From 374b2afe6a4fe8217af610171eb9534294b3f41d Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 16 Sep 2026 03:42:07 +0000 Subject: [PATCH 1/2] Initial plan From d294c3c51a76f82d8d30e9cdada6e492ea0f5ed8 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 16 Sep 2026 03:43:08 +0000 Subject: [PATCH 2/2] docs: clarify /graphql/stream is read-only GET, mutations POST-only, and CORS allow-list expectations Co-authored-by: charles2ke <6725706+charles2ke@users.noreply.github.com> --- README.md | 40 +++++++++++++++++++++++++++++++--------- 1 file changed, 31 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index dfa1da7..cef96fb 100644 --- a/README.md +++ b/README.md @@ -408,18 +408,32 @@ curl http://localhost:4000/graphql \ ## Streaming -Subscriptions (and any query or mutation) can be streamed over Server-Sent -Events at `POST|GET /graphql/stream`, which takes the same -`query`/`variables`/`operationName` payload as `/graphql`. SSE keeps the -transport plain HTTP — no WebSocket upgrade or extra service is required. +Subscriptions can be streamed over Server-Sent Events at `POST|GET +/graphql/stream`. **`GET` is read-only streaming**: it only accepts `query` +and `subscription` operations, taken from plain `query`/`variables`/ +`operationName` query-string parameters, and is therefore safe to treat as a +"simple" cross-origin request. This is *not* the same payload contract as +`/graphql` — **mutations sent with `GET` are rejected with `405 Method Not +Allowed`** so a mutating operation can never be triggered from a plain +cross-site navigation or ``/`