Description
An external API endpoint using http: cannot provide the confidentiality, integrity, and server authentication offered by TLS when the request is actually transmitted. An attacker with access to the network path may read or modify requests and responses. However, browsers generally block Axios requests from HTTPS pages under their mixed-content policy. In that case, the request fails instead of being sent in cleartext.
Review the sensitive data in both directions and the browser or server environment in which the code runs.
Potential impact
- Cleartext transmission may expose credentials, tokens, personal information, or other included data.
- An attacker may alter responses to deliver incorrect data or malicious content to the application.
- Mixed-content blocking on an HTTPS page may cause API failures and disrupt functionality.
Remediation
- Change endpoints to
https:and confirm that the API serves the same resources over HTTPS. Do not rely on redirecting an API request after first sending it over HTTP. - Configure valid server certificates and current TLS settings, and reject cleartext API requests. Apply HSTS to HTTPS origins used by browsers.
- Keep local development addresses in environment-specific configuration and check that they do not enter production bundles. Do not disable certificate validation or browser mixed-content protections.
Examples
Before
tsx
import axios from 'axios';
axios.post('http://api.example.com/login', credentials);
const api = axios.create({
baseURL: 'http://api.example.com/v1',
});
After
tsx
import axios from 'axios';
axios.post('https://api.example.com/login', credentials);
const api = axios.create({
baseURL: 'https://api.example.com/v1',
});
Explanation:
- Before: Requests and responses may travel over cleartext HTTP in an insecure context or outside a browser. A browser may block the requests from an HTTPS page.
- After: Properly configured HTTPS protects confidentiality, integrity, and server authentication in transit. Verify the server's TLS configuration as well as the application URLs.