Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Add configurable validation security rules #1244

Merged
merged 5 commits into from
Oct 7, 2021
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions config/schema/graphql.schema.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,15 @@ graphql.graphql_servers.*:
batching:
type: boolean
label: 'Batching'
disable_introspection:
type: boolean
label: 'Disable Introspection'
query_depth:
type: integer
label: 'Max query depth'
query_complexity:
type: integer
label: 'Max query complexity'
schema_configuration:
type: 'graphql.schema.[%parent.schema]'
persisted_queries_settings:
Expand Down
112 changes: 109 additions & 3 deletions src/Entity/Server.php
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@
use GraphQL\Server\Helper;
use GraphQL\Type\Definition\ResolveInfo;
use GraphQL\Validator\DocumentValidator;
use GraphQL\Validator\Rules\DisableIntrospection;
use GraphQL\Validator\Rules\QueryComplexity;
use GraphQL\Validator\Rules\QueryDepth;

/**
* The main GraphQL configuration and request entry point.
Expand Down Expand Up @@ -59,7 +62,10 @@
* "endpoint",
* "debug_flag",
* "caching",
* "batching"
* "batching",
* "disable_introspection",
* "query_depth",
* "query_complexity"

This comment was marked as resolved.

* },
* links = {
* "collection" = "/admin/config/graphql/servers",
Expand Down Expand Up @@ -123,6 +129,27 @@ class Server extends ConfigEntityBase implements ServerInterface {
*/
public $batching = TRUE;

/**
* Whether to disable query introspection.
*
* @var bool
*/
public $disable_introspection = FALSE;

/**
* The query complexity.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should be similar to the form description like "The maximum allowed query complexity, NULL means unlimited."

*
* @var int|null
*/
public $query_complexity = NULL;

/**
* The query depth.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

same here

*
* @var int|null
*/
public $query_depth = NULL;

/**
* The server's endpoint.
*
Expand All @@ -137,7 +164,6 @@ class Server extends ConfigEntityBase implements ServerInterface {
*/
public $persisted_queries_settings = [];


/**
* Persisted query plugin instances available on this server.
*
Expand Down Expand Up @@ -498,10 +524,90 @@ protected function getValidationRules() {
return [];
}

return array_values(DocumentValidator::defaultRules());
$rules = array_values(DocumentValidator::defaultRules());
if ($this->getDisableIntrospection()) {
$rules[] = new DisableIntrospection();
}
if ($this->getQueryDepth()) {
$rules[] = new QueryDepth($this->getQueryDepth());
}
if ($this->getQueryComplexity()) {
$rules[] = new QueryComplexity($this->getQueryComplexity());
}

return $rules;
};
}

/**
* Gets disable introspection config.
*
* @return bool
* The disable introspection config, FALSE otherwise.
*/
public function getDisableIntrospection(): bool {
return (bool) $this->disable_introspection;
}

/**
* Sets disable introspection config.
*
* @param bool $introspection
* The value for the disable introspection config.
*
* @return $this
*/
public function setDisableIntrospection(bool $introspection) {
$this->disable_introspection = $introspection;
return $this;
}

/**
* Gets query depth config.
*
* @return int|null
* The query depth, NULL otherwise.
*/
public function getQueryDepth(): ?int {
return (int) $this->query_depth;
}

/**
* Sets query depth config.
*
* @param int|null $depth
* The value for the query depth config.
*
* @return $this
*/
public function setQueryDepth(?int $depth) {
$this->query_depth = $depth;
return $this;
}

/**
* Gets query complexity config.
*
* @return int|null
* The query complexity, NULL otherwise.
*/
public function getQueryComplexity(): ?int {
return (int) $this->query_complexity;
}

/**
* Sets query complexity config.
*
* @param int|null $complexity
* The value for the query complexity config.
*
* @return $this
*/
public function setQueryComplexity(?int $complexity) {
$this->query_complexity = $complexity;
return $this;
}

/**
* {@inheritDoc}
*/
Expand Down
26 changes: 26 additions & 0 deletions src/Form/ServerForm.php
Original file line number Diff line number Diff line change
Expand Up @@ -186,6 +186,32 @@ public function form(array $form, FormStateInterface $formState): array {
'#description' => $this->t('Whether caching of queries and partial results is enabled.'),
];

$form['validation'] = [
'#title' => $this->t('Validation rules'),
'#type' => 'fieldset',
];

$form['validation']['disable_introspection'] = [
'#title' => $this->t('Disable introspection'),
'#type' => 'checkbox',
'#default_value' => $server->get('disable_introspection'),
'#description' => $this->t('Security rule: Whether introspection should be disabled.'),
];

$form['validation']['query_depth'] = [
'#title' => $this->t('Max query depth'),
'#type' => 'number',
'#default_value' => $server->get('query_depth'),
'#description' => $this->t('Security rule: The maximum allowed depth of nested queries. Leave empty to set unlimited.'),
];

$form['validation']['query_complexity'] = [
'#title' => $this->t('Max query complexity'),
'#default_value' => $server->get('query_complexity'),
'#type' => 'number',
'#description' => $this->t('Security rule: The maximum allowed complexity of a query. Leave empty to set unlimited.'),
];

$debug_flags = $server->get('debug_flag') ?? 0;
$form['debug_flag'] = [
'#title' => $this->t('Debug settings'),
Expand Down