Skip to content

Document safe transport contract for /graphql/stream and CORS - #23

Merged
charles2ke merged 2 commits into
mainfrom
copilot/restrict-get-graphql-stream
Sep 16, 2026
Merged

charles2ke merged 2 commits into
mainfrom
copilot/restrict-get-graphql-stream

Conversation

Copilot AI commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

GET /graphql/stream was documented as accepting the "same payload as /graphql", implying mutations could be triggered from a plain cross-origin GET — a CSRF risk that Apollo Server's default csrfPrevention otherwise guards against on /graphql.

README updates

  • GET /graphql/stream documented as read-only streaming: only query/subscription operations are accepted over GET; mutations sent via GET are rejected with 405 Method Not Allowed (already enforced by src/streaming/sseRouter.js).
  • Mutations documented as POST-only, requiring a CSRF-resistant request shape (non-simple Content-Type such as application/json and/or a custom header), consistent with Apollo Server's default CSRF prevention on /graphql.
  • Removed "same payload as /graphql" wording for GET, replaced with explicit limitations on what GET accepts.
  • Added a CORS section documenting that /graphql, /graphql/stream, and /export should be served behind an explicit origin allow-list, not a wildcard, in production.

This is a documentation-only change — no runtime code was modified, since the GET-mutation rejection is already implemented in sseRouter.js.

…and CORS allow-list expectations

Co-authored-by: charles2ke <6725706+charles2ke@users.noreply.github.com>
Copilot AI changed the title [WIP] Restrict GET operations on /graphql/stream to queries and subscriptions Document safe transport contract for /graphql/stream and CORS Sep 16, 2026
Copilot AI requested a review from charles2ke September 16, 2026 03:43
Comment thread README.md
@charles2ke
charles2ke marked this pull request as ready for review September 16, 2026 03:46
@charles2ke
charles2ke requested review from charles2ke and a lite review from Copilot September 16, 2026 03:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

Only a minor documentation nit remains; no blocking issues were identified.

Pull request overview

Documents safe GET streaming behavior, POST-only mutations, and production CORS guidance.

Changes:

  • Clarifies /graphql/stream accepts only queries and subscriptions over GET.
  • Documents CSRF-resistant mutation requests.
  • Adds explicit CORS allow-list guidance.
File summaries
File Summary
README.md Documents safe transport restrictions and CORS expectations.
Review details

Suppressed comments (1)

README.md:424

  • X-Requested-With is not one of the headers recognized by Apollo Server's default CSRF-prevention middleware. With a simple content type, a client following this example can still be rejected by /graphql; document Apollo's supported preflight headers (Apollo-Require-Preflight or X-Apollo-Operation-Name) instead, or omit the custom-header alternative.
custom header (e.g. `X-Requested-With`), matching the CSRF-prevention shape
that Apollo Server enforces by default on `/graphql`. Requests that omit
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@charles2ke
charles2ke merged commit 7a5034d into main Sep 16, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

4 participants