Skip to content

Fix the Nitro tool answering refused GraphQL GET requests - #10483

Merged
glen-84 merged 2 commits into
mainfrom
gai/nitro-tool-accept-gate
Oct 5, 2026
Merged

glen-84 merged 2 commits into
mainfrom
gai/nitro-tool-accept-gate

Conversation

@glen-84

@glen-84 glen-84 commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

  • With the Nitro tool on, a GET or HEAD on the GraphQL endpoint path that no GraphQL middleware handled went to the tool, which answered with a 301 and then the Nitro page. A refused GraphQL GET, such as one sent while GET requests are disabled, therefore got HTML with a success status, and the 405 that Draft20260903 specifies for a disabled GET was reachable only with the tool off.
  • Such a request now reaches the tool only when its Accept header rates text/html above every media type the default response formatter writes, using its RFC 9110 range matching. The media types of a custom formatter are not part of this comparison, which the transport page documents. Ties, */*, a missing header, and an unparsable header count as GraphQL and get the endpoint's 404, or 405 with Allow under Draft20260903 when GET requests are disabled. MapGraphQL, and with it Fusion gateways, and the Azure Functions pipeline apply the gate. Browser navigation, the tool's sub-paths, and other methods are unchanged.
  • The answers change under every transport version, Legacy and Draft20250508 included, as an approved exception for 16.7. Health checks pointed at the GraphQL endpoint now get 404; the 16.6 to 16.7 migration guide documents this and points them at MapHealthChecks. The transport page states the rule and now says which requests a missing preflight header refuses.

Test plan

  • DefaultHttpResponseFormatterTests and the new HttpContextExtensionsTests pin the preference rule (browser headers, ties, wildcards, q=0, casing, several Accept lines) and the gate (GET and HEAD, trailing slash, site root, unparsable headers, other methods, and sub-paths).
  • GraphQLOverHttpSpecTests pin, with the tool on under Legacy, Draft20250508, and Draft20260903, the 404 or 405 and Allow for refused GET and HEAD requests, including on /graphql/, and the tool's redirect for a browser Accept, each with Vary: Accept. The Azure Functions in-process and isolated tests pin the same split for the embedded tool.
  • HotChocolate.AspNetCore.Tests, both Azure Functions test projects, and HotChocolate.Fusion.AspNetCore.Tests pass on net10.0.
  • In a browser, with the tool's default CDN serve mode, opening /graphql, reloading on /graphql/, running a query, and signing in all work.

Copilot AI lite review requested due to automatic review settings October 5, 2026 12:19
@github-actions github-actions Bot added 📚 documentation This issue is about working on our documentation. 🌶️ hot chocolate labels Oct 5, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The custom response formatter handling has an unresolved moderate issue, alongside a documentation correction.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

This PR updates Nitro routing so refused GraphQL GET/HEAD requests retain GraphQL responses unless HTML is explicitly preferred.

Changes:

  • Adds RFC 9110 Accept negotiation and Nitro gating.
  • Applies the gate to ASP.NET Core and Azure Functions.
  • Adds tests and documentation for transport and migration behavior.

Open findings: a moderate issue affects custom response formatters, and a nit requires documenting the Draft20260903 405 behavior.

File Reviewed change
website/​content/​docs/​hotchocolate/​server/​http-transport.md Documents Nitro preference and preflight behavior.
website/​content/​docs/​hotchocolate/​server/​endpoints.md Updates endpoint browser behavior guidance.
website/​content/​docs/​hotchocolate/​migrating/​migrate-from-16-6-to-16-7.md Documents migration and health-check impacts.
src/​HotChocolate/​AzureFunctions/​test/​HotChocolate.AzureFunctions.Tests/​InProcessEndToEndTests.cs Tests in-process Nitro routing.
src/​HotChocolate/​AzureFunctions/​test/​HotChocolate.AzureFunctions.IsolatedProcess.Tests/​IsolatedProcessEndToEndTests.cs Tests isolated-process Nitro routing.
src/​HotChocolate/​AzureFunctions/​src/​HotChocolate.AzureFunctions/​PipelineBuilder.cs Adds conditional pipeline branching.
src/​HotChocolate/​AzureFunctions/​src/​HotChocolate.AzureFunctions/​Extensions/​HotChocolateAzureFunctionServiceCollectionExtensions.cs Applies Nitro gating to Azure Functions.
src/​HotChocolate/​AspNetCore/​test/​AspNetCore.Tests/​GraphQLOverHttpSpecTests.cs Tests transport-version routing behavior.
src/​HotChocolate/​AspNetCore/​test/​AspNetCore.Tests/​Formatters/​DefaultHttpResponseFormatterTests.cs Tests media-type preference matching.
src/​HotChocolate/​AspNetCore/​test/​AspNetCore.Tests/​Extensions/​HttpContextExtensionsTests.cs Tests Nitro eligibility decisions.
src/​HotChocolate/​AspNetCore/​src/​AspNetCore.Pipeline/​Formatters/​DefaultHttpResponseFormatter.cs Implements media-type preference evaluation.
src/​HotChocolate/​AspNetCore/​src/​AspNetCore.Pipeline/​Extensions/​HttpRequestExtensions.cs Removes obsolete Accept handling.
src/​HotChocolate/​AspNetCore/​src/​AspNetCore.Pipeline/​Extensions/​HttpContextExtensions.cs Adds Nitro eligibility logic.
src/​HotChocolate/​AspNetCore/​src/​AspNetCore.Pipeline/​Extensions/​EndpointRouteBuilderExtensions.cs Gates ASP.NET Core Nitro middleware.
dictionary.txt Adds the health-check terminology.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread website/content/docs/hotchocolate/server/http-transport.md
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Patch coverage

100.0% of changed lines covered (90/90)

File Covered Changed Patch %
…/Extensions/EndpointRouteBuilderExtensions.cs 3 3 100.0% 🟢
…/src/AspNetCore.Pipeline/Extensions/HttpContextExtensions.cs 9 9 100.0% 🟢
…/Formatters/DefaultHttpResponseFormatter.cs 56 56 100.0% 🟢
…/HotChocolateAzureFunctionServiceCollectionExtensions.cs 3 3 100.0% 🟢
…/src/HotChocolate.AzureFunctions/PipelineBuilder.cs 19 19 100.0% 🟢

Project coverage: 57.9% (301162/520002 lines)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Only minor naming nits remain, with no blocking issues identified.

Review effort: Lite
Findings: None

Resolved since last review (2)

@glen-84
glen-84 merged commit 0fa5a99 into main Oct 5, 2026
159 checks passed
@glen-84
glen-84 deleted the gai/nitro-tool-accept-gate branch October 5, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📚 documentation This issue is about working on our documentation. 🌶️ hot chocolate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants