Azure / Azure/azure-functions-core-tools

Azure Function App host not regarding authentication for enterprise proxy (local development)

Open
#4,267 0 comments 0 reactions 0 assignees View on GitHub
needs-investigation potential-bug
Dominant language
C#
Stars
1.5k
Forks
498
Avg merge
4d 20h
Merged PRs (30d)
14

Description

### Version

4.0.65.18

### Description

Calling HTTP services outside the network during local development when having an enterprise proxy that expects authentication in between and a WPAD file set up on system level, the function app host does not correctly authenticate which leads to a HTTP 407 response.
Setting the commonly known environment variables ALL_PROXIES, HTTP_PROXY, HTTPS_PROXY and NO_PROXY does not work either as this leads to a low-level crash (observed on macOS) of the host as soon as authentication information is provided in one of those environment variables. Also, this is not a good way to do it.

Expectation: the Azure Function App host should provide a proper way of dealing with an enterprise proxy and auth as this is a common requirement for developers and can only be worked around with by massive investment of resources. At the very least the environment variables solution needs to work (which it did in the past).

### Steps to reproduce

1. Create a minimal Azure Function App project (in-process)
2. Add an HTTP client in the startup
3. Create a function (trigger does not matter) that makes an HTTP call to a service outside your network
4. Configure a proxy server that requires authentication (NTLM first, basic auth as fallback) on system level (ideally as a WPAD file to reproduce as closely as possible)
5. Trigger the function

Current result: HTTP 407 response

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the minimal in-process Azure Function App described in the issue with an authenticated enterprise proxy and WPAD configured. Investigate the local host's proxy handling and environment-variable path; done means the outbound HTTP call authenticates successfully without an HTTP 407 response or a macOS crash.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, csharp
Domain
authentication, cli, networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.