summaryrefslogtreecommitdiff
path: root/school/node_modules/graphql/validation/rules/custom/NoSchemaIntrospectionCustomRule.js.flow
diff options
context:
space:
mode:
authorMinteck <contact@minteck.org>2023-01-10 14:54:04 +0100
committerMinteck <contact@minteck.org>2023-01-10 14:54:04 +0100
commit99c1d9af689e5325f3cf535c4007b3aeb8325229 (patch)
treee663b3c2ebdbd67c818ac0c5147f0ce1d2463cda /school/node_modules/graphql/validation/rules/custom/NoSchemaIntrospectionCustomRule.js.flow
parent9871b03912fc28ad38b4037ebf26a78aa937baba (diff)
downloadpluralconnect-99c1d9af689e5325f3cf535c4007b3aeb8325229.tar.gz
pluralconnect-99c1d9af689e5325f3cf535c4007b3aeb8325229.tar.bz2
pluralconnect-99c1d9af689e5325f3cf535c4007b3aeb8325229.zip
Update - This is an automated commit
Diffstat (limited to 'school/node_modules/graphql/validation/rules/custom/NoSchemaIntrospectionCustomRule.js.flow')
-rw-r--r--school/node_modules/graphql/validation/rules/custom/NoSchemaIntrospectionCustomRule.js.flow38
1 files changed, 38 insertions, 0 deletions
diff --git a/school/node_modules/graphql/validation/rules/custom/NoSchemaIntrospectionCustomRule.js.flow b/school/node_modules/graphql/validation/rules/custom/NoSchemaIntrospectionCustomRule.js.flow
new file mode 100644
index 0000000..333ba41
--- /dev/null
+++ b/school/node_modules/graphql/validation/rules/custom/NoSchemaIntrospectionCustomRule.js.flow
@@ -0,0 +1,38 @@
+// @flow strict
+import { GraphQLError } from '../../../error/GraphQLError';
+
+import type { FieldNode } from '../../../language/ast';
+import type { ASTVisitor } from '../../../language/visitor';
+
+import { getNamedType } from '../../../type/definition';
+import { isIntrospectionType } from '../../../type/introspection';
+
+import type { ValidationContext } from '../../ValidationContext';
+
+/**
+ * Prohibit introspection queries
+ *
+ * A GraphQL document is only valid if all fields selected are not fields that
+ * return an introspection type.
+ *
+ * Note: This rule is optional and is not part of the Validation section of the
+ * GraphQL Specification. This rule effectively disables introspection, which
+ * does not reflect best practices and should only be done if absolutely necessary.
+ */
+export function NoSchemaIntrospectionCustomRule(
+ context: ValidationContext,
+): ASTVisitor {
+ return {
+ Field(node: FieldNode) {
+ const type = getNamedType(context.getType());
+ if (type && isIntrospectionType(type)) {
+ context.reportError(
+ new GraphQLError(
+ `GraphQL introspection has been disabled, but the requested query contained the field "${node.name.value}".`,
+ node,
+ ),
+ );
+ }
+ },
+ };
+}