Description
Login data, session cookies, and user input sent over HTTP can be observed or altered. App Service’s https_only = true redirects HTTP requests to HTTPS. It does not encrypt the initial HTTP request, so clients should use HTTPS from the start.
Potential impact
Plaintext HTTP can expose data in transit and permit request tampering or session theft.
Remediation
Set https_only = true and configure app links, API clients, and redirects to use HTTPS. Check certificates, minimum TLS versions, secure cookies, and a suitable HSTS policy. Test that sensitive data is not sent over HTTP first.
Examples
These are legacy AzureRM 3.x azurerm_app_service examples. Current Linux and Windows Web App resources also support https_only.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
https_only = false
}
After
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
https_only = true
}
The revision redirects HTTP requests to HTTPS. It does not replace user authentication or authorization.