如何在Strapi生产模式下正确禁用GraphQL Playground
正确禁用Strapi GraphQL Playground的方案
你当前写入./config/plugins.js的初始配置如下:
module.exports = { graphql: { enabled: true, config: { endpoint: "/graphql", shadowCRUD: true, playgroundAlways: process.env.NODE_ENV === "development", depthLimit: 50, amountLimit: 100, defaultLimit: 100, maxLimit: 100, apolloServer: { tracing: true, }, }, }, ckeditor: true, };
后续尝试将playgroundAlways字段直接改为false:
playgroundAlways: false
修改后开发、生产环境仍可正常访问GraphQL Playground,可按以下步骤排查修复:
- 首先确认修改配置后已完全重启Strapi服务:Strapi插件配置不支持热更新,修改后必须终止当前运行的Node进程,重新执行对应的启动命令才会加载新配置,仅保存文件不会生效。
- 配置项补全:仅设置
playgroundAlways: false不足以完全关闭Playground,该字段是Strapi插件层的开关,还需要同步关闭Apollo Server内置的Playground开关,否则仍会透出访问入口。
全环境永久禁用Playground
直接修改./config/plugins.js中graphql相关配置为以下内容,保存后重启服务即可生效:
module.exports = { graphql: { enabled: true, config: { endpoint: "/graphql", shadowCRUD: true, playgroundAlways: false, depthLimit: 50, amountLimit: 100, defaultLimit: 100, maxLimit: 100, apolloServer: { tracing: true, playground: false, // 关闭Apollo内置Playground introspection: false, // 生产环境建议同步关闭接口内省,避免字段被恶意爬取 }, }, }, ckeditor: true, };
仅开发环境开启、生产环境禁用(推荐实践)
不要在全局配置中通过环境判断写死逻辑,可利用Strapi的环境配置覆盖能力,在./config/env/production/目录下新建plugins.js文件,写入生产环境专属配置,部署生产时会自动覆盖全局配置,无需手动改值:
// ./config/env/production/plugins.js module.exports = { graphql: { config: { playgroundAlways: false, apolloServer: { playground: false, introspection: false, }, }, }, };
全局配置中保留开发环境的开启逻辑即可。
排查提示:如果重启后依旧能访问Playground,先清空浏览器缓存再验证,部分浏览器会缓存Playground的静态资源导致页面仍可打开。
内容的提问来源于stack exchange,提问作者Sarah Diba
相关产品推荐
相关产品推荐

