graphprotocol / graphprotocol/graph-node
[Feature] Need a environment variable for Alias limit in GraphQL
まだ誰も着手していません。
- 主要言語
- Rust
- スター
- 3.2k
- フォーク
- 1.1k
- 平均マージ
- 4日 1時間
- マージ済み PR(30日)
- 1
説明
Description
I use the docker to start graphnode postgres and ipfs , I can find the GRAPH_GRAPHQL_MAX_DEPTH in Environment Variables, but I can not find Alias limit in GraphQL.
Maybe you can add the environment variable .
According to this blog https://checkmarx.com/blog/alias-and-directive-overloading-in-graphql/
When we talk about preventing DoS in GraphQL, we’re usually discussing how to handle complex queries with deeply nested or circular relationships or even about preventing batching attacks, but it’s not often that alias and directives are mentioned as potential vectors.
Are you aware of any blockers that must be resolved before implementing this feature? If so, which? Link to any relevant GitHub issues.
No response
Some information to help us out
- Tick this box if you plan on implementing this feature yourself.
- I have searched the issue tracker to make sure this issue is not a duplicate.
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
まず、既存の GRAPH_GRAPHQL_MAX_DEPTH 環境変数の処理と、GraphQL クエリ制限の設定を見つけます。Docker 環境変数がどのように文書化および設定されているかを確認し、既存の深さ制限と併せてエイリアス制限を設定して適用できることを検証します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- docker, graphql, rust
- 領域
- api, devops, security
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 停滞
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 35/100