Conversation
Register the server with `app.http()`, emit a v4 `package.json` (`main`) instead of `function.json`, and trace `@azure/functions` into the output.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (7)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe Azure Static Web Apps preset now checks for Azure Functions v4, generates v4 host files, and registers an HTTP handler that forwards requests to Nitro. The documented and generated Node.js runtime default changes to 22. ChangesAzure Static Web Apps Functions v4
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Merge Risk: ⚪ Minimal · up to The response-buffering concern does not change existing delivery behavior. No actionable merge-blocking risk remains from the reviewed changes. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The function-host and request-routing contracts change materially. Existing anonymous registration and header forwarding are preserved, and no introduced security vulnerability was established. Production authorization behavior and deployment recovery remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 5 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
Ensure `@azure/functions@^4` is installed in the project (it is traced, not bundled), default `apiRuntime` to `node:22`, and build the request url from `req.url` instead of the decoded route param.
Migrates the
azure-swapreset from the Azure Functions Node.js v3 programming model to v4.Changes
app.http("server", { route: "{*url}", ... })and uses the fetch-style v4HttpRequest/HttpResponseInit.function.jsonis no longer emitted..output/server/package.jsonnow has"type": "module"and"main": "functions/index.mjs".@azure/functionsis traced into the output (traceDeps) instead of bundled, since it requires@azure/functions-core, which only the Functions host provides.@azure/functions@^4in their project dependencies. The preset checks this onbuild:before(offering to install it viaensureDep) and fails the build with a clear error if it is missing or if v3 is installed..output/server/local.settings.json(FUNCTIONS_WORKER_RUNTIME: "node") soswa start/func startwork for local preview. Withoutfunction.json, Core Tools cannot detect the worker runtime.platform.apiRuntimefallback is nownode:22(wasnode:18;@azure/functionsv4 requires Node >= 20 and Node 20 is EOL).x-ms-original-urlor the rawreq.url, instead of the decodedparams.url. Query strings on direct/api/*requests are now forwarded (the v3 handler dropped them), and encoded%3F/%23in paths are no longer turned into a query or fragment.@azure/functionsdevDependency bumped to^4.16.5.Testing
@azure/functionsmissing (error), with v3 installed (error) and with v4 installed (3 packages traced).server: [DELETE,GET,...] /api/{*url}), and routes, query strings, JSON and binary request bodies, multipleSet-Cookieheaders andx-ms-original-urlproxied requests all work.TEST_AZURE=1suite through SWA CLI: 16 passed / 41 failed, with the exact same failing set as the v3 implementation (non-/apiroutes, emulator does not seem to pick upstaticwebapp.config.json). Not a regression, and not run in CI.req.urlassumes the function still sees the/api/...path there, which the fixedapiroute prefix implies.🤖 Generated with AI assistant