Replies: 2 comments 6 replies
-
Not aginst a fix here to help you but would it be possible for you to share a bit more on the usecase as if this is allowed then any user sent query would be executed. Trying to understand your usecase so i can come-up with a fix without creating a user experience issue where folks open up their db mistake. Would you be ok with a |
Beta Was this translation helpful? Give feedback.
-
new config param |
Beta Was this translation helpful? Give feedback.
-
Hi @dosco , how are you?
We would like to use the DisableAllowList config option in production mode, but seems that it is not possible to do that at this moment.
Would it be possible to change this line https://github.com/dosco/graphjin/blob/master/core/api.go#L316 to be
if !gj.conf.DisableAllowList {
so that the only thing that dictates the usage of the allow list is the DisableAllowList flag, and give the flexibility to disable it in production in that way?Thanks,
Andres
Beta Was this translation helpful? Give feedback.
All reactions