This repository has been archived by the owner on Sep 10, 2024. It is now read-only.
Disallow OAuth 2.0 use of the GraphQL API by default #3092
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes #3056
This adds a new flag on the
graphql
listener:undocumented_oauth2_access
.This is meant for internal use only as it is not documented, and not meant to be, as it is being replaced by the Admin API.
It also disables the GraphQL playground by default, as we don't really want people to mess with it anymore
What this does not cover is requesting the
urn:mas:graphql
scope. Right now, clients will still be able to request it, but I think this is fine.