You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform配置Azure Web应用的客户端应用要求为仅允许自身请求

解决方案:配置Azure Windows Web应用仅允许自身请求的身份验证限制

要将Azure Windows Web应用的“Client application requirement”设置为“allow requests only from this application itself”,你需要在Terraform的auth_settings_v2.active_directory_v2块中添加客户端应用ID白名单配置,仅包含当前Web应用自身的Client ID。

修改后的完整Terraform配置

resource "azurerm_windows_web_app" "terra_webapp" {
 resource_group_name = var.web_app_resource_group_name
 name                = var.web_app_name
 location            = var.web_app_location
 service_plan_id     = var.service_plan_id
 tags                = var.tags

 https_only = true
 app_settings = {
   WEBSITE_AUTH_AAD_ALLOWED_TENANTS = "<TenantID>"
 }

 site_config {
   minimum_tls_version = "1.2"
 }

 auth_settings_v2 {
   auth_enabled           = true
   require_authentication = true
   require_https          = true
   runtime_version        = "~1"
   default_provider       = "azureactivedirectory"
   unauthenticated_action = "RedirectToLoginPage"

   login {
     token_store_enabled            = true
     token_refresh_extension_time   = 6
     allowed_external_redirect_urls = []
   }

   active_directory_v2 {
     client_id            = "<appClientID>"
     tenant_auth_endpoint = "https://sts.windows.net/<TenantID>/v2.0"
     # 添加这一行,仅允许当前应用自身的客户端ID
     allowed_client_app_ids = ["<appClientID>"]
   }
 }
}

关键说明

  • allowed_client_app_ids是控制“Client application requirement”的核心参数:当数组中仅包含当前Web应用的Client ID时,Azure会自动将该选项设置为“allow requests only from this application itself”。
  • 确保替换配置中的<TenantID>和<appClientID>为你实际的租户ID和Web应用客户端ID。

验证方法

部署修改后的Terraform配置后,登录Azure门户,进入目标Web应用的Authentication设置页面,查看“Client application requirement”选项,确认已切换为目标设置。

内容的提问来源于stack exchange,提问作者Paul

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 06:23:17