Securing Public GraphQL APIs with Persisted Query Allowlists
Stop arbitrary GraphQL execution on public endpoints by implementing a SHA-256 persisted query allowlist, separating public identity-based access from internal ad-hoc querying.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
Stop arbitrary GraphQL execution on public endpoints by implementing a SHA-256 persisted query allowlist, separating public identity-based access from internal ad-hoc querying.
Transitioning from automatic persisted queries to static persisted queries in Apollo Server v4 causes production 'Query not found' errors. In development, the server successfully caches hashes on-the-fly when the client sends full query strings. However, the production environment is configured to rely on a pre-computed mapping file to restrict arbitrary que