# Known Limitations (Beta)

> **Audience:** operators running a WHost 1.0.0 beta.

This page lists what the current beta release does not do yet, or does
differently from what the panel might suggest. Each entry says what you see
and what to do instead. An entry leaves this page with the release that
changes it; the release notes say so.

---

## Installation

**Install with `--webserver=nginx` or `--webserver=nginx_apache`.** The
installer refuses `apache`, `openlitespeed` and `litespeed` before it changes
anything. OpenLiteSpeed and LiteSpeed Enterprise are switched on after the
installation under **Plugins** in the admin panel.

**Debian 12 cannot run this release.** The agent needs Python 3.12, which
Debian 12 does not package; the installer recognises Debian 12 and stops
before changing anything. See [Supported Operating Systems](supported-os.md).

**SELinux runs in Permissive mode on AlmaLinux, Rocky Linux and CentOS
Stream.** WHost ships no SELinux policy yet. The installer switches a host
that enforces SELinux to Permissive, now and for the next boot, and says so
(see [SELinux on the RHEL family](installation.md#selinux-on-the-rhel-family)).
Running with SELinux enforcing is planned after the beta.

---

## Accounts and plans

**Traffic (bandwidth) is not counted per account.** The plan field
"Bandwidth" is stored, but WHost does not measure each account's monthly
traffic and does not enforce the limit: the account's traffic gauge in the
admin panel and on the customer's dashboard always shows 0. Only the
server's total network traffic is measured. If you bill by traffic, take
the numbers from the web server's access logs for now.

**Usage counters.** On the admin panel's account page the domain count is
always 1, whatever the account holds. On the customer's dashboard the
addon-domain allowance shown is one higher than the number that can still be
added, because the plan's domain limit counts the primary domain too.

**Reseller accounts (experimental).** Suspending a reseller suspends its
customers' websites, cron jobs and logins, but their FTP users, mailboxes and
Node.js / Python applications stay active. Suspend a customer account
directly when all of its services must stop.

---

## Web servers

Our test servers run nginx and nginx + Apache. The configuration WHost writes
for servers that run **Apache alone** or **OpenLiteSpeed** differs as follows:

- **No automatic HTTP → HTTPS redirect.** A site with a certificate answers
  on both `http://` and `https://`; nginx-based setups redirect with `301`.
  Add the redirect in the site's `.htaccess` if you need it. (The Apache
  HTTPS site still sends the HSTS header.)

**Ubuntu 22.04 loads the WAF rule set without one file.** Ubuntu 22.04 ships
libmodsecurity 3.0.6, which cannot read `REQUEST-922-MULTIPART-ATTACK.conf` of
the OWASP Core Rule Set 3.3.7 (the file needs 3.0.8). That file is set aside
as `REQUEST-922-MULTIPART-ATTACK.conf.disabled` and the rest of the rule set
is loaded. What is left out are the rule set's checks of the headers inside
multipart request bodies (file uploads and forms). The engine version itself
predates the fixes to multipart request parsing that ModSecurity 3.0.8
released (CVE-2022-48279); Ubuntu's 3.0.6-1 package carries no backport of
them (September 2026). Where the WAF matters, use Ubuntu 24.04 (libmodsecurity
3.0.12) or the RHEL family, whose EPEL package (3.0.15 on Rocky Linux 9) reads
the whole rule set; the agent puts the file back at its next start once the
engine can read it. The WAF page shows the WAF as inactive, with a note,
whenever nginx has not loaded the rule set.

**nginx does not check the agent's certificate on the panel's internal
connection.** nginx hands panel and API requests to the agent on
`127.0.0.1:2000` without verifying the agent's certificate. Ports below 2001
can only be opened by root, so no process of a hosting account can take the
agent's place on that port, not even while the agent restarts. A separate
internal certificate for this connection is planned after the beta.

---

## Client panel

**Subdomains and redirects cannot be edited in the client panel.** The row
offers delete only; remove the entry and add it again with the new values.
A redirect can also be changed in place through the API
(`PUT /api/v1/client/redirects/{id}`).

**Webmail has no server-side filters or vacation replies.** Mail filters and
automatic replies are not available on the server; the webmail's own
Filters screen is hidden.

---

## Backups

**A scheduled backup interrupted by an agent restart runs again from the
start.** When the agent is stopped while a scheduled backup is running (an
operator restart, a package upgrade that restarts it, a crash), the run is
repeated from the beginning at the next start instead of continuing.

---

## Experimental areas

These work in our tests, but not every path has been measured on every
supported system yet; treat them as experimental during the beta and report
what you find:

- Node.js and Python application hosting
- Migration from cPanel and DirectAdmin over SSH; the other sources the
  wizard offers (Plesk, HestiaCP, CyberPanel, CloudPanel, CWP and another
  WHost server) have not been measured yet
- Reseller accounts
- White label

**No restore from an uploaded backup file.** Migrate over SSH. The
Migration page has no Upload tab and the upload endpoints refuse.

---

## API and PHP SDK

- An API key cannot change an account's password or the server's root
  password (`403 HMAC_FORBIDDEN_FOR_CREDENTIAL_MUTATION`); the account owner
  changes it in the panel. This is a design decision, not a gap.
- The PHP SDK is a download from this site, not a Packagist package; some of
  its accessors answer only a signed-in panel session. See the
  [PHP SDK page](../developer/sdk-php.md).

---

## Reporting

Report what you find with a support ticket from your wisecp.com client area
(or `hello@wisecp.com` when you cannot open one) and add the WHost version
(**Updates** page, or `GET /api/v1/system/update/status` →
`current_version`), the operating system and what you did.
