Skip to content

Latest commit

 

History

History
156 lines (151 loc) · 8.87 KB

File metadata and controls

156 lines (151 loc) · 8.87 KB

* This report was auto-generated by graphql-http

GraphQL over HTTP audit report

  • 68 audits in total
  • 65 pass
  • 💡 3 notices (suggestions)

Passing

  1. 22EB MUST accept application/graphql-response+json and match the content-type
  2. 4655 MUST accept application/json and match the content-type
  3. 47DE SHOULD accept */* and use application/graphql-response+json or application/json for the content-type
  4. 80D8 SHOULD assume application/json or application/graphql-response+json content-type when accept is missing
  5. 82A3 MUST use utf-8 encoding when responding
  6. BF61 MUST accept utf-8 encoded request
  7. 78D5 MUST assume utf-8 in request if encoding is unspecified
  8. 2C94 MUST accept POST requests
  9. 5A70 MAY accept application/x-www-form-urlencoded formatted GET requests
  10. 9C48 MAY NOT allow executing mutations on GET requests
  11. 9ABE MAY respond with 4xx status code if content-type is not supplied on POST requests
  12. 03D4 MUST accept application/json POST requests
  13. 423L MAY use 400 status code on missing {query} parameter
  14. LKJ0 MAY use 400 status code on object {query} parameter
  15. LKJ1 MAY use 400 status code on number {query} parameter
  16. LKJ2 MAY use 400 status code on boolean {query} parameter
  17. LKJ3 MAY use 400 status code on array {query} parameter
  18. 34A2 MUST allow string {query} parameter when accepting application/graphql-response+json
  19. 13EE MUST allow string {query} parameter when accepting application/json
  20. 6C00 MAY use 400 status code on object {operationName} parameter
  21. 6C01 MAY use 400 status code on number {operationName} parameter
  22. 6C02 MAY use 400 status code on boolean {operationName} parameter
  23. 6C03 MAY use 400 status code on array {operationName} parameter
  24. 8161 MUST allow string {operationName} parameter when accepting application/graphql-response+json
  25. B8B3 MUST allow string {operationName} parameter when accepting application/json
  26. 94B0 MUST allow null {variables} parameter when accepting application/graphql-response+json
  27. 0220 MUST allow null {variables} parameter when accepting application/json
  28. 94B1 MUST allow null {operationName} parameter when accepting application/graphql-response+json
  29. 0221 MUST allow null {operationName} parameter when accepting application/json
  30. 94B2 MUST allow null {extensions} parameter when accepting application/graphql-response+json
  31. 0222 MUST allow null {extensions} parameter when accepting application/json
  32. 4760 MAY use 400 status code on string {variables} parameter
  33. 4761 MAY use 400 status code on number {variables} parameter
  34. 4762 MAY use 400 status code on boolean {variables} parameter
  35. 4763 MAY use 400 status code on array {variables} parameter
  36. 2EA1 MUST allow map {variables} parameter when accepting application/graphql-response+json
  37. 28B9 MUST allow map {variables} parameter when accepting application/json
  38. D6D5 MAY allow URL-encoded JSON string {variables} parameter in GETs when accepting application/graphql-response+json
  39. 6A70 MAY allow URL-encoded JSON string {variables} parameter in GETs when accepting application/json
  40. 0280 MUST use 4xx or 5xx status codes on string {extensions} parameter when accepting application/graphql-response+json
  41. 0281 MUST use 4xx or 5xx status codes on number {extensions} parameter when accepting application/graphql-response+json
  42. 0282 MUST use 4xx or 5xx status codes on boolean {extensions} parameter when accepting application/graphql-response+json
  43. 0283 MUST use 4xx or 5xx status codes on array {extensions} parameter when accepting application/graphql-response+json
  44. 2330 SHOULD use 4xx status code on string {extensions} parameter when accepting application/graphql-response+json
  45. 2331 SHOULD use 4xx status code on number {extensions} parameter when accepting application/graphql-response+json
  46. 2332 SHOULD use 4xx status code on boolean {extensions} parameter when accepting application/graphql-response+json
  47. 2333 SHOULD use 4xx status code on array {extensions} parameter when accepting application/graphql-response+json
  48. 58B0 SHOULD use 4xx or 5xx status codes on string {extensions} parameter when accepting application/json
  49. 58B1 SHOULD use 4xx or 5xx status codes on number {extensions} parameter when accepting application/json
  50. 58B2 SHOULD use 4xx or 5xx status codes on boolean {extensions} parameter when accepting application/json
  51. 58B3 SHOULD use 4xx or 5xx status codes on array {extensions} parameter when accepting application/json
  52. 428F MUST allow map {extensions} parameter when accepting application/graphql-response+json
  53. 1B7A MUST allow map {extensions} parameter when accepting application/json
  54. 8764 MAY use 4xx or 5xx status codes if parameters are invalid
  55. 3E3A MAY use 400 status code if parameters are invalid
  56. 572B SHOULD use 200 status code on document parsing failure when accepting application/json
  57. FDE2 SHOULD use 200 status code on document validation failure when accepting application/json
  58. 7B9B SHOULD use a status code of 200 on variable coercion failure when accepting application/json
  59. 865D MUST use 4xx or 5xx status codes on document parsing failure when accepting application/graphql-response+json
  60. 556A SHOULD use 400 status code on document parsing failure when accepting application/graphql-response+json
  61. D586 SHOULD not contain the data entry on document parsing failure when accepting application/graphql-response+json
  62. 51FE MUST use 4xx or 5xx status codes on document validation failure when accepting application/graphql-response+json
  63. 74FF SHOULD use 400 status code on document validation failure when accepting application/graphql-response+json
  64. 5E5B SHOULD not contain the data entry on document validation failure when accepting application/graphql-response+json
  65. 86EE SHOULD use a status code of 400 on variable coercion failure when accepting application/graphql-response+json

Notices

The server MAY support these, but are truly optional. These are suggestions following recommended conventions.
  1. A5BF MAY use 400 status code when request body is missing on POST
    Response status code is not 400
    {
      "statusText": "OK",
      "status": 200,
      "headers": {
        "keep-alive": "timeout=5",
        "date": "",
        "content-type": "application/json; charset=utf-8",
        "content-length": "55",
        "connection": "keep-alive"
      },
      "body": {
        "errors": [
          {
            "message": "POST body sent invalid JSON."
          }
        ]
      }
    }
    
  2. B6DC MAY use 4xx or 5xx status codes on JSON parsing failure
    Response status is not between 400 and 499
    {
      "statusText": "OK",
      "status": 200,
      "headers": {
        "keep-alive": "timeout=5",
        "date": "",
        "content-type": "application/json; charset=utf-8",
        "content-length": "55",
        "connection": "keep-alive"
      },
      "body": {
        "errors": [
          {
            "message": "POST body sent invalid JSON."
          }
        ]
      }
    }
    
  3. BCF8 MAY use 400 status code on JSON parsing failure
    Response status code is not 400
    {
      "statusText": "OK",
      "status": 200,
      "headers": {
        "keep-alive": "timeout=5",
        "date": "",
        "content-type": "application/json; charset=utf-8",
        "content-length": "55",
        "connection": "keep-alive"
      },
      "body": {
        "errors": [
          {
            "message": "POST body sent invalid JSON."
          }
        ]
      }
    }