Azure Web App HTTPS 강제 설정 점검

웹 요청에 HTTPS를 사용하고 평문 요청으로 민감한 정보를 보내지 마세요.

설명

HTTP로 전송하는 로그인 정보, 세션 쿠키와 사용자 입력은 관찰되거나 변조될 수 있습니다. App Service의 https_only = true는 HTTP 요청을 HTTPS로 리디렉션합니다. 최초 HTTP 요청 자체가 암호화되는 것은 아니므로 클라이언트도 처음부터 HTTPS를 사용해야 합니다.

잠재적 영향

평문 HTTP를 사용하면 전송 중 데이터 노출, 요청 변조와 세션 탈취 위험이 생길 수 있습니다.

해결 방법

https_only = true를 설정하고 앱 링크, API 클라이언트와 리디렉션이 HTTPS를 사용하도록 구성하세요. 인증서와 최소 TLS 버전, 보안 쿠키와 적절한 HSTS 정책도 확인하세요. 민감한 데이터를 HTTP로 먼저 보내지 않도록 시험하세요.

예시

AzureRM 3.x의 기존 azurerm_app_service 예시이며, 현재 Linux·Windows Web App도 https_only를 지원합니다.

변경 전

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
  }

  https_only = false
}

변경 후

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
  }

  https_only = true
}

변경 후에는 HTTP 요청이 HTTPS로 리디렉션됩니다. 이는 사용자 인증이나 호출 권한 검증을 대신하지 않습니다.

참조