overblog-GraphQLBundle生产环境POST请求失效,求助配置支持Mutation
Hey there, let's work through this GraphQL POST issue you're hitting in production! That "Unrecognized token '<'" error is a dead giveaway that your POST request is getting an HTML response (like a 404 page) instead of the expected JSON from your GraphQL endpoint. Since GET works fine, the problem is almost certainly related to how production is handling POST requests to your GraphQL route. Here are the most likely fixes to check:
1. Verify your production endpoint & routing configuration
- Double-check that your POST request is targeting the exact same endpoint as your working GET requests. Sometimes production setups use different paths (e.g.,
/api/graphqlinstead of just/graphql) or have routing rules that redirect/block POSTs. - If you're using a reverse proxy like Nginx or Apache, make sure it's configured to allow POST requests to your GraphQL endpoint. For example, in Nginx, your location block should explicitly permit POST (and not just GET):
location /graphql { proxy_pass http://your-graphql-service:4000; proxy_set_header Content-Type application/json; # Ensure POST is allowed if ($request_method !~ ^(GET|POST)$) { return 405; } } - Confirm that the proxy isn't stripping or modifying the request body for POST calls—this can cause your GraphQL server to reject the request and return a 404.
2. Check CORS settings for cross-origin requests
If your frontend is hosted on a different domain than your GraphQL server in production:
- Make sure your CORS configuration explicitly allows the
POSTmethod. TheAccess-Control-Allow-Methodsheader should includePOST(along withGETif you need it). - Verify that
Access-Control-Allow-HeadersincludesContent-Type, since GraphQL POST requests rely on sending JSON payloads with this header.
3. Ensure your POST requests have the correct Content-Type
- GraphQL POST requests must send a
Content-Type: application/jsonheader. If your client isn't setting this, your server might not recognize the request as a valid GraphQL call and return a 404 instead. - Test this in Altair by explicitly adding the
Content-Typeheader to your POST request—if that works, make sure your production frontend code includes this header for all GraphQL POST/mutation calls.
4. Rule out middleware/firewall interference
- Production environments often have WAFs (Web Application Firewalls), Cloudflare rules, or server-side middleware that might block or alter POST requests. Check your server's access logs to confirm if the POST requests are even reaching your GraphQL service.
- If you're using Cloudflare, temporarily disable any security rules that might be flagging POST requests as malicious to test if that's the issue.
5. Confirm your GraphQL server supports POST
While most GraphQL servers (like Apollo Server, GraphQL Yoga) support POST by default, if you've customized your server's route handling, double-check that you haven't accidentally disabled POST method support. For example, in a Node.js Express setup, make sure you're using app.post() for your GraphQL endpoint alongside app.get().
Once you work through these checks, you should be able to pinpoint why POST requests are failing and get your mutations working in production. Good luck!
内容的提问来源于stack exchange,提问作者FOKO THierry

