[Bug] ASGI cookie conversion serializes an absent Domain attribute and breaks __Host- cookies
还没有人认领这个 Issue。
评估
调研方向
从 workers/azure_functions_worker/bindings/datumdef.py 第 232-245 行附近开始,然后运行 workers/tests/unittests/test_http_functions.py 第 374-379 行附近的相关测试。为提供的 __Host-test 响应添加一个回归用例,并验证缺失的 Domain 属性会被省略,而显式指定的域仍会被序列化。
由索引模型根据 Issue 内容生成。
描述
Expected Behavior
This surfaced in FastMCP issue #4748. FastMCP's OAuth consent flow emits a valid __Host- cookie, but when the application runs on Azure Functions, the browser receives a Domain attribute and rejects it.
Azure Functions should preserve the absence of Domain in this ASGI response:
Set-Cookie: __Host-test=value; Path=/; Secure; HttpOnly; SameSite=Lax
__Host- cookies require Secure, Path=/, and no Domain attribute.
Actual Behavior
The Python ASGI response path parses Set-Cookie into a structured cookie and serializes the missing domain as a present, empty domain. The final response contains domain= or surfaces the Function App hostname as its effective domain. Browsers therefore reject the __Host- cookie; in FastMCP this causes the consent POST's CSRF check to fail.
Steps to Reproduce
- Deploy the ASGI application below to Azure Functions.
- Request its HTTP endpoint over HTTPS.
- Inspect the final
Set-Cookieheader and the browser cookie warnings. - Observe that the response includes a Domain attribute and the browser rejects
__Host-test.
Relevant code being tried
import azure.functions as func
async def asgi_app(scope, receive, send):
assert scope["type"] == "http"
await send(
{
"type": "http.response.start",
"status": 200,
"headers": [
(b"content-type", b"text/plain"),
(
b"set-cookie",
b"__Host-test=value; Path=/; Secure; HttpOnly; SameSite=Lax",
),
],
}
)
await send(
{
"type": "http.response.body",
"body": b"ok",
"more_body": False,
}
)
app = func.AsgiFunctionApp(
app=asgi_app,
http_auth_level=func.AuthLevel.ANONYMOUS,
)
Relevant log output
No application error is logged. The failure appears in the response header and browser cookie warning.
requirements.txt file
azure-functions==1.24.0
Where are you facing this problem?
Production Environment
Function app name
Not publicly shareable
Additional Information
azure-functions-python-library removes the raw header and parses it with SimpleCookie:
https://github.com/Azure/azure-functions-python-library/blob/dev/azure/functions/http.py#L113-L116
The worker then passes the empty cookie_entity['domain'] value to to_nullable_string, creating a present RPC domain:
https://github.com/Azure/azure-functions-python-worker/blob/dev/workers/azure_functions_worker/bindings/datumdef.py#L232-L245
The existing end-to-end test expects an attribute-free cookie to become foo=bar; domain=; path=:
https://github.com/Azure/azure-functions-python-worker/blob/dev/workers/tests/unittests/test_http_functions.py#L374-L379
A targeted fix would omit the RPC domain when cookie_entity['domain'] is empty while preserving explicit domains. A __Host- regression test can verify that the final response contains Path=/; Secure and no Domain.
- 主要语言
- Python
- 星标
- 357
- 派生
- 117
- 平均合并
- 9 天 27 分钟
- 30 天内合并 PR
- 3
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
Azure/azure-functions-python-worker 的其他 Issue
-
难度 5/5 一周以上 新手友好度 28/100
Azure/azure-functions-python-worker#1908 · 2 条评论 ·
-
难度 4/5 3-5 天 新手友好度 55/100
Azure/azure-functions-python-worker#1906 · 1 条评论 ·
-
难度 5/5 一周以上 新手友好度 35/100
-
难度 4/5 3-5 天 新手友好度 55/100
-
bug python
难度 4/5 3-5 天 新手友好度 55/100
Azure/azure-functions-python-worker#1887 · 1 个 reaction ·
查看 Azure/azure-functions-python-worker 的全部 Issue
相似的 Issue
-
namespace operations
难度 1/5 1 小时以内 新手友好度 82/100
EclipseFdn/open-vsx.org#13573 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
collective/icalendar#1854 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
rancher/rancher-ai-agent#412 ·
维护者通常 6 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
TUDelftGeodesy/DePSI#134 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
HenriquesLab/rxiv-maker#335 ·