The GraphQL endpoint built its gqlgen server with bare handler.New and no limits, so a single request with thousands of aliased resolver calls was parsed, validated, executed, and marshalled in full. Under load this let an unauthenticated client drive excessive CPU and memory use against POST /api/connect/v1/graphql and the console and trust endpoints, which share the same constructor (GHSA-prh2-g8pv-m7p9). Add configurable guards in the shared gqlutils.NewHandler: a parser token limit rejects oversized queries at lex time before any execution, a fixed complexity limit caps field-selection count, an LRU query cache avoids repeated parsing, and field suggestions are disabled. The limits flow from a new APIConfig.GraphQL section through server and api config into all three GraphQL handlers, with PROBOD_API_GRAPHQL_* env vars and Helm values exposed for per-environment tuning. Defaults are sized with generous headroom over real traffic: the parser token limit (15000) and complexity limit (2000) sit far above the largest legitimate frontend query yet well below the proof-of-concept flood, so normal usage is unaffected while floods are rejected cheaply. Signed-off-by: Bryan Frimin <bryan@probo.com>
9.5 KiB
9.5 KiB