Review Web App HTTPS redirection

Enable HTTPS redirection and configure clients to use encrypted URLs from the start.

Description

Handling Web App requests over HTTP can send login information, session cookies, and request data in plaintext. Enabling httpsOnly makes App Service redirect HTTP requests to HTTPS. It does not encrypt the first HTTP request that the client sent before the redirect.

Potential impact

  • Sensitive request information sent over HTTP can be exposed or altered along the connection path.
  • Configuring an HTTPS certificate while retaining plaintext paths can leave some clients using HTTP.

Remediation

Set httpsOnly: true and update links, API clients, and scripts to use HTTPS directly. Apply appropriate HSTS and Secure cookies, and retain certificate validation. If a CDN or reverse proxy is involved, check every segment from the client to the app and test actual redirection and HTTPS connectivity.

Examples

These are site-property excerpts. Replace the app name and Azure region with actual values and configure other required inputs, including the App Service plan.

Before

bicep
resource webSite 'Microsoft.Web/sites@2020-12-01' = {
  name: 'webSite'
  location: 'location1'
  tags: {}
  properties: {
    enabled: true
  }
}

This definition does not specify httpsOnly. Also check redirection at other layers and the existing app's effective settings.

After

bicep
resource webSite 'Microsoft.Web/sites@2020-12-01' = {
  name: 'webSite'
  location: 'location1'
  tags: {}
  properties: {
    enabled: true
    httpsOnly: true
  }
}

This enables App Service HTTP-to-HTTPS redirection. Clients still need changes to avoid sending sensitive data over HTTP first.

References