Alicloud API Gateway API allows HTTP

Accept API requests over HTTPS only.

Description

Allowing HTTP in API Gateway can send requests and responses between clients and the gateway without encryption. Allowing both HTTP and HTTPS still leaves plaintext access available.

Potential impact

An attacker able to intercept network traffic may read or alter authentication headers and request data.

Remediation

Set request_config.protocol to HTTPS and update clients to use HTTPS addresses. Configure TLS between the gateway and its backend separately.

Examples

These excerpts change the request protocol. API group, authentication, and backend settings are omitted.

Before

hcl
resource "alicloud_api_gateway_api" "api_gateway" {
  request_config {
    protocol = "HTTP"
    method   = "GET"
    path     = "/test/path1"
    mode     = "MAPPING"
  }
}

After

hcl
resource "alicloud_api_gateway_api" "api_gateway" {
  request_config {
    protocol = "HTTPS"
    method   = "GET"
    path     = "/test/path1"
    mode     = "MAPPING"
  }
}

References