Description
Disabling https_only on Azure Web App permits HTTP access to the application. Enabling HTTPS Only redirects HTTP requests to HTTPS.
Potential impact
Sensitive data in HTTP requests or responses can be exposed or modified. A subsequent redirect cannot protect a plaintext request already sent.
Remediation
Set https_only to true and make user links and client URLs use HTTPS from the start. Check custom-domain certificates and redirect behavior.
Examples
The examples compare only HTTPS Only settings. Certificate bindings and application deployment are separate.
Before
yaml
- name: Web App 생성
azure_rm_webapp:
resource_group: myResourceGroup
name: myWinWebapp
https_only: false
plan:
resource_group: myAppServicePlan_rg
name: myAppServicePlan
is_linux: false
sku: S1
After
yaml
- name: Web App 생성
azure_rm_webapp:
resource_group: myResourceGroup
name: myWinWebapp
https_only: true
plan:
resource_group: myAppServicePlan_rg
name: myAppServicePlan
is_linux: false
sku: S1