All fixes

Disable GraphQL introspection

exposed-graphql

Introspection publishes every type, query and mutation your API supports. Turn it off in production so your schema is not a public document.

Why this matters

Your GraphQL endpoint has introspection enabled. The full schema is visible — reconnaissance data that maps your API but is not directly exploitable.

Express

  1. 1 Disable introspection in production
javascript
// Apollo Server
const server = new ApolloServer({
  typeDefs,
  resolvers,
  introspection: process.env.NODE_ENV !== 'production',
});

Does your app still have this?

Scan your domain