pub struct ValidationConfig {
pub max_query_depth: Option<u32>,
pub max_query_complexity: Option<u32>,
pub max_response_bytes: Option<u64>,
pub max_page_size: Option<u32>,
}Expand description
Query validation limits (compiled from [validation] in fraiseql.toml).
Fields§
§max_query_depth: Option<u32>Maximum allowed query nesting depth; DEFAULT_MAX_QUERY_DEPTH when unset.
max_query_complexity: Option<u32>Maximum allowed query complexity score.
max_response_bytes: Option<u64>Maximum bytes a single read may deliver, measured on the rows that come back.
max_query_depth and max_query_complexity score a document — they are
the guard for fields resolved at runtime, where the work grows with the
shape of the request. They say nothing about a read served from a
materialised view, which is one row read whatever its nesting depth, and
whose cost is the bytes those rows weigh.
That is the quantity this bounds, and it is the only one that means the
same thing on every transport: a GraphQL document, a REST ?select=, a
gRPC column read and an NDJSON export all end in rows, and none of them
can be scored for size before the database has answered. So this is
enforced on the delivered rows rather than on the request — resolved once
at the read chokepoint, charged wherever the rows arrive.
A streamed read is cut at the frame that crosses the ceiling rather than being read to the end, so the bytes in the error are the running total at refusal, not the size of the whole answer.
None leaves reads unbounded by size, which is the previous behaviour.
max_page_size: Option<u32>Maximum number of rows a top-level first/last/limit argument may
request, guarding against unbounded-pagination denial of service (#421).
When unset, the runtime default (1000) applies; set to a large value to
raise the ceiling. The server also honours the FRAISEQL_MAX_PAGE_SIZE
environment variable as an override.
Trait Implementations§
Source§impl Clone for ValidationConfig
impl Clone for ValidationConfig
Source§impl Debug for ValidationConfig
impl Debug for ValidationConfig
Source§impl Default for ValidationConfig
impl Default for ValidationConfig
Source§impl<'de> Deserialize<'de> for ValidationConfigwhere
ValidationConfig: Default,
impl<'de> Deserialize<'de> for ValidationConfigwhere
ValidationConfig: Default,
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for ValidationConfig
Source§impl PartialEq for ValidationConfig
impl PartialEq for ValidationConfig
Source§impl Serialize for ValidationConfig
impl Serialize for ValidationConfig
impl StructuralPartialEq for ValidationConfig
Auto Trait Implementations§
impl Freeze for ValidationConfig
impl RefUnwindSafe for ValidationConfig
impl Send for ValidationConfig
impl Sync for ValidationConfig
impl Unpin for ValidationConfig
impl UnsafeUnpin for ValidationConfig
impl UnwindSafe for ValidationConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.