# graphql-yoga-disable-introspection

> Disable introspection in graphql-yoga with a validation rule

Latest version **0.0.1** (published 2021-10-21) · MIT license · 0 weekly downloads

## Install

```sh
npm install graphql-yoga-disable-introspection
pnpm add graphql-yoga-disable-introspection
yarn add graphql-yoga-disable-introspection
bun add graphql-yoga-disable-introspection
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.0.1 |
| Published | 2021-10-21 |
| First published | 2021-10-21 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Unpacked size | 6.9 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 0 |
| Author | performautodev |
| Maintainers | performautodev |
| Keywords | GraphQL, Introspection, Node, disable, query, validation, rule |

## Links

- npm: https://www.npmjs.com/package/graphql-yoga-disable-introspection
- Repository: https://github.com/performautodev/graphql-yoga-disable-introspection
- Homepage: https://github.com/performautodev/graphql-yoga-disable-introspection#readme
- Issues: https://github.com/performautodev/graphql-yoga-disable-introspection/issues
- npm.io page: https://npm.io/package/graphql-yoga-disable-introspection

## Alternatives

- [gamedig](https://npm.io/package/gamedig.md) — 29.3K weekly downloads
- [join-monster](https://npm.io/package/join-monster.md) — 12.8K weekly downloads
- [masked](https://npm.io/package/masked.md) — 5.5K weekly downloads
- [@comunica/actor-query-process-explain-logical](https://npm.io/package/@comunica/actor-query-process-explain-logical.md) — 4.7K weekly downloads
- [@veracity/vui](https://npm.io/package/@veracity/vui.md) — 4.6K weekly downloads

## Recent versions

- 0.0.1 (latest) — 2021-10-21

## README

# graphql-disable-introspection fro graphql-yoga
Disable introspection queries in GraphQL with a simple validation rule. Queries that contain `__schema` or `__type` will fail validation with this rule. For example, the following queries will be rejected:

QUERY

```graphql
query {
  __schema {
    queryType {
      name
    }
  }
}
```

[BEFORE]  RESULT QUERY :

```graphql
{
    "data": {
        "__schema": {
            "types": [
                {
                    "name": "Query"
                },
                {
                    "name": "String"
                },
               ...
            ]
        }
    }
}
```

[AFTER] RESULT QUERY :

```graphql
{
    "errors": [
        {
            "message": "GraphQL introspection is not allowed, but the query contained __schema or __type",
            "locations": [
                {
                    "line": 2,
                    "column": 3
                }
            ]
        }
    ]
}
```


## Usage

The package can be installed from npm

```sh
npm install -save graphql-disable-introspection
```

It exports a single validation rule which you can pass to your node GraphQL server with the `validationRules` argument. 

Here's an example for `graphql-yoga`:

```diff
import express from 'express';
+ const NoIntrospection = require("graphql-disable-introspection");


// Start server
server.start(
  {
+   validationRules: [NoIntrospection],
    playground: false,
    port: 4000,
...

+ i changed the message 'GraphQL introspection is not allowed'
this repo moded | Forked from https://www.npmjs.com/package/graphql-disable-introspection

---
_Source: https://npm.io/package/graphql-yoga-disable-introspection · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
