Description
If a Function App HTTP endpoint that needs authentication accepts anonymous requests, unauthorized users may access its functions or data. Missing platform authentication settings do not establish that the application has no authentication. Also examine function keys, application authentication and the actual access path.
Potential impact
- Functions that need protection may receive unwanted calls.
- Callers may read or change data within the function’s permissions.
- Automated calls can increase resource use and cost.
Remediation
Configure authentication appropriate for the endpoint’s intended audience. When using platform authentication, set up the identity provider and handling of unauthenticated requests, then test that protected paths reject anonymous requests. Limit authenticated users to the operations they need.
Examples
These excerpts use the legacy azurerm_function_app resource from AzureRM 3.x and omit required settings such as storage. For current configurations, use the Function App resource for the operating system.
Before
resource "azurerm_function_app" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
}
After
resource "azurerm_function_app" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
auth_settings {
enabled = true
}
}
The after example enables auth_settings, but that setting alone does not block anonymous requests. Complete the identity provider and request-handling policy, then verify authentication and authorization at the actual endpoint.