Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,14 @@ const ComplexityLimitRule = createComplexityLimitRule(1000, {
});
```

By default, the validation rule applies a custom, lower cost factor for lists of introspection types, to prevent introspection queries from having unreasonably high costs. You can adjust this by setting `introspectionListFactor` on the configuration object.

```js
const ComplexityLimitRule = createComplexityLimitRule(1000, {
introspectionListFactor: 10, // Default is 2.
});
```

[build-badge]: https://img.shields.io/travis/4Catalyzer/graphql-validation-complexity/master.svg
[build]: https://travis-ci.org/4Catalyzer/graphql-validation-complexity

Expand Down
34 changes: 31 additions & 3 deletions src/index.js
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
import {
getVisitFn, GraphQLError, GraphQLNonNull, GraphQLList, GraphQLObjectType,
} from 'graphql';
import * as IntrospectionTypes from 'graphql/type/introspection';

export class CostCalculator {
constructor() {
Expand Down Expand Up @@ -46,15 +47,20 @@ export class ComplexityVisitor {
scalarCost = 1,
objectCost = 0,
listFactor = 10,

// Special list factor to make schema queries not have huge costs.
introspectionListFactor = 2,
}) {
this.context = context;

this.scalarCost = scalarCost;
this.objectCost = objectCost;
this.listFactor = listFactor;
this.introspectionListFactor = introspectionListFactor;

this.currentFragment = null;
this.listDepth = 0;
this.introspectionListDepth = 0;

this.rootCalculator = new CostCalculator();
this.fragmentCalculators = Object.create(null);
Expand All @@ -80,7 +86,12 @@ export class ComplexityVisitor {
if (type instanceof GraphQLNonNull) {
this.enterType(type.ofType);
} else if (type instanceof GraphQLList) {
++this.listDepth;
if (this.isIntrospectionList(type)) {
++this.introspectionListDepth;
} else {
++this.listDepth;
}

this.enterType(type.ofType);
} else {
const fieldCost = type instanceof GraphQLObjectType ?
Expand All @@ -89,13 +100,25 @@ export class ComplexityVisitor {
}
}

isIntrospectionList({ ofType }) {
let type = ofType;
if (type instanceof GraphQLNonNull) {
type = type.ofType;
}

return IntrospectionTypes[type.name] === type;
}

getCalculator() {
return this.currentFragment === null ?
this.rootCalculator : this.fragmentCalculators[this.currentFragment];
}

getDepthFactor() {
return this.listFactor ** this.listDepth;
return (
this.listFactor ** this.listDepth *
this.introspectionListFactor ** this.introspectionListDepth
);
}

leaveField() {
Expand All @@ -106,7 +129,12 @@ export class ComplexityVisitor {
if (type instanceof GraphQLNonNull) {
this.leaveType(type.ofType);
} else if (type instanceof GraphQLList) {
--this.listDepth;
if (this.isIntrospectionList(type)) {
--this.introspectionListDepth;
} else {
--this.listDepth;
}

this.leaveType(type.ofType);
}
}
Expand Down
22 changes: 20 additions & 2 deletions test/ComplexityVisitor.test.js
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
import { parse, TypeInfo, ValidationContext, visit, visitWithTypeInfo }
from 'graphql';
import {
introspectionQuery,
parse,
TypeInfo,
ValidationContext,
visit,
visitWithTypeInfo,
} from 'graphql';

import { ComplexityVisitor } from '../src';

Expand Down Expand Up @@ -128,4 +134,16 @@ describe('ComplexityVisitor', () => {
expect(visitor.getCost()).toBe(54);
});
});

describe('introspection query', () => {
it('should calculate a reduced cost for the introspection query', () => {
const ast = parse(introspectionQuery);

const context = new ValidationContext(schema, ast, typeInfo);
const visitor = new ComplexityVisitor(context, {});

visit(ast, visitWithTypeInfo(typeInfo, visitor));
expect(visitor.getCost()).toBeLessThan(1000);
});
});
});