The OPTIONS method can be disabled on the OneClick server by updating the web.xml file and adding the block below BEFORE
the </web-app> closing tag.
FILE: $SPECROOT/tomcat/conf/web.xml
- backup the existing web.xml
cp -p $SPECROOT/tomcat/conf/web.xml $SPECROOT/tomcat/conf/web.xml.backup
- edit $SPECROOT/tomcat/conf/web.xml (add below just before the closing </web-app> tag)
<web-resource-name>restricted methods</web-resource-name>
<auth-constraint />
- save changes
- restart OneClick tomcat
Tomcat should now block the OPTIONS method.