App Service authentication disabled 이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다. Id: terraform-azure-app-service-authentication-disabled
Provider: Azure
Platform: Terraform
Severity: Medium
Category: Access Control
Learn More Description Azure App Service authentication settings should be enabled to ensure that access to the application is restricted to authenticated users. Without enabling the auth_settings { enabled = true } block in Terraform, anyone can anonymously access the app, which exposes it to unauthorized access and potential misuse of sensitive data or resources. Properly configuring authentication securely helps mitigate risks from attacks such as data exfiltration, account takeover, or service abuse.
auth_settings = {
enabled = true
}
Compliant Code Examples resource "azurerm_app_service" "negative1" {
name = "example-app-service"
location = azurerm_resource_group . example . location
resource_group_name = azurerm_resource_group . example . name
app_service_plan_id = azurerm_app_service_plan . example . id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
app_settings = {
"SOME_KEY" = "some-value"
}
auth_settings = {
enabled = true
}
connection_string {
name = "Database"
type = "SQLServer"
value = "Server=some-server.mydomain.com;Integrated Security=SSPI"
}
}
Non-Compliant Code Examples resource "azurerm_app_service" "positive1" {
name = "example-app-service"
location = azurerm_resource_group . example . location
resource_group_name = azurerm_resource_group . example . name
app_service_plan_id = azurerm_app_service_plan . example . id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
app_settings = {
"SOME_KEY" = "some-value"
}
connection_string {
name = "Database"
type = "SQLServer"
value = "Server=some-server.mydomain.com;Integrated Security=SSPI"
}
}
resource "azurerm_app_service" "positive2" {
name = "example-app-service"
location = azurerm_resource_group . example . location
resource_group_name = azurerm_resource_group . example . name
app_service_plan_id = azurerm_app_service_plan . example . id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
app_settings = {
"SOME_KEY" = "some-value"
}
auth_settings = {
enabled = false
}
connection_string {
name = "Database"
type = "SQLServer"
value = "Server=some-server.mydomain.com;Integrated Security=SSPI"
}
}