【问题标题】:How does Apollo Server serve up its schema?Apollo Server 如何提供其模式?
【发布时间】:2021-01-09 01:40:32
【问题描述】:

我有一个问题,我的本地开发人员架构服务正常,但在我从 yarn 2 嵌套层次结构构建的 docker 容器中,它不服务架构,查询似乎工作正常。我想这是没有被复制到正确的地方,或者从正确的地方运行的东西,但我不确定它可能是什么。我在日志中没有看到任何错误,但我们可能没有在某个地方发现它们。这是请求/响应。

* Preparing request to http://localhost:4000/
* Current time is 2020-09-22T21:45:08.957Z
* Using libcurl/7.69.1 OpenSSL/1.1.1g zlib/1.2.11 brotli/1.0.7 libidn2/2.1.1 libssh2/1.9.0 nghttp2/1.41.0
* Using default HTTP version
* Disable timeout
* Enable automatic URL encoding
* Enable SSL validation
* Enable cookie sending with jar of 0 cookies
* Too old connection (2410 seconds), disconnect it
* Connection 47 seems to be dead!
* Closing connection 47
*   Trying ::1:4000...
* Connected to localhost (::1) port 4000 (#48)

> POST / HTTP/1.1
> Host: localhost:4000
> User-Agent: insomnia/2020.4.0
> Content-Type: application/json
> Accept: */*
> Content-Length: 1765

| {"query":"\n    query IntrospectionQuery {\n      __schema {\n        queryType { name }\n        mutationType { name }\n        subscriptionType { name }\n        types {\n          ...FullType\n        }\n        directives {\n          name\n          description\n          locations\n          args {\n            ...InputValue\n          }\n        }\n      }\n    }\n\n    fragment FullType on __Type {\n      kind\n      name\n      description\n      fields(includeDeprecated: true) {\n        name\n        description\n        args {\n          ...InputValue\n        }\n        type {\n          ...TypeRef\n        }\n        isDeprecated\n        deprecationReason\n      }\n      inputFields {\n        ...InputValue\n      }\n      interfaces {\n        ...TypeRef\n      }\n      enumValues(includeDeprecated: true) {\n        name\n        description\n        isDeprecated\n        deprecationReason\n      }\n      possibleTypes {\n        ...TypeRef\n      }\n    }\n\n    fragment InputValue on __InputValue {\n      name\n      description\n      type { ...TypeRef }\n      defaultValue\n    }\n\n    fragment TypeRef on __Type {\n      kind\n      name\n      ofType {\n        kind\n        name\n        ofType {\n          kind\n          name\n          ofType {\n            kind\n            name\n            ofType {\n              kind\n              name\n              ofType {\n                kind\n                name\n                ofType {\n                  kind\n                  name\n                  ofType {\n                    kind\n                    name\n                  }\n                }\n              }\n            }\n          }\n        }\n      }\n    }\n  ","operationName":"IntrospectionQuery"}

* upload completely sent off: 1765 out of 1765 bytes
* Mark bundle as not supporting multiuse

< HTTP/1.1 400 Bad Request
< X-Powered-By: Express
< Vary: Origin
< Access-Control-Allow-Credentials: true
< Content-Type: application/json; charset=utf-8
< Content-Length: 292
< ETag: W/"124-3pl/vJTvcH05VKWfKO4DAa/Thmw"
< Date: Tue, 22 Sep 2020 21:45:08 GMT
< Connection: keep-alive


 * Received 292 B chunk
 * Connection #48 to host localhost left intact

【问题讨论】:

    标签: typescript graphql apollo-server


    【解决方案1】:

    来自docs:

    introspection:如果为 true,则启用客户端的架构自省。

    默认值为 true,除非 NODE_ENV 环境变量设置为生产环境变量。

    如果您的NODE_ENV 环境变量设置为production,您需要确保将introspection 明确设置为true。 playground 选项也是如此。

    【讨论】:

    • 呵呵,我可以提出另一个问题,但为什么会在生产模式下禁用呢?信息曝光?
    • 如果您使架构易于访问,则假设您可以让恶意行为者更容易找到一些要暴露的漏洞。实际上,一个坚定的攻击者无论如何都可以通过检查流量来推测您的架构。实际上,您应该首先采取措施(授权、复杂性/深度限制、速率限制等)来防止滥用您的 API。禁用自省是一种空洞的姿态,不应不被视为标准做法。
    猜你喜欢
    • 2017-08-26
    • 2019-06-02
    • 1970-01-01
    • 2022-07-11
    • 2021-07-11
    • 2021-11-09
    • 2019-07-22
    • 2022-10-07
    • 2019-07-27
    相关资源
    最近更新 更多