Skip to main content

FC HTTP Trigger Authentication Check

ID: rule:aliyun:fc-trigger-http-not-anonymous
Severity: high

Description

FC HTTP triggers should require authentication to prevent unauthorized access.

Reason for Violation

The FC HTTP trigger allows anonymous access, which may expose the function to unauthorized invocations.

Recommendation

Configure authentication for the HTTP trigger by setting appropriate authorization type.

Resource Types

  • ALIYUN::FC::Trigger