[Bug] Python Azure Function worker incorrectly URL encodes cookie value

Open
#1,794 1 comment 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
azure, fastapi, python
Domain
api, backend

Research direction

Begin with the ASGI adapter path created by func.AsgiFunctionApp and compare its response-header handling with FastAPI's PlainTextResponse.set_cookie output. Reproduce with func start and curl -v using the value hello//world; done means the Set-Cookie header preserves the expected cookie value and a regression check covers it.

Written by the indexing model from the issue text.

Description

area:python-functions bug python python-sdk
Expected Behavior

Azure Function worker using Python FastAPI should not URL encode cookie values

Expected behavior on HTTP Response Headers:
set-cookie: test="hello//world"; Path=/; SameSite=lax

e.g. when using Python FastAPI without Azure Functions, it correctly does not URL encode.

import uvicorn
from fastapi import FastAPI
from fastapi.responses import PlainTextResponse

app = FastAPI()

@app.get("/")
def http_trigger():
    response = PlainTextResponse("", status_code=200)
    response.set_cookie(key='test', value='hello//world')

    return response

if __name__ == "__main__":
    uvicorn.run(app, host="127.0.0.1", port=7071)

Run curl -v http://localhost:7071/ and response is correct as set-cookie: test="hello//world"; Path=/; SameSite=lax

Actual Behavior

Actual incorrect behavior on HTTP Response Headers, cookie value is incorrect and unexpectedly URL encoded

Set-Cookie: test=hello%2F%2Fworld; domain=; path=/; samesite=lax

Tested bug with

  • Python 3.12 with FastAPI
  • Azure Functions Core tools 4.3.0 locally
  • Deployed to production Azure Function
Steps to Reproduce
  1. Run func start or deploy to Azure using sample code provided below
  2. Send a test HTTP request e.g. curl -v http://localhost:7071/
  3. Azure Functions worker incorrectly URL encodes the response cookie value in the Set-Cookie header
Relevant code being tried
import azure.functions as func
from fastapi import FastAPI
from fastapi.responses import PlainTextResponse

app = FastAPI()
func_app = func.AsgiFunctionApp(app=app, http_auth_level=func.AuthLevel.ANONYMOUS)

@app.get("/")
def http_trigger():

    response = PlainTextResponse("", status_code=200)
    response.set_cookie(key='test', value='hello//world')

    return response
Relevant log output
N/A
requirements.txt file
azure-functions
fastapi
Where are you facing this problem?

Production Environment (explain below)

Function app name

Private

Additional Information

No response

Dominant language
Python
Stars
357
Forks
116
Avg merge
32m
Merged PRs (30d)
1

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Azure/azure-functions-python-worker

All issues in Azure/azure-functions-python-worker

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.