You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Strapi生产模式下正确禁用GraphQL Playground

正确禁用Strapi GraphQL Playground的方案

你当前写入./config/plugins.js的初始配置如下:

module.exports = {
  graphql: {
    enabled: true,
    config: {
      endpoint: "/graphql",
      shadowCRUD: true,
      playgroundAlways: process.env.NODE_ENV === "development",
      depthLimit: 50,
      amountLimit: 100,
      defaultLimit: 100,
      maxLimit: 100,
      apolloServer: {
        tracing: true,
      },
    },
  },
  ckeditor: true,
};

后续尝试将playgroundAlways字段直接改为false:

playgroundAlways: false

修改后开发、生产环境仍可正常访问GraphQL Playground,可按以下步骤排查修复:

  • 首先确认修改配置后已完全重启Strapi服务:Strapi插件配置不支持热更新,修改后必须终止当前运行的Node进程,重新执行对应的启动命令才会加载新配置,仅保存文件不会生效。
  • 配置项补全:仅设置playgroundAlways: false不足以完全关闭Playground,该字段是Strapi插件层的开关,还需要同步关闭Apollo Server内置的Playground开关,否则仍会透出访问入口。

全环境永久禁用Playground

直接修改./config/plugins.js中graphql相关配置为以下内容,保存后重启服务即可生效:

module.exports = {
  graphql: {
    enabled: true,
    config: {
      endpoint: "/graphql",
      shadowCRUD: true,
      playgroundAlways: false,
      depthLimit: 50,
      amountLimit: 100,
      defaultLimit: 100,
      maxLimit: 100,
      apolloServer: {
        tracing: true,
        playground: false, // 关闭Apollo内置Playground
        introspection: false, // 生产环境建议同步关闭接口内省,避免字段被恶意爬取
      },
    },
  },
  ckeditor: true,
};

仅开发环境开启、生产环境禁用(推荐实践)

不要在全局配置中通过环境判断写死逻辑,可利用Strapi的环境配置覆盖能力,在./config/env/production/目录下新建plugins.js文件,写入生产环境专属配置,部署生产时会自动覆盖全局配置,无需手动改值:

// ./config/env/production/plugins.js
module.exports = {
  graphql: {
    config: {
      playgroundAlways: false,
      apolloServer: {
        playground: false,
        introspection: false,
      },
    },
  },
};

全局配置中保留开发环境的开启逻辑即可。

排查提示:如果重启后依旧能访问Playground,先清空浏览器缓存再验证,部分浏览器会缓存Playground的静态资源导致页面仍可打开。

内容的提问来源于stack exchange,提问作者Sarah Diba

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.30 04:24:13