graphile / graphile/graphile.github.io
Add documentation on things to do before going into production
- Vorherrschende Sprache
- SCSS
- Sterne
- 27
- Forks
- 126
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
- [ ] Note that disabling GraphiQL does NOT prevent people from inspecting your schema/documentation/etc - they can just run it themselves
- [ ] Beware various security issues, break down by types of auth: JWT, cookies, etc
- [ ] Prevent DOS attacks - analyse incoming requests for complexity and only allow through if simple enough; require limits for all collections; etc etc. Simplest workaround is to just whitelist the queries you're using
- [ ] Ensure logging isn't too much!
- [ ] Ensure Row Level Security is enabled on every table
More to come
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Rechercherichtung
Prüfe zuerst die vorhandene Dokumentation des Repositorys zu Produktion und Deployment; im Issue wird keine bestimmte Datei oder kein bestimmter Einstiegspunkt genannt. Verwandle die Checkliste in einen strukturierten Leitfaden zu GraphiQL-Sichtbarkeit, authentifizierungsspezifischer Sicherheit, Anforderungs- und Sammlungskomplexitätslimits, Logging und PostgreSQL Row-Level Security, wobei jede Empfehlung eindeutig umsetzbar sein soll.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- graphql, postgresql
- Bereich
- databases, documentation, security
- Issue-Typ
- Dokumentation
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 30/100