Skip to content

feat: Added authrentication set up - #2392

Merged
Roopan-Microsoft merged 2 commits into
Azure-Samples:devfrom
Prajwal-Microsoft:main
Oct 7, 2026
Merged

Roopan-Microsoft merged 2 commits into
Azure-Samples:devfrom
Prajwal-Microsoft:main

Conversation

@Prajwal-Microsoft

Copy link
Copy Markdown
Contributor

Purpose

This pull request improves the security guidance and automation for authentication in Azure Container Apps deployments. It updates documentation and setup instructions to emphasize that backend authentication is required (not just recommended) for public deployments, introduces clearer steps for securing both frontend and backend apps, and explains the importance of running the provided setup scripts to protect sensitive admin APIs from anonymous access.

Security and Authentication Improvements:

  • Updated the deployment guide to clarify that configuring authentication is required for public deployments, and provided explicit instructions for running the setup_auth script to secure both frontend and backend Container Apps. The script now ensures Easy Auth is enabled on the backend and that anonymous admin API access is blocked.
  • Enhanced the authentication setup documentation to explain the separation between frontend and backend ingress, the risks of leaving the backend unauthenticated, and the need for the setup script. Added detailed, step-by-step instructions for running the script and verifying backend protection, plus guidance for local development and manual portal setup if needed.

Admin API Protection:

  • Updated the admin documentation to describe the two-layer admin access control (backend ingress authentication and in-app gate), and added a warning that failing to run the authentication setup script leaves the admin API open to anonymous callers.

Setup Script Instructions:

  • Added new post-deployment instructions in azure.yaml for both PowerShell and Bash users, guiding them to run the setup_auth script as a required step to secure the backend. [1] [2]

Documentation Metadata:

  • Updated documentation dates and descriptions to reflect the new guidance and clarify the authentication flow. [1] [2]

Does this introduce a breaking change?

  • Yes
  • No

How to Test

  • Get the code
git clone [repo-address]
cd [repo-name]
git checkout [branch-name]
npm install
  • Test the code

What to Check

Verify that the following are valid

  • ...

Other Information

@Roopan-Microsoft
Roopan-Microsoft merged commit d3e3979 into Azure-Samples:dev Oct 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants