integer - description: 'The vendor''s unique short name. **Note:** You can use a comma-delimited list for multiple vendors.' examples: multiple: summary: Call multiple vendors. value: vendor=SomeVendor,AnotherVendor single: summary: Call a single vendor. value: SomeVendor in: query name: vendor_id required: false schema: type: string responses: '200': content: application/json: schema: properties: data: properties: chunks: description: An array of objects that contains elements that represent the contents of each configuration file's rules. items: properties: config: description: The file path to the configuration file, relative to the `/usr/local/apache/conf/` directory. example: modsec_vendor_configs/SomeVendor/config.conf type: string config_active: description: 'Whether the configuration file is active. * `1` — Active. * `0` — **Not** active.' enum: - 1 - 0 example: 0 type: integer disabled: description: 'Whether the rule is active. * `1` — **Not** Active. * `0` — Active.' enum: - 1 - 0 example: 0 type: integer id: description: 'The ModSecurity rule''s ID number. **Note:** The function does not always return this parameter.' example: 662452 minimum: 1 type: integer meta_msg: description: The description of the rule. example: Denied dangerous config traffic type: string rule: description: 'The rule''s text. **Note:** This return may include multiple directives and comments if they are all part of the same rule.' example: SecRule REQUEST_FILENAME "config" "deny,id:662452,msg:'Denied dangerous config traffic',severity:1,auditlog" type: string staged: description: 'Whether the system has added the rule to the ModSecurity configuration file. * `1` — Rule staged. * `0` — Rule **not** staged.' enum: - 1 - 0 example: 0 type: integer vendor_active: description: 'Whether the vendor is active. * `1` — Active. * `0` — **Not** active.' enum: - 1 - 0 example: 0 type: integer vendor_id: description: The vendor's unique short name. example: SomeVendor type: string type: object type: array staged_changes: description: 'Whether the chunks array includes staged changes that the system has not yet added to the ModSecurity configuration file. * `1` — Staged changes in output. * `0` — **No** staged changes in output.' enum: - 1 - 0 example: 0 type: integer type: object metadata: properties: command: description: The method name called. example: modsec_get_rules type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return ModSecurity rules tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_get_rules\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_get_rules?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_get_settings: get: description: 'This function retrieves the server''s ModSecurity™ configuration settings. The system stores these settings in the `/usr/local/apache/conf/modsec2.conf` file. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_get_settings parameters: [] responses: '200': content: application/json: schema: properties: data: properties: settings: description: An array of objects containing ModSecurity global configuration settings. example: - default: 'Off' description: This setting controls the behavior of the audit engine. directive: SecAuditEngine engine: 1 missing: 1 name: Audit Log Level radio_options: - name: Log all transactions. option: 'On' - name: Do not log any transactions. option: 'Off' - name: Only log noteworthy transactions. option: RelevantOnly setting_id: 0 state: '' type: radio url: https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#secauditengine - description: Specify an external program to pipe transaction log information to for additional analysis. The syntax is analogous to the .forward file, in which a pipe at the beginning of the field indicates piping to an external program. directive: SecGuardianLog missing: 1 name: Guardian Log setting_id: 6 state: '' type: text url: https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#secguardianlog validation: - arg: '[|]' name: startsWith - path items: properties: default: description: The setting's default value. oneOf: - type: string - minimum: 0 type: integer description: description: 'The setting''s description. The user''s [locale](https://go.cpanel.net/locale) may translate this value.' type: string directive: description: The setting's Apache® configuration directive. type: string engine: description: 'Whether the setting is an engine directive. If the setting is a normal directive, the function does **not** return this value. * `1` — Engine directive.' enum: - 1 type: integer missing: description: 'Whether the setting is missing. * `1` — The value is missing.' enum: - 1 type: integer name: description: The setting's name. type: string radio_options: description: 'An array of objects containing the options that the client should display, as radio buttons, for this setting in a user interface. **Note:** The function **only** returns this value when the `type` parameter is the `radio` values.' items: properties: name: description: 'The setting name to display to the user. The user''s [locale](https://go.cpanel.net/locale) may translate this value.' type: string option: description: 'The setting that the system used to select the setting''s state. **Note:** This value is identical to the string that the client sends in as the `state` value when users select the specified setting. In most cases, you should **not** display this value to the user. Instead, display the `name` value.' type: string type: object type: array setting_id: description: The setting ID. minimum: 0 type: integer state: description: The setting's current state, if available. type: string type: description: 'The form element that the WHM interface uses to display this setting. * `text` — WHM users modify this setting via a text box. * `radio` — WHM users modify this setting via a radio button. * `number` — WHM users modify this setting via a text box that only allows numeric values.' enum: - text - radio - number type: string url: description: The URL of the setting's entry in the ModSecurity reference manual. format: url type: string validation: description: 'A list of validators to apply when updating the state. Use these validators to perform frontend validation through your preferred implementation methods. **Note:** The function may represent each validator as either a string or an object. * When the function represents the validator as a string, no arguments exist for the validator. * When the function returns the validator as a object, the API may also include an argument for the validator.' items: anyOf: - description: An object that contains the validation rule and arguments. properties: arg: description: The regular expression pattern that is used with the validator identified in the `name` property. type: string name: description: 'One of the following validators: * `startsWith` - Check if the updated `state` starts with the pattern passed in `arg`.' enum: - startsWith - endsWith type: string type: object - description: 'One of the following validators: * `path` — An instruction to verify whether the user''s input is a valid path. * `honeypotAccessKey` — An instruction to verify whether the user''s input fits the constraints of an `Http:BL` API access key. * `positiveInteger` — An instruction to verify whether the user''s input is a positive integer.' enum: - path - honeypotAccessKey - positiveInteger type: string type: array type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_get_settings type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return ModSecurity configuration tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_get_settings\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_get_settings?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_get_vendors: get: description: 'The function returns a list of configured ModSecurity™ vendors. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_get_vendors parameters: [] responses: '200': content: application/json: schema: properties: data: properties: vendors: description: An array of objects that represent the list of configured vendors on the system. items: properties: archive_url: description: The URL to download the vendor rules. example: http://www.example.com/SAMPLE_1415038544.zip format: url type: string configs: description: A list of information about the configuration files that the vendor provides. example: - active: 1 config: modsec_vendor_configs/SAMPLE/modsecurity_crs_10_setup.conf vendor_id: SAMPLE - active: 0 config: modsec_vendor_configs/SAMPLE/optional_rules/modsecurity_crs_16_session_hijacking.conf vendor_id: SAMPLE - active: 1 config: modsec_vendor_configs/SAMPLE/optional_rules/modsecurity_crs_46_av_scanning.conf vendor_id: SAMPLE items: properties: active: description: 'Whether the configuration is active. * `1` — Active. * `0` — Inactive.' enum: - 1 - 0 example: 1 type: integer config: description: The configuration file path, relative to the `/usr/local/apache/conf` directory. example: modsec_vendor_configs/SAMPLE/slr_rules/modsecurity_crs_46_slr_et_joomla_attacks.conf type: string vendor_id: description: The vendor's unique short name. example: SAMPLE type: string type: object type: array cpanel_provided: description: 'Whether cPanel & WHM installed the vendor rule set. * `1` — Installed. * `0` — **Not** installed.' enum: - 1 - 0 example: 0 type: integer description: description: The ModSecurity vendor's description. example: A SAMPLE-curated ModSecurity rule set. type: string dist_md5: description: 'The download''s [MD5](https://en.wikipedia.org/wiki/MD5) checksum value.' example: ffbaa3a7ead8dfaf0b661a729ce6ad3b type: string dist_sha512: description: The download's [sha512](https://en.wikipedia.org/wiki/SHA-2) hash. example: b55c09bb1835ed4209f0f3ea4a70d099665363f23d3819c0369be429438d675ba2c749dcefdb85cee682ee0bf485558e67d0b0965fe4799865529d943e8e14cb type: string enabled: description: 'Whether the vendor is enabled. * `1` — Enabled. * `0` — Disabled.' enum: - 1 - 0 example: 1 type: integer in_use: description: The number of configuration files in the vendor rule set. example: 32 minimum: 0 type: integer inst_dist: description: The rule set version's unique identifier. example: SAMPLE_1415038544 type: string installed: description: 'Whether the vendor is installed. * `1` — Installed. * `0` — **Not** installed.' enum: - 1 - 0 example: 1 type: integer installed_from: description: The URL to the vendor's metadata file. example: http://www.example.com/meta_SAMPLE.yaml type: string name: description: The vendor's name. example: SAMPLE ModSecurity Core Rule Set type: string path: description: The full path to the vendor's ModSecurity configuration files. example: /usr/local/apache/conf/modsec_vendor_configs/SAMPLE type: string report_url: description: 'The URL of the vendor''s Report Receiver API endpoint that reports problems with the vendor''s rules. **Note:** The function may not always return this parameter.' example: https://www.example.com/report format: url type: string supported_versions: description: A list of the ModSecurity versions that the vendor supports. example: - 2.9.1 - 2.9.2 - 2.9.3 items: type: string type: array update: description: 'Whether the vendor rule set can receive automatic updates. * `1` — Can receive automatic updates. * `0` — **Cannot** receive automatic updates.' enum: - 1 - 0 example: 1 type: integer vendor_id: description: The vendor's unique short name. example: SAMPLE type: string vendor_url: description: The URL of the vendor's website. example: https://www.example.com/index.php/Category:SAMPLE_ModSecurity_Core_Rule_Set_Project format: url type: string type: object type: array type: object metadata: properties: command: description: The method name called. example: modsec_get_vendors type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return ModSecurity vendors tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_get_vendors\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_get_vendors?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_is_installed: get: description: 'This function checks whether the ModSecurity™ module is installed. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_is_installed parameters: [] responses: '200': content: application/json: schema: properties: data: properties: data: properties: installed: description: 'Whether ModSecurity is installed on the server. * `1` — Installed. * `0` — **Not** installed.' enum: - 0 - 1 example: 1 type: integer type: object type: object metadata: properties: command: description: The method name called. example: modsec_is_installed type: string reason: description: 'The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds.' example: OK type: string result: description: '* `1` — Success * `0` — Failed. Check the `reason` field for more details.' enum: - 0 - 1 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return ModSecurity module status tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_is_installed\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_is_installed?api.version=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_make_config_active: get: description: 'This function adds an include for a ModSecurity™ configuration file to the `modsec2.cpanel.conf` file. This makes the ModSecurity configuration file active. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_make_config_active parameters: - description: The ModSecurity configuration file's path and filename, relative to the `/usr/local/apache/conf/` diretory. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_make_config_active type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Add ModSecurity configuration file include tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_make_config_active \\\n config='modsec_vendor_configs/example.conf'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_make_config_active?api.version=1&config=modsec_vendor_configs%2fexample.conf x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_make_config_inactive: get: description: 'This function removes an include for a ModSecurity™ configuration file from the `modsec2.cpanel.conf` file. This makes the ModSecurity configuration file inactive. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_make_config_inactive parameters: - description: The ModSecurity configuration file's path and filename, relative to the `/etc/apache2/conf.d/` directory. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_make_config_inactive type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Remove ModSecurity configuration file include tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_make_config_inactive \\\n config='modsec_vendor_configs/example.conf'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_make_config_inactive?api.version=1&config=modsec_vendor_configs%2fexample.conf x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_preview_vendor: get: description: 'This function returns the metadata for a ModSecurity™ vendor rule set. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_preview_vendor parameters: - description: 'The YAML metadata''s URL, which describes the vendor and how to obtain its rules. **Note:** * The file uses YAML format. * The filename **must** use the `meta_` prefix. * The filename **must** match the `vendor_id` value for your vendor. * The filename **must** end with the `.yaml` extension.' in: query name: url required: true schema: example: https://www.example.com/vendor1rules/meta_vendor1.yaml format: url type: string responses: '200': content: application/json: schema: properties: data: properties: archive_url: description: The URL to the vendor's rule set archive. example: https://www.example.com/vendor1.zip format: url type: string cpanel_provided: description: 'Whether WebPros International, LLC provided the vendor. * `1` — cPanel-provided. * `0` — **Not** cPanel-provided.' enum: - 1 - 0 example: 0 type: integer description: description: The vendor's description. example: This is the Vendor1 ModSecurity Core Rule Set. type: string dist_md5: description: The download's [MD5](https://en.wikipedia.org/wiki/Md5) checksum value. example: 307cb5320441ebd712e5581d12100dc9 type: string dist_sha512: description: The download's [sha512](https://en.wikipedia.org/wiki/SHA-2) hash. example: b55c09bb1835ed4209f0f3ea4a70d099665363f23d3819c0369be429438d675ba2c749dcefdb85cee682ee0bf485558e67d0b0965fe4799865529d943e8e14cb type: string installed: description: 'Whether the vendor is installed. * `1` — Installed. * `0` — **Not** installed.' enum: - 1 - 0 example: 1 type: integer installed_from: description: The vendor's metadata file URL. example: https://www.example.com/vendor1rules/meta_vendor1.yaml format: url type: string name: description: The vendor's name. example: Vendor1 ModSecurity Core Rule Set type: string path: description: The absolute path to the directory that contains the vendor's configuration files. example: /usr/local/apache/conf/modsec_vendor_configs/vendor1 type: string report_url: description: The URL to which the system will send reports. example: https://waf.example.com/api/cpanel_feedback?source=1&rule_set=1.229 format: url type: string supported_versions: description: A list of the ModSecurity versions that the vendor supports. example: - 2.9.1 - 2.9.2 - 2.9.3 items: type: string type: array vendor_id: description: The vendor's unique short name. example: vendor1 type: string vendor_url: description: The vendor's website URL. example: http://www.example.com format: url type: string type: object metadata: properties: command: description: The method name called. example: modsec_preview_vendor type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Return ModSecurity vendor rule metadata tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_preview_vendor \\\n url='https://www.example.com/vendor1rules/meta_vendor1.yaml'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_preview_vendor?api.version=1&url=https%3a%2f%2fwww.example.com%2fvendor1rules%2fmeta_vendor1.yaml x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_remove_rule: get: description: 'This function removes a rule from a ModSecurity™ configuration file. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_remove_rule parameters: - description: The ModSecurity configuration file's path and filename, relative to the `/usr/local/apache/conf/` directory. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string - description: The rule's ID. in: query name: id required: true schema: example: 1234567890 minimum: 1 type: integer responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_remove_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Remove ModSecurity rule tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_remove_rule \\\n config='modsec_vendor_configs/example.conf' \\\n id='1234567890'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_remove_rule?api.version=1&config=modsec_vendor_configs%2fexample.conf&id=1234567890 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_remove_setting: get: description: 'This function removes a global ModSecurity™ configuration directive. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_remove_setting parameters: - description: The setting's ID. For a list of available settings and their IDs, call the `modsec_get_settings` function. in: query name: setting_id required: true schema: example: 3 type: integer responses: '200': content: application/json: schema: properties: data: properties: {} metadata: properties: command: description: The method name called. example: modsec_remove_setting type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Remove ModSecurity configuration tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_remove_setting \\\n setting_id='3'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_remove_setting?api.version=1&setting_id=3 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_remove_vendor: get: description: 'This function removes a ModSecurity™ vendor. When you call this function, the system removes the vendor''s includes, disablement directives, configuration files, and metadata file. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_remove_vendor parameters: - description: The ModSecurity vendor's unique short name. in: query name: vendor_id required: true schema: example: SomeVendor type: string responses: '200': content: application/json: schema: properties: metadata: properties: command: description: The method name called. example: modsec_remove_vendor type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Remove ModSecurity vendor tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_remove_vendor \\\n vendor_id='SomeVendor'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_remove_vendor?api.version=1&vendor_id=SomeVendor x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_report_rule: get: description: 'This function submits ModSecurity™ rule error reports to a remote receiver. The third party rule vendors use these error reports to identify problems with their rule sets. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_report_rule parameters: - description: The contact email address to send with the error report. This allows the rule's vendor to reply to the user directly. in: query name: email required: true schema: example: john.doe@example.com format: email type: string - description: A short message that explains the reason for the report. in: query name: message required: true schema: example: 'Hi. We''re having some trouble with this rule. It seems to be blocking all requests.' type: string - description: 'The MySQL® row IDs from the `hits` table in the `modsec` database for the audit log event to report. **Note:** If you specify more than one row ID: * You **must** comma-separate the rule IDs. * The rule IDs **must** all correspond to the same ModSecurity rule.' examples: multiple: summary: Report multiple row IDs. value: 794828, 794829, 794820 single: summary: Report a single row ID. value: 794828 explode: false in: query name: row_ids required: true schema: type: integer style: form - description: 'Whether the function sends the report to the rule''s vendor. * `1` — Send the report. * `0` — Do **not** send the report.' in: query name: send required: true schema: enum: - 1 - 0 example: 1 type: integer - description: 'The report''s type. **Note:** This value does **not** use a specified format. Treat the value as freeform text.' in: query name: type required: true schema: example: false positive type: string responses: '200': content: application/json: schema: properties: data: properties: report: description: An array of objects containing information for the report. items: properties: email: description: The contact email address to send with the error report. This allows the rule's vendor to reply to the report directly. example: john.doe@example.com format: email type: string hits: description: An array of objects containing information about the hit. items: properties: action_desc: description: The web server's response to the client. example: Access denied with code 406 (phase 2). type: string handler: description: This parameter only returns a `null` value. example: null type: - string - 'null' host: description: The virtual host's (vhost) domain name. example: example.com format: domain type: string http_method: description: 'The [HTTP method](http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html) that the client used to generate the hit.' example: GET type: string http_status: description: 'The [HTTP status code](http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html) that the web server returned.' example: 406 type: integer http_version: description: The HTTP version number. example: HTTP/1.1 type: string id: description: The `modsec` database line number. example: 794828 minimum: 1 type: integer ip: description: The client's IP address. example: 10.215.215.236 format: ipv4 type: string justification: description: The specific criteria from the ModSecurity rule that generated the hit. example: Unconditional match in SecAction. type: string meta_file: description: The ModSecurity configuration file that contains the rule that triggered the log entry. example: /usr/local/apache/conf/modsec_vendor_configs/MyVendor/one.conf type: string meta_id: description: The ID of the ModSecurity rule that triggered the log entry. example: 12345694 type: integer meta_line: description: The line number of the ModSecurity rule that triggered the log entry. example: 1 minimum: 1 type: integer meta_logdata: description: The transaction data fragment from the ModSecurity rule's `logdata` action. example: null type: - string - 'null' meta_msg: description: The human-readable message from the ModSecurity rule's `msg` action. example: Method is not allowed by policy type: - string - 'null' meta_offset: description: 'The byte offset at which a match occurred within the target data. **Note:** This data is not always available.' example: 0 minimum: 0 type: integer meta_rev: description: The revision number from the ModSecurity rule's `rev` action. example: 1 minimum: 1 type: - integer - 'null' meta_severity: description: 'The hit severity level from the ModSecurity rule''s `severity` action. * `ALERT` * `CRITICAL` * `DEBUG` * `EMERGENCY` * `ERROR` * `INFO` * `NOTICE` * `WARNING`' enum: - ALERT - CRITICAL - DEBUG - EMERGENCY - ERROR - INFO - NOTICE - WARNING example: CRITICAL type: - string - 'null' meta_uri: description: 'The client-requested URI. **Note:** This data is not always available.' example: null format: uri type: - string - 'null' path: description: The accessed file's path, relative to the document root. example: /something type: string timestamp: description: 'The date and time at which the log entry was made. **Note:** This parameter uses the server''s configured time zone.' example: '2019-10-13T07:58:04.000Z' format: ISO-8601 Date Time (Space Separated) type: string timezone: description: The server's configured timezone, in minutes difference from UTC/GMT. example: '-300' type: string type: object type: array message: description: A short message that explains the reason for the report. example: Hi. We're having some trouble with this rule. It seems to be blocking all requests. type: string rule_text: description: The rule text from the configuration file. example: 'SecAction "deny,auditlog,id:''12345694''" ' type: string type: description: 'The report''s type. **Note:** This value does **not** use a specified format. Treat the value as freeform text.' example: false positive type: string type: object type: object metadata: properties: command: description: The method name called. example: modsec_report_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Export ModSecurity rule error report tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_report_rule \\\n row_ids='794828' \\\n message=$'Hi. We\\'re having some trouble with this rule. It seems to be\nblocking all requests.' \\\n email='john.doe@example.com' \\\n type='false positive' \\\n send='1'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_report_rule?api.version=1&row_ids=794828&message=Hi.%20We%27re%20having%20some%20trouble%20with%20this%20rule.%20It%20seems%20to%20be%0ablocking%20all%20requests.&email=john.doe%40example.com&type=false%20positive&send=1 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_set_config_text: get: description: 'This function sets the contents of a specified ModSecurity™ configuration file. The system stages any changes to the configuration file. To deploy the changes, call WHM API 1''s `modsec_deploy_rule_changes` function. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_set_config_text parameters: - description: The configuration file name. in: query name: config required: true schema: example: modsec2.example.conf type: string - description: The configuration text. in: query name: text required: true schema: example: SecRule REQUEST_URI "example" "deny,id:123456789" SecAction "pass,auditlog,id" type: string responses: '200': content: application/json: schema: properties: data: {} metadata: properties: command: description: The method name called. example: modsec_set_config_text type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 0 - 1 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Update ModSecurity configuration file tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_set_config_text \\\n config='modsec2.example.conf' \\\n text='SecRule REQUEST_URI \"example\" \"deny,id:123456789\" SecAction \"pass,auditlog,id\"'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_set_config_text?api.version=1&config=modsec2.example.conf&text=SecRule%20REQUEST_URI%20%22example%22%20%22deny%2cid%3a123456789%22%20SecAction%20%22pass%2cauditlog%2cid%22 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_set_setting: get: description: 'This function sets a global ModSecurity™ configuration directive. **Important:** When you disable the Web Server role, the system **disables** this function.' operationId: ModSecurity-modsec_set_setting parameters: - description: "The setting's ID.\n\n**Note:**\n\n The WHM API 1 `modsec_get_settings` function returns this value." in: query name: setting_id required: true schema: example: 8 minimum: 0 type: integer - description: "The setting's new state. The function uses this as a valid argument\nfor the directive.\n\n**Note:**\n\n For more information, read SpiderLabs' [ModSecurity documentation](https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual)." in: query name: state required: true schema: example: '2000' type: string responses: '200': content: application/json: schema: properties: data: properties: default: description: The setting's default value. example: '1500' type: string description: description: The setting's description. example: This setting allows you to define the match limit of the PCRE library. type: string directive: description: The setting's Apache® directive. example: SecPcreMatchLimit type: string name: description: The setting's name. example: PCRE library match limit type: string radio_options: description: "An array of objects with the options that the client should display, as buttons, for this setting in a user interface.\n\n**Note:**\n\n The function **only** returns this array of objects when you set the `type` parameter's value to `radio`." items: properties: name: description: The setting name to display to the user. The user's [locale](https://go.cpanel.net/localedocs) may translate this value. example: Log all transactions. type: string option: description: "The setting that the system used to select the setting's state.\n\n**Note:**\n\n This value is identical to the string that the client sends in as `state` value when users select the specified setting. In most cases, you should **not** display this value to the user. Instead, display the `name` value." example: 'On' type: string type: object type: array setting_id: description: The setting's ID. example: 8 minimum: 0 type: integer state: description: The setting's new state. example: 2000 type: integer type: description: "The type of UI control that the client should use to represent the setting.\n\n* `text` - WHM users modify this setting via a text box.\n* `radio` - WHM users modify this setting via a radio button.\n - **Note:** If the `type` parameter's value is `radio`, the function also returns the `radio_options` array of objects.\n* `number` - WHM users modify this setting via a text box that only allows numeric values." enum: - text - radio - number example: text type: string url: description: The URL for the setting's documentation. example: https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#secpcrematchlimit format: url type: string validation: description: "A validator or array of validators to apply. Use these validators to perform frontend validation through your preferred implementation methods.\n\n**Note:**\n\n The function may represent each validator as either a string or an object.\n * When the function represents the validator as a string, no arguments exist for the validator.\n * When the function returns the validator as a object, the API may also include an argument for the validator." items: anyOf: - description: A JSON object string that contains one or more arguments for the validator. properties: arg: description: The regular expression pattern that is used with `name` when the validator checks a user's input. example: '[Ee]xample' name: description: The method that determines where the validator should match a pattern in a user's input. example: startsWith type: object - description: "A string that is one of the following values:\n * `path` - An instruction to verify whether the user's input is a valid path.\n * `honeypotAccessKey` - An instruction to verify whether the user's input fits the constraints of an `Http:BL` API access key.\n * `positiveInteger` - An instruction to verify whether the user's input is a positive integer." enum: - path - honeypotAccessKey - positiveInteger example: positiveInteger type: string type: array type: object metadata: properties: command: description: The method name called. example: modsec_set_setting type: string reason: description: The reason the API function failed when the `metadata.result` field is 0. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` - Success * `0` - Failed: Check the reason field for more details.' enum: - 0 - 1 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Update ModSecurity configuration tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_set_setting \\\n setting_id='8' \\\n state='2000'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_set_setting?api.version=1&setting_id=8&state=2000 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_undisable_rule: get: description: 'This function enables a ModSecurity™ rule. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_undisable_rule parameters: - description: The ModSecurity configuration file. in: query name: config required: true schema: example: modsec_vendor_configs/example.conf type: string - description: The ModSecurity rule's ID. in: query name: id required: true schema: example: '1234567890' type: string responses: '200': content: application/json: schema: properties: metadata: properties: command: description: The method name called. example: modsec_undisable_rule type: string reason: description: The reason the API function failed when the `metadata.result` field is 0. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` - Success * `0` - Failed: Check the reason field for more details.' enum: - 0 - 1 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Enable ModSecurity rule tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_undisable_rule \\\n config='modsec_vendor_configs/example.conf' \\\n id='1234567890'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_undisable_rule?api.version=1&config=modsec_vendor_configs%2fexample.conf&id=1234567890 x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.46' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. /modsec_update_vendor: get: description: 'This function updates a vendor with the current version of the rule set. **Important:** When you disable the Web Server role, the system disables this function.' operationId: ModSecurity-modsec_update_vendor parameters: - description: The vendor metadata file's URL. in: query name: url required: true schema: example: http://example.com/update/meta_MyVendor.yaml format: url type: string responses: '200': content: application/json: schema: properties: data: properties: diagnostics: description: A list of diagnostic information about the update. properties: added_configs: description: A list of the ModSecurity configuration files that the update added. items: example: modsec_vendor_configs/MyVendor/three.conf type: string type: array deleted_configs: description: An array of objects containing the ModSecurity configuration files that the update removed. items: example: modsec_vendor_configs/MyVendor/one.conf type: string type: array new_configs: description: A complete list of configuration files that the update modified. items: properties: active: description: 'Whether the configuration file is active. * `1` — Active. * `0` — **Not** active.' enum: - 1 - 0 example: 0 type: integer config: description: The file path to the configuration file, relative to the `/usr/local/apache/conf/` Apache configuration directory. example: modsec_vendor_configs/MyVendor/two.conf type: string vendor_id: description: The vendor's unique name. example: MyVendor type: string type: object type: array prev_configs: description: A list of configuration files in the old version. items: properties: config: description: The file path of the configuration file, relative to the `/usr/local/apache/conf/` Apache configuration directory. example: modsec_vendor_configs/MyVendor/two.conf type: string type: object type: array type: object vendor: description: A list of updated vendor information. properties: archive_url: description: The URL to download the vendor rules. example: http://example.com/update/MyVendor.zip format: url type: string cpanel_provided: description: 'Whether WebPros International, LLC provided the rule set. * `1` — Provided by WebPros International, LLC. * `0` — Not provided WebPros International, LLC.' enum: - 1 - 0 example: 0 type: integer description: description: The vendor's description. example: This is an example of a custom vendor set (updated). type: string dist_md5: description: The download's [MD5](https://en.wikipedia.org/wiki/MD5) checksum value. example: ecafce1bf148532250a8d4743a8374d1 type: string enabled: description: 'Whether the vendor is enabled. * `1` — Enabled. * `0` — Disabled.' enum: - 1 - 0 example: 1 type: integer inst_dist: description: The unique identifier for the rule set version. example: MyVendor-2 type: string installed: description: 'Whether the vendor is installed. * `1` — Installed. * `0` — **Not** installed.' enum: - 1 - 0 example: 1 type: integer installed_from: description: The URL to the vendor's metadata file. example: http://example.com/update/meta_MyVendor.yaml format: url type: string name: description: The vendor's name. example: My Vendor type: string path: description: The file path to the vendor's ModSecurity configuration files. example: /usr/local/apache/conf/modsec_vendor_configs/MyVendor type: string report_url: description: The URL that the vendor uses to receive problem reports. example: http://example.com/report/ format: url type: string vendor_id: description: The vendor's unique short name. example: MyVendor type: string vendor_url: description: The URL to the vendor's website. example: http://example.com/ format: url type: string type: object type: object metadata: properties: command: description: The method name called. example: modsec_update_vendor type: string reason: description: The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds. example: OK type: string result: description: '* `1` — Success. * `0` — Failed. Check the `reason` field for more details.' enum: - 1 - 0 example: 1 type: integer version: description: The version of the API function. example: 1 type: integer type: object description: HTTP Request was successful. summary: Update ModSecurity vendor ruleset tags: - ModSecurity x-codeSamples: - label: CLI lang: Shell source: "whmapi1 --output=jsonpretty \\\n modsec_update_vendor \\\n url='http://example.com/update/meta_MyVendor.yaml'\n" - label: URL lang: HTTP source: https://hostname.example.com:2087/cpsess##########/json-api/modsec_update_vendor?api.version=1&url=http%3a%2f%2fexample.com%2fupdate%2fmeta_MyVendor.yaml x-cpanel-api-version: WHM API 1 x-cpanel-available-version: '11.48' servers: - description: A server running WHM. url: https://{host}:{port}/json-api variables: host: default: whm-server.tld description: The hostname of a server running WHM. port: default: '2087' description: The WHM port. components: securitySchemes: BasicAuth: scheme: basic type: http externalDocs: url: https://cpanel.net/developers/ x-refined-from: - cpanel-uapi-openapi.yml - cpanel-whm-api-openapi.yml x-tagGroups: - name: API Development Tools tags: - API Token Management - Batch - SSE Task Management - URL Parsing - name: Authentication tags: - External Authentication - Two-Factor Settings - name: Backup Information tags: - BackupInfo - BackupInfo Status - name: Block Ip Addresses tags: - Block IP - name: Commerce Integration tags: - Market Integration - SSL Certificates - name: Contact Information tags: - Contact Information - name: cPanel Account tags: - Account Enhancements - Account Information - Account Management - AuditLog - Contact Information - cPanel Features - Disk Quotas - DomainRecommendations - Personalization - Resource Usage and Statistics - Subaccount Management - Team Roles - Team Users - name: cPanel Account Backups tags: - Backup - File Restoration - name: cPanel Plugin Framework tags: - Formbricks - Plugins - name: cPanel Theme Management tags: - Application Information - Brand Management - Branding Files - Browser Cache Management - Language - Theme Settings - name: Directory Management tags: - Directory Indexes - Directory Privacy - Directory Protection - name: DNS tags: - DNS - DNS Information - DNS Security - Dynamic DNS - Email DNS Settings - ZoneEdit - name: Domain tags: - Domain - name: Domain Management tags: - AddonDomain - Direct Link Protection (Hotlink) - Domain - Domain Information - Domain Redirection - DomainLookup - Park - SubDomain - Virtual Host Information - name: Domains tags: - Subdomains - name: Email tags: - Email Accounts - Email Filtering - Email Forwarding - Email Server Information - Email Suspensions - Mail Server Information - Mailbox Management - Mailing Lists - Signing and Encryption (GnuPG Keys) - Spam Filtering (Greylisting) - Spam Management - Spam Prevention (BoxTrapper) - Webmail Applications - Webmail Sessions - name: Extract Information tags: - ExtractInfo - ExtractInfo Status - name: File Manager tags: - Trash - name: Files tags: - FTP Accounts - FTP Server Settings - Image Tools - Jodit - Manage Files - Manage Files - WebDisk Settings - name: GIT Management tags: - Deployment Settings - Repository Management - name: InProductSurvey tags: - InProductSurvey - name: MySQL and MariaDB tags: - Database Information - Database Management - Remote Databases - User Management - name: Notifications tags: - Pushbullet - name: Optional Applications tags: - Antivirus Protection (ClamAV) - Calendar and Contacts (DAV) - Calendar and Contacts Server - WordPress Manager Backups - name: PostgreSQL tags: - PostgreSQL Database Management - PostgreSQL User Management - name: Retrieve bandwidth information tags: - Bandwidth - name: Security tags: - Known SSH Hosts Management - Login Information - name: Server Information tags: - cPanel Server Information - Notifications - Password Strength - SSH - WebPros MCP - WebProsMCP - name: ServiceProxy tags: - ServiceProxy - name: Site Quality Monitoring tags: - SiteQuality - name: SSL Certificates tags: - Auto-generated SSL Certificates - cPanel Account SSL Management - SNI Email Settings - SSL Certificate Management - Verify Domain Ownership - name: Statistics tags: - Domain Statistics - Weblog Settings - name: UserData tags: - UserData - name: Web Server Configuration tags: - EA4 - EasyApache Settings - PHP - name: Web Server Management tags: - Application Manager - ModSecurity - NginxCaching - PHP Settings - Web Apps - name: Website Configuration tags: - Handler Management - Logs - Mime Type Management - Nova - Site Information - Site Installation - Sitejet - WPX