graphile / graphile/graphile.github.io

Add documentation on things to do before going into production

Offen
#27 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement
Vorherrschende Sprache
SCSS
Sterne
27
Forks
126
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

- [ ] Note that disabling GraphiQL does NOT prevent people from inspecting your schema/documentation/etc - they can just run it themselves
- [ ] Beware various security issues, break down by types of auth: JWT, cookies, etc
- [ ] Prevent DOS attacks - analyse incoming requests for complexity and only allow through if simple enough; require limits for all collections; etc etc. Simplest workaround is to just whitelist the queries you're using
- [ ] Ensure logging isn't too much!
- [ ] Ensure Row Level Security is enabled on every table

More to come

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Prüfe zuerst die vorhandene Dokumentation des Repositorys zu Produktion und Deployment; im Issue wird keine bestimmte Datei oder kein bestimmter Einstiegspunkt genannt. Verwandle die Checkliste in einen strukturierten Leitfaden zu GraphiQL-Sichtbarkeit, authentifizierungsspezifischer Sicherheit, Anforderungs- und Sammlungskomplexitätslimits, Logging und PostgreSQL Row-Level Security, wobei jede Empfehlung eindeutig umsetzbar sein soll.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
graphql, postgresql
Bereich
databases, documentation, security
Issue-Typ
Dokumentation
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
30/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.