Skip to content

feat(azure): migrate azure-swa to azure functions v4 programming model - #4717

Open
pi0x wants to merge 2 commits into
mainfrom
feat/azure-v4
Open

pi0x wants to merge 2 commits into
mainfrom
feat/azure-v4

Conversation

@pi0x

@pi0x pi0x commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Migrates the azure-swa preset from the Azure Functions Node.js v3 programming model to v4.

Changes

  • Runtime registers the server with app.http("server", { route: "{*url}", ... }) and uses the fetch-style v4 HttpRequest / HttpResponseInit.
  • function.json is no longer emitted. .output/server/package.json now has "type": "module" and "main": "functions/index.mjs".
  • @azure/functions is traced into the output (traceDeps) instead of bundled, since it requires @azure/functions-core, which only the Functions host provides.
  • Users need @azure/functions@^4 in their project dependencies. The preset checks this on build:before (offering to install it via ensureDep) and fails the build with a clear error if it is missing or if v3 is installed.
  • Writes .output/server/local.settings.json (FUNCTIONS_WORKER_RUNTIME: "node") so swa start / func start work for local preview. Without function.json, Core Tools cannot detect the worker runtime.
  • Default platform.apiRuntime fallback is now node:22 (was node:18; @azure/functions v4 requires Node >= 20 and Node 20 is EOL).
  • The request URL is built from x-ms-original-url or the raw req.url, instead of the decoded params.url. Query strings on direct /api/* requests are now forwarded (the v3 handler dropped them), and encoded %3F / %23 in paths are no longer turned into a query or fragment.
  • @azure/functions devDependency bumped to ^4.16.5.

Testing

  • Built a project with @azure/functions missing (error), with v3 installed (error) and with v4 installed (3 packages traced).
  • Ran the build output with Azure Functions Core Tools 4.15.2: function is discovered (server: [DELETE,GET,...] /api/{*url}), and routes, query strings, JSON and binary request bodies, multiple Set-Cookie headers and x-ms-original-url proxied requests all work.
  • TEST_AZURE=1 suite through SWA CLI: 16 passed / 41 failed, with the exact same failing set as the v3 implementation (non-/api routes, emulator does not seem to pick up staticwebapp.config.json). Not a regression, and not run in CI.
  • Not yet verified with a real Azure SWA deployment. Using req.url assumes the function still sees the /api/... path there, which the fixed api route prefix implies.

🤖 Generated with AI assistant

Register the server with `app.http()`, emit a v4 `package.json` (`main`) instead of `function.json`, and trace `@azure/functions` into the output.
@pi0x
pi0x requested a review from pi0 as a code owner October 3, 2026 17:11
@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nitro.build Ready Ready Preview Oct 3, 2026 5:20pm UTC

Request Review

@socket-security

socket-security Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​azure/​functions@​3.6.0 ⏵ 4.16.510010093 +298 -1100

View full report

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
.agents/docs.md — configured

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: df401198-1a25-4d72-b3e7-859ebc85057d
📥 Commits

Reviewing files that changed from the base of the PR and between 136fb29 and 5aec01d.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (7)
  • docs/2.deploy/20.providers/azure.md
  • package.json
  • src/presets/azure/preset.ts
  • src/presets/azure/runtime/_utils.ts
  • src/presets/azure/runtime/azure-swa.ts
  • src/presets/azure/utils.ts
  • test/unit/azure.utils.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The Azure Static Web Apps preset now checks for Azure Functions v4, generates v4 host files, and registers an HTTP handler that forwards requests to Nitro. The documented and generated Node.js runtime default changes to 22.

Changes

Azure Static Web Apps Functions v4

Layer / File(s) Summary
Configure the Azure Functions v4 host
package.json, src/presets/azure/utils.ts, src/presets/azure/preset.ts, docs/2.deploy/20.providers/azure.md
The preset checks for @azure/functions v4 before build and traces the package. Generated files use an ES-module entry point and Node.js 22 default. The documentation describes the v4 requirement and runtime default.
Register and adapt HTTP requests
src/presets/azure/runtime/azure-swa.ts, src/presets/azure/runtime/_utils.ts, test/unit/azure.utils.test.ts
The adapter registers a v4 HTTP handler, forwards request method, headers, and an optional body to Nitro, then returns the response body stream with status, cookies, and other headers. Base URL resolution and its test use the standard Headers class.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 5aec0

The response-buffering concern does not change existing delivery behavior. No actionable merge-blocking risk remains from the reviewed changes.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 5aec0

The function-host and request-routing contracts change materially. Existing anonymous registration and header forwarding are preserved, and no introduced security vulnerability was established. Production authorization behavior and deployment recovery remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The boundary under review can affect routes reachable through each application's Azure wildcard handler. Any privileged outcome would depend on that application's downstream handlers and authority; cross-tenant, data-store, and infrastructure privilege exposure were not established.

Trust Boundaries and Controls

  • observed — The adapter does not authenticate identity headers or enforce application authorization before Nitro dispatch. It forwards the received headers and derives the origin from forwarded or host metadata. This responsibility split existed previously; whether clients can influence trusted metadata in production remains unresolved.

Resilience and Maintainability Implications

  • inferred — The awaited dependency gate contains ordinary missing-dependency and detected-v3 failures before host configuration generation. Interrupted installation, later write failures, repetition, and concurrent builds require recovery guarantees beyond the inspected code; no insecure terminal state was demonstrated.

Hardening Proposals

  • proposed — Validate the migration in a real Static Web Apps deployment using direct and proxied requests, encoded paths, attempted metadata-header overrides, and authorization-sensitive routes. Include interrupted-build recovery and rollback checks, and publish only a completed, consistent artifact.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 5 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title follows the Conventional Commits format with the feat type, azure scope, and a clear summary of the Azure Functions v4 migration.
Description check ✅ Passed The description explains the Azure Functions v4 migration and its implementation, dependency, runtime, and testing changes.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 5 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/nitro@4717

commit: 5aec01d

Ensure `@azure/functions@^4` is installed in the project (it is traced, not bundled), default `apiRuntime` to `node:22`, and build the request url from `req.url` instead of the decoded route param.

This branch was successfully deployed

1 active deployment
Preview — 5aec01da Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants