Description
Allowing HTTP in API Gateway can send requests and responses between clients and the gateway without encryption. Allowing both HTTP and HTTPS still leaves plaintext access available.
Potential impact
An attacker able to intercept network traffic may read or alter authentication headers and request data.
Remediation
Set request_config.protocol to HTTPS and update clients to use HTTPS addresses. Configure TLS between the gateway and its backend separately.
Examples
These excerpts change the request protocol. API group, authentication, and backend settings are omitted.
Before
hcl
resource "alicloud_api_gateway_api" "api_gateway" {
request_config {
protocol = "HTTP"
method = "GET"
path = "/test/path1"
mode = "MAPPING"
}
}
After
hcl
resource "alicloud_api_gateway_api" "api_gateway" {
request_config {
protocol = "HTTPS"
method = "GET"
path = "/test/path1"
mode = "MAPPING"
}
}