Skip to content

Prefer external URL in WWW-Authenticate header for RFC 9728#169658

Open
allenporter wants to merge 2 commits intohome-assistant:devfrom
allenporter:www-authenticate-fix
Open

Prefer external URL in WWW-Authenticate header for RFC 9728#169658
allenporter wants to merge 2 commits intohome-assistant:devfrom
allenporter:www-authenticate-fix

Conversation

@allenporter
Copy link
Copy Markdown
Contributor

Proposed change

Update the HTTP view request handler to use prefer_external=True when generating the resource metadata URL in the WWW-Authenticate header. This ensures that remote OAuth clients (targeted at MCP clients) can correctly locate authentication information.

This is working around a larger issue related to port matching that I am looking at in #169654. This is a smaller scoped changed for WWW-Authenticate to reduce the scope.

Chagnes:

  • Add comprehensive regression tests in test_view.py for URL matching.
  • Refactor test_view.py to use a cleaner, fixture-based approach for mocking the current request context.

Type of change

  • Dependency upgrade
  • Bugfix (non-breaking change which fixes an issue)
  • New integration (thank you!)
  • New feature (which adds functionality to an existing integration)
  • Deprecation (breaking change to happen in the future)
  • Breaking change (fix/feature causing existing functionality to break)
  • Code quality improvements to existing code or addition of tests

Additional information

Checklist

  • I understand the code I am submitting and can explain how it works.
  • The code change is tested and works locally.
  • Local tests pass. Your PR cannot be merged unless tests pass
  • There is no commented out code in this PR.
  • I have followed the development checklist
  • I have followed the perfect PR recommendations
  • The code has been formatted using Ruff (ruff format homeassistant tests)
  • Tests have been added to verify that the new code works.
  • Any generated code has been carefully reviewed for correctness and compliance with project standards.

If user exposed functionality or configuration variables are added/changed:

If the code communicates with devices, web services, or third-party tools:

  • The manifest file has all fields filled out correctly.
    Updated and included derived files by running: python3 -m script.hassfest.
  • New or updated dependencies have been added to requirements_all.txt.
    Updated by running python3 -m script.gen_requirements_all.
  • For the updated dependencies a diff between library versions and ideally a link to the changelog/release notes is added to the PR description.

To help with the load of incoming pull requests:

Update the HTTP view request handler to use `prefer_external=True` when
generating the resource metadata URL in the `WWW-Authenticate` header.
This ensures that remote OAuth clients (such as MCP clients) can correctly
locate authentication information, even when Home Assistant is accessed
via an internal URL that might not be reachable by the client.

This is working around a larger issue related to port matching against the urls.

- Add comprehensive regression tests in `test_view.py` for URL matching.
- Refactor `test_view.py` to use a cleaner, fixture-based approach for
  mocking the current request context.
Copilot AI review requested due to automatic review settings May 2, 2026 17:25
@allenporter allenporter requested a review from a team as a code owner May 2, 2026 17:25
@home-assistant
Copy link
Copy Markdown
Contributor

home-assistant Bot commented May 2, 2026

Hey there @home-assistant/core, mind taking a look at this pull request as it has been labeled with an integration (http) you are listed as a code owner for? Thanks!

Code owner commands

Code owners of http can trigger bot actions by commenting:

  • @home-assistant close Closes the pull request.
  • @home-assistant mark-draft Mark the pull request as draft.
  • @home-assistant ready-for-review Remove the draft status from the pull request.
  • @home-assistant rename Awesome new title Renames the pull request.
  • @home-assistant reopen Reopen the pull request.
  • @home-assistant unassign http Removes the current integration label and assignees on the pull request, add the integration domain after the command.
  • @home-assistant update-branch Update the pull request branch with the base branch.
  • @home-assistant add-label needs-more-information Add a label (needs-more-information, problem in dependency, problem in custom component, problem in config, problem in device, feature-request) to the pull request.
  • @home-assistant remove-label needs-more-information Remove a label (needs-more-information, problem in dependency, problem in custom component, problem in config, problem in device, feature-request) on the pull request.

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the HTTP request handler’s WWW-Authenticate header generation (RFC 9728 resource metadata link) to prefer the external URL, and adds regression tests to validate URL selection behavior.

Changes:

  • Call get_url(..., prefer_external=True) when building the resource_metadata URL for WWW-Authenticate.
  • Add/extend tests in tests/components/http/test_view.py to cover URL selection across internal/external configurations.
  • Introduce a fixture to set the current request context for these tests.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
homeassistant/helpers/http.py Forces external-preferred URL selection when building RFC 9728 resource_metadata in WWW-Authenticate.
tests/components/http/test_view.py Adds a request-context fixture and parametrized tests for WWW-Authenticate URL selection.

Comment thread tests/components/http/test_view.py
Comment thread tests/components/http/test_view.py Outdated
Comment thread homeassistant/helpers/http.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants