Control: Web Application should only be accessible over HTTPS
Description
Use of HTTPS ensures server/service authentication and protects data in transit from network layer eavesdropping attacks.
Usage
Run the control in your terminal:
powerpipe control run terraform_azure_compliance.control.appservice_web_app_use_httpsSnapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run terraform_azure_compliance.control.appservice_web_app_use_https --shareSQL
This control uses a named query:
select  address as resource,  case    when (attributes_std -> 'https_only')::boolean then 'ok'    else 'ok'  end status,  split_part(address, '.', 2) || case    when (attributes_std -> 'https_only')::boolean then ' redirects all HTTP traffic to HTTPS'    else ' does not redirect all HTTP traffic to HTTPS'  end || '.' reason    , path || ':' || start_linefrom  terraform_resourcewhere  type = 'azurerm_app_service';