.Net: Add server URL validation options for OpenAPI plugins#13631
Open
SergeyMenshykh wants to merge 3 commits intomicrosoft:mainfrom
Open
.Net: Add server URL validation options for OpenAPI plugins#13631SergeyMenshykh wants to merge 3 commits intomicrosoft:mainfrom
SergeyMenshykh wants to merge 3 commits intomicrosoft:mainfrom
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
westey-m
reviewed
Mar 4, 2026
dotnet/src/Functions/Functions.OpenApi/RestApiOperationServerUrlValidationOptions.cs
Show resolved
Hide resolved
westey-m
approved these changes
Mar 4, 2026
westey-m
approved these changes
Mar 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation and Context
When loading OpenAPI specifications, the SDK uses the
servers[].urlfield to construct HTTP request targets. This PR adds an opt-in mechanism for consumers to validate and restrict which URLs the OpenAPI plugin is allowed to call at runtime.Description
Introduces
RestApiOperationServerUrlValidationOptions, a new options class that can be configured viaOpenApiFunctionExecutionParameters.ServerUrlValidationOptionsto control outbound request targets:IReadOnlyList\<string\>?) — restricts which URI schemes are permitted. When null/empty, defaults tohttpsonly.IReadOnlyList\<Uri\>?) — restricts requests to URLs matching one of the specified base URL prefixes. When null, no base URL restriction is applied.Validation is performed in
RestApiOperationRunnerbefore any HTTP request is sent. WhenServerUrlValidationOptionsis not set (default), behavior is unchanged — no validation is performed.Changes
RestApiOperationServerUrlValidationOptionsOpenApiFunctionExecutionParameters: addedServerUrlValidationOptionsproperty ([Experimental("SKEXP0040")])RestApiOperationRunner: addedValidateUrl()with scheme and base URL checksOpenApiKernelPluginFactory: wires validation options through to the runnerUsage Example
Contribution Checklist