Merge pull request #6303 from Ocelot-Social-Community/fix-graphiql-helmet

fix(backend): helmet + graphiql
This commit is contained in:
Ulf Gebhardt 2023-05-16 12:08:35 +02:00 committed by GitHub
commit fef12f51c0
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -82,7 +82,11 @@ const createServer = (options) => {
const app = express()
app.set('driver', driver)
app.use(helmet())
// TODO: this exception is required for the graphql playground, since the playground loads external resources
// See: https://github.com/graphql/graphql-playground/issues/1283
app.use(
helmet(CONFIG.DEBUG && { contentSecurityPolicy: false, crossOriginEmbedderPolicy: false }),
)
app.use('/.well-known/', webfinger())
app.use(express.static('public'))
app.use(bodyParser.json({ limit: '10mb' }))