SV-274697r1143731_rule
V-274697
SRG-APP-000419
SRG-APP-000419-API-000945
CAT II
10
Clients must be configured to call a single API gateway URL rather than accessing backend services directly.
Note: The authorizing official (AO) may conduct a risk assessment if not using an API Gateway.
Check Client API Endpoints:
Examine the client-side code (whether a web app, mobile app, or another service) to confirm that all API calls are configured to point to a single gateway URL.
Review the access logs or traffic logs of the API gateway to determine where incoming requests are coming from. Verify all requests are originating from the expected single API gateway endpoint.
If the API is not configured to route requests through a single, authorized API Gateway endpoint, this is a finding.
V-274697
False
SRG-APP-000419-API-000945
Note: The authorizing official (AO) may conduct a risk assessment if not using an API Gateway.
Check Client API Endpoints:
Examine the client-side code (whether a web app, mobile app, or another service) to confirm that all API calls are configured to point to a single gateway URL.
Review the access logs or traffic logs of the API gateway to determine where incoming requests are coming from. Verify all requests are originating from the expected single API gateway endpoint.
If the API is not configured to route requests through a single, authorized API Gateway endpoint, this is a finding.
M
5703