-
Notifications
You must be signed in to change notification settings - Fork 323
Closed
Labels
in: webIssues related to web handlingIssues related to web handlingstatus: supersededIssue is superseded by anotherIssue is superseded by anothertype: enhancementA general enhancementA general enhancement
Description
According to the OWASP cheatsheet for GraphQL, GraphiQL and introspection should not be on and accessible without authentication by default. For now simply having GraphiQL disabled by default, but beyond that we need to consider the options more broadly. How it works out of the box, how it is configured and controlled, how it relates to development mode, security settings, and so on.
Metadata
Metadata
Assignees
Labels
in: webIssues related to web handlingIssues related to web handlingstatus: supersededIssue is superseded by anotherIssue is superseded by anothertype: enhancementA general enhancementA general enhancement