Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disabling introspection should also disable "Did you mean ...?" #7846

Closed
Sainan opened this issue Mar 9, 2024 · 3 comments
Closed

Disabling introspection should also disable "Did you mean ...?" #7846

Sainan opened this issue Mar 9, 2024 · 3 comments

Comments

@Sainan
Copy link

Sainan commented Mar 9, 2024

This is a somewhat well-known workaround to introspection being disabled, especially since a client can just send a bunch of queries in a single go. Those queries could e.g. be sourced from an English dictionary.

Example projects exploiting this:

@Sainan Sainan changed the title Disabling introspection should also enable "Did you mean ...?" Disabling introspection should also disable "Did you mean ...?" Mar 9, 2024
@glasser
Copy link
Member

glasser commented Mar 19, 2024

Duplicate of #3919. There are several workarounds in comments on that issue.

Would love to see progress made in the linked graphql-js issue!

@glasser glasser closed this as not planned Won't fix, can't repro, duplicate, stale Mar 19, 2024
@Sainan
Copy link
Author

Sainan commented Mar 19, 2024

A workaround like that is useless when not enabled by default. This is a security issue, not a preference issue.

Copy link
Contributor

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
For general questions, we recommend using StackOverflow or our discord server.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Apr 19, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants