feat: register plex-hardening-plugin (9530000-9530999) - #50
davidscarth wants to merge 3 commits into
Conversation
feat: register plex-hardening-plugin (9530000-9530999)
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited) Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe registry adds ChangesPlugin registry
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Feature Suggested labels: Merge Risk: ⚪ Minimal · up to The registry entry and generated files are consistent, with no identified merge blocker. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 3 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 16 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (16 passed)
Full details: Ai Contribution DisclosureExplanation
Resolution Update the PR body to include concrete lowercase Full details: Renovate: Config Present And ValidExplanation No Renovate configuration exists in either the PR base or head. The PR changes only README.md, registry.json, and registry.yaml, but the repository-wide absence triggers the check. Checks 1–3 therefore do not pass: the required file, exact $schema value, and shared preset extension are absent.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
chore: regenerate registry outputs
chore: regenerate registry outputs
|
Regenerated README.md and registry.json from registry.yaml per the drift check (run 7). Workflow runs on the two follow-up commits are awaiting approval. |
|
I just saw #40 also requests 9,530,000-9,530,999 (for n8n). Happy to move to 9,531,000-9,531,999 or whatever the next free block is, just let me know. the plugin's IDs are a constant offset from the block base, so renumbering is mechanical. |
|
I suggest to split this into two plugins:
|
Thought more about it. I also see a similar pattern for the WordPress plugin. I'm gonna go ahead and split it. |
|
I'd expect a hardening plugin specifically for plex would work out of the box without any false positives, or make certain hardening options configurable i.e restricting an plex admin panel to only trusted IPs or similar. You can of course bundle both the rule-exclusions and hardening together, it is your plugin after all but in that case, I'd suggest splitting the plugin files based on rule-exclusions and hardening rules for better readability. |
|
Two people telling me to split it up is good enough for me. I have a work in progress split version running locally. i've also added in the config conf a place to specify exception IPs for the admin endpoints, that makes sense. i plan to have an update out this week. |
what
Registers plex-hardening-plugin in the next free block, 9,530,000-9,530,999, and adds the regenerated README.md and registry.json.
why
Hardening plugin for Plex Media Server behind CRS 4.x: the rule exclusions Plex needs to run at PL1, detection rules for CVE-2026-96651/96652/96654/96655/96656 and the Zenofex Plex_Vuln_PoCs classes, and switchable owner-only endpoint denies. Tested on ModSecurity 2/3 via the shared plugin workflows and on Coraza in production.
refs
ai disclosure
tools used: Claude (Anthropic), Fable 5.1, via claude.ai.
assisted with: converting my existing production rules into the plugin file structure, drafting rule comments, tests, and diagnosing a Coraza-on-Windows transform issue in the endpoint denies.
review performed: every rule was deployed and exercised against live Plex clients (Plex Web, Windows, Android TV, Android mobile); exclusion test payloads were checked against the CRS 4.29.0 regexes; the registry entry and regenerated files were produced per the drift-check output.
Summary by CodeRabbit