Arwid ThornströmandGitHub c68c182b64 3010: Apollo 4 major update and complete security overhaul to prepare for public api support
* 2919: rewrite for update to apollo 4 (#131)

* rewrite for update to apollo 4

* removed container tests, edited make to publish any branch to staging

* revert makefile

* cleanup

* update 1

* more fixes to get it working on aws

* enabled csrf prevention protection, testing if build works

* switched to express version

* changed the healthcheck url

* added cache to restdatasources

* 3011: create a login mutation on graphql server that responds with a access token (#133)

* 3011 added login rest endpoint and general scope fixes

* changed login auth to basic auth username and password

* minor changes from CR feedback

* force update

* added tighter timeout for idle knex connection

* Refactor authentication and scopes (#134)

* big refactor of scopes in graphql

* cr fixes

* some security fixes (#135)

* some security fixes

* cleanup

* update staging

* minor readme change
2022-12-12 12:58:24 +01:00
2022-02-23 13:05:44 +01:00
2021-10-11 16:53:18 +02:00
2021-06-17 11:04:22 +02:00
2021-07-26 10:35:52 +02:00
WIP
2021-04-06 09:56:18 +02:00
2021-07-26 10:35:52 +02:00

graphql-api-js

Apollo graphql api server for Photowall

This servers runs in two instances on AWS. graphql.photowall.com is used for photowall admin. data.photowall.com is used by the website (client).
When clients want to use the public data.photowall.com they use the /login REST endpoint to retreive a BearerToken with restricted cognito scopes. They can then access certain product and designer information with the token.

Third party systems like Unbox (Synergy) will use the graphql.photowall.com to read their data like they are doing now. This is to make sure the website wont be affected by larger downloads of data like unbox does. Unbox has their own cognito app client with limited scopes.

Run it locally

Create an .env file (see .env.example for what to set). COGNITO_LOGIN_CLIENT_SECRET, COGNITO_LOGIN_CLIENT_ID is found in cognito photowall-test-staff pool. In photowall-web-test-client app.

Development

This project does only run in docker, so when developing start the docker environment and let it updated when changing files. Sometimes the watch for files doesnt trigger. Like when you edit the .graphql file. Then just edit a .ts file and it will reload.

Run

$ npm install
$ docker compose build
$ docker compose up

For testing use a tool like Insomnia or similar. Server is running on http://localhost:4000/ and to connect you need to use basic auth with username and password from "GraphQl Basic Auth" in lastpass. If you wish the Bearer Token used in prodlike environment also works.

If you dont have access to photowall shared lastpass please contact any collegaue.

If you use Insomnia ask a colleague for the queries that can be exported/imported from Insomnia. To tests the data.photowall.com its possible to run the login rest endpoint to get a Bearer accessToken. Check code for username and password.

Run prod-like container locally

Run

$ docker compose -f docker-compose-prodlike.yml build
$ docker compose -f docker-compose-prodlike.yml up

Get your AD-token from this path in the browser <url to photowall>/admin/auth/token Take the value of the token param and add header in insomnia:Authorization: Bearer . The token is valid for 2-3 hours.

Run tests

Tests

npm test

Force update the staging

update 3

S
Description
No description provided
Readme
1.4 MiB
Languages
TypeScript 96.2%
Makefile 2.9%
JavaScript 0.7%
Dockerfile 0.2%