Files
graphql-api-js/README.md
T
Arwid ThornströmandGitHub c68c182b64 3010: Apollo 4 major update and complete security overhaul to prepare for public api support
* 2919: rewrite for update to apollo 4 (#131)

* rewrite for update to apollo 4

* removed container tests, edited make to publish any branch to staging

* revert makefile

* cleanup

* update 1

* more fixes to get it working on aws

* enabled csrf prevention protection, testing if build works

* switched to express version

* changed the healthcheck url

* added cache to restdatasources

* 3011: create a login mutation on graphql server that responds with a access token (#133)

* 3011 added login rest endpoint and general scope fixes

* changed login auth to basic auth username and password

* minor changes from CR feedback

* force update

* added tighter timeout for idle knex connection

* Refactor authentication and scopes (#134)

* big refactor of scopes in graphql

* cr fixes

* some security fixes (#135)

* some security fixes

* cleanup

* update staging

* minor readme change
2022-12-12 12:58:24 +01:00

60 lines
2.3 KiB
Markdown

# graphql-api-js
Apollo graphql api server for Photowall
This servers runs in two instances on AWS. `graphql.photowall.com` is used for photowall admin. `data.photowall.com` is used by the website (client).
When clients want to use the public `data.photowall.com` they use the `/login` REST endpoint to retreive a BearerToken with restricted cognito scopes. They can then access certain product and designer information with the token.
Third party systems like Unbox (Synergy) will use the `graphql.photowall.com` to read their data like they are doing now. This is to make sure the website wont be affected by larger downloads of data like unbox does. Unbox has their own cognito app client with limited scopes.
## Run it locally
Create an .env file (see .env.example for what to set).
`COGNITO_LOGIN_CLIENT_SECRET`, `COGNITO_LOGIN_CLIENT_ID` is found in cognito `photowall-test-staff` pool. In `photowall-web-test-client` app.
### Development
This project does only run in docker, so when developing start the docker environment and let it updated when changing files. Sometimes the watch for files doesnt trigger. Like when you edit the .graphql file. Then just edit a .ts file and it will reload.
Run
```
$ npm install
$ docker compose build
$ docker compose up
```
For testing use a tool like Insomnia or similar. Server is running on http://localhost:4000/ and to
connect you need to use `basic auth` with username and password from "GraphQl Basic Auth" in lastpass.
If you wish the Bearer Token used in prodlike environment also works.
If you dont have access to photowall shared lastpass please contact any collegaue.
If you use Insomnia ask a colleague for the queries that can be exported/imported from Insomnia.
To tests the data.photowall.com its possible to run the login rest endpoint to get a Bearer accessToken. Check code for username and password.
### Run prod-like container locally
Run
```
$ docker compose -f docker-compose-prodlike.yml build
$ docker compose -f docker-compose-prodlike.yml up
```
Get your AD-token from this path in the browser `<url to photowall>/admin/auth/token`
Take the value of the token param and add header in insomnia:Authorization: Bearer <token>.
The token is valid for 2-3 hours.
## Run tests
Tests
```
npm test
```
### Force update the staging
update 3