Azure / Azure/azure-functions-python-worker

[Bug] Python Azure Function worker incorrectly URL encodes cookie value

Open
#1,794 1 comment 2 reactions 0 assignees View on GitHub
area:python-functions bug python python-sdk
Dominant language
Python
Stars
357
Forks
116
Avg merge
32m
Merged PRs (30d)
1

Description

### Expected Behavior

Azure Function worker using Python FastAPI should not URL encode cookie values

Expected behavior on HTTP Response Headers:
`set-cookie: test="hello//world"; Path=/; SameSite=lax`

e.g. when using Python FastAPI without Azure Functions, it correctly does not URL encode.
````
import uvicorn
from fastapi import FastAPI
from fastapi.responses import PlainTextResponse

app = FastAPI()

@app.get("/")
def http_trigger():
response = PlainTextResponse("", status_code=200)
response.set_cookie(key='test', value='hello//world')

return response

if __name__ == "__main__":
uvicorn.run(app, host="127.0.0.1", port=7071)

````

Run `curl -v http://localhost:7071/` and response is correct as `set-cookie: test="hello//world"; Path=/; SameSite=lax`

### Actual Behavior

Actual incorrect behavior on HTTP Response Headers, cookie value is incorrect and unexpectedly URL encoded

`Set-Cookie: test=hello%2F%2Fworld; domain=; path=/; samesite=lax`

Tested bug with
* Python 3.12 with FastAPI
* Azure Functions Core tools 4.3.0 locally
* Deployed to production Azure Function

### Steps to Reproduce

1. Run `func start` or deploy to Azure using sample code provided below
2. Send a test HTTP request e.g. `curl -v http://localhost:7071/`
3. Azure Functions worker incorrectly URL encodes the response cookie value in the `Set-Cookie` header

### Relevant code being tried

```shell
import azure.functions as func
from fastapi import FastAPI
from fastapi.responses import PlainTextResponse

app = FastAPI()
func_app = func.AsgiFunctionApp(app=app, http_auth_level=func.AuthLevel.ANONYMOUS)

@app.get("/")
def http_trigger():

response = PlainTextResponse("", status_code=200)
response.set_cookie(key='test', value='hello//world')

return response
```

### Relevant log output

```shell
N/A
```

### requirements.txt file

```shell
azure-functions
fastapi
```

### Where are you facing this problem?

Production Environment (explain below)

### Function app name

Private

### Additional Information

_No response_

Contributor guide

Open the contributing guide

Research direction

Begin with the ASGI adapter path created by func.AsgiFunctionApp and compare its response-header handling with FastAPI's PlainTextResponse.set_cookie output. Reproduce with func start and curl -v using the value hello//world; done means the Set-Cookie header preserves the expected cookie value and a regression check covers it.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, fastapi, python
Domain
api, backend
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.