From 374b2afe6a4fe8217af610171eb9534294b3f41d Mon Sep 17 00:00:00 2001
From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com>
Date: Wed, 16 Sep 2026 03:42:07 +0000
Subject: [PATCH 1/2] Initial plan
From d294c3c51a76f82d8d30e9cdada6e492ea0f5ed8 Mon Sep 17 00:00:00 2001
From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com>
Date: Wed, 16 Sep 2026 03:43:08 +0000
Subject: [PATCH 2/2] docs: clarify /graphql/stream is read-only GET, mutations
POST-only, and CORS allow-list expectations
Co-authored-by: charles2ke <6725706+charles2ke@users.noreply.github.com>
---
README.md | 40 +++++++++++++++++++++++++++++++---------
1 file changed, 31 insertions(+), 9 deletions(-)
diff --git a/README.md b/README.md
index dfa1da7..cef96fb 100644
--- a/README.md
+++ b/README.md
@@ -408,18 +408,32 @@ curl http://localhost:4000/graphql \
## Streaming
-Subscriptions (and any query or mutation) can be streamed over Server-Sent
-Events at `POST|GET /graphql/stream`, which takes the same
-`query`/`variables`/`operationName` payload as `/graphql`. SSE keeps the
-transport plain HTTP — no WebSocket upgrade or extra service is required.
+Subscriptions can be streamed over Server-Sent Events at `POST|GET
+/graphql/stream`. **`GET` is read-only streaming**: it only accepts `query`
+and `subscription` operations, taken from plain `query`/`variables`/
+`operationName` query-string parameters, and is therefore safe to treat as a
+"simple" cross-origin request. This is *not* the same payload contract as
+`/graphql` — **mutations sent with `GET` are rejected with `405 Method Not
+Allowed`** so a mutating operation can never be triggered from a plain
+cross-site navigation or `
`/`