Repository navigation
Fix the Nitro tool answering refused GraphQL GET requests - #10483
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The custom response formatter handling has an unresolved moderate issue, alongside a documentation correction.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
This PR updates Nitro routing so refused GraphQL GET/HEAD requests retain GraphQL responses unless HTML is explicitly preferred.
Changes:
- Adds RFC 9110
Acceptnegotiation and Nitro gating. - Applies the gate to ASP.NET Core and Azure Functions.
- Adds tests and documentation for transport and migration behavior.
Open findings: a moderate issue affects custom response formatters, and a nit requires documenting the Draft20260903 405 behavior.
| File | Reviewed change |
|---|---|
website/content/docs/hotchocolate/server/http-transport.md |
Documents Nitro preference and preflight behavior. |
website/content/docs/hotchocolate/server/endpoints.md |
Updates endpoint browser behavior guidance. |
website/content/docs/hotchocolate/migrating/migrate-from-16-6-to-16-7.md |
Documents migration and health-check impacts. |
src/HotChocolate/AzureFunctions/test/HotChocolate.AzureFunctions.Tests/InProcessEndToEndTests.cs |
Tests in-process Nitro routing. |
src/HotChocolate/AzureFunctions/test/HotChocolate.AzureFunctions.IsolatedProcess.Tests/IsolatedProcessEndToEndTests.cs |
Tests isolated-process Nitro routing. |
src/HotChocolate/AzureFunctions/src/HotChocolate.AzureFunctions/PipelineBuilder.cs |
Adds conditional pipeline branching. |
src/HotChocolate/AzureFunctions/src/HotChocolate.AzureFunctions/Extensions/HotChocolateAzureFunctionServiceCollectionExtensions.cs |
Applies Nitro gating to Azure Functions. |
src/HotChocolate/AspNetCore/test/AspNetCore.Tests/GraphQLOverHttpSpecTests.cs |
Tests transport-version routing behavior. |
src/HotChocolate/AspNetCore/test/AspNetCore.Tests/Formatters/DefaultHttpResponseFormatterTests.cs |
Tests media-type preference matching. |
src/HotChocolate/AspNetCore/test/AspNetCore.Tests/Extensions/HttpContextExtensionsTests.cs |
Tests Nitro eligibility decisions. |
src/HotChocolate/AspNetCore/src/AspNetCore.Pipeline/Formatters/DefaultHttpResponseFormatter.cs |
Implements media-type preference evaluation. |
src/HotChocolate/AspNetCore/src/AspNetCore.Pipeline/Extensions/HttpRequestExtensions.cs |
Removes obsolete Accept handling. |
src/HotChocolate/AspNetCore/src/AspNetCore.Pipeline/Extensions/HttpContextExtensions.cs |
Adds Nitro eligibility logic. |
src/HotChocolate/AspNetCore/src/AspNetCore.Pipeline/Extensions/EndpointRouteBuilderExtensions.cs |
Gates ASP.NET Core Nitro middleware. |
dictionary.txt |
Adds the health-check terminology. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Contributor
Patch coverage100.0% of changed lines covered (90/90)
Project coverage: 57.9% (301162/520002 lines) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
301and then the Nitro page. A refused GraphQL GET, such as one sent while GET requests are disabled, therefore got HTML with a success status, and the405thatDraft20260903specifies for a disabled GET was reachable only with the tool off.Acceptheader ratestext/htmlabove every media type the default response formatter writes, using its RFC 9110 range matching. The media types of a custom formatter are not part of this comparison, which the transport page documents. Ties,*/*, a missing header, and an unparsable header count as GraphQL and get the endpoint's404, or405withAllowunderDraft20260903when GET requests are disabled.MapGraphQL, and with it Fusion gateways, and the Azure Functions pipeline apply the gate. Browser navigation, the tool's sub-paths, and other methods are unchanged.LegacyandDraft20250508included, as an approved exception for 16.7. Health checks pointed at the GraphQL endpoint now get404; the 16.6 to 16.7 migration guide documents this and points them atMapHealthChecks. The transport page states the rule and now says which requests a missing preflight header refuses.Test plan
DefaultHttpResponseFormatterTestsand the newHttpContextExtensionsTestspin the preference rule (browser headers, ties, wildcards,q=0, casing, severalAcceptlines) and the gate (GET and HEAD, trailing slash, site root, unparsable headers, other methods, and sub-paths).GraphQLOverHttpSpecTestspin, with the tool on underLegacy,Draft20250508, andDraft20260903, the404or405andAllowfor refused GET and HEAD requests, including on/graphql/, and the tool's redirect for a browserAccept, each withVary: Accept. The Azure Functions in-process and isolated tests pin the same split for the embedded tool.HotChocolate.AspNetCore.Tests, both Azure Functions test projects, andHotChocolate.Fusion.AspNetCore.Testspass onnet10.0./graphql, reloading on/graphql/, running a query, and signing in all work.