Skip to content

Request for HASURA_GRAPHQL_MAX_ALIAS_COUNT configurable in Hasura Cloud instance #10620

Open
@alex-sl-eng

Description

Is your proposal related to a problem?

We need the option to configure the limitation of alias allowed in single GraphQL query to address batching attack (a known security issue in GraphQL)

https://lab.wallarm.com/graphql-batching-attack/

Describe the solution you'd like

Ability to configure the alias limitation in Hasura Cloud instance: HASURA_GRAPHQL_MAX_ALIAS_COUNT

Describe alternatives you've considered

None

Metadata

Assignees

No one assigned

    Labels

    k/enhancementNew feature or improve an existing feature

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions