Manuel
cb9b54264d
fix: GraphQL error messages disclose pointer and relation target class names when public introspection is disabled ([GHSA-r2g6-4f6j-f6rf]( https://github.com/parse-community/parse-server/security/advisories/GHSA-r2g6-4f6j-f6rf )) ( #10568 )
2026-07-11 00:28:29 +02:00
Manuel
d96c945b6d
fix: GraphQL error messages disclose required input field names when public introspection is disabled ([GHSA-2fgh-8j2g-w354]( https://github.com/parse-community/parse-server/security/advisories/GHSA-2fgh-8j2g-w354 )) ( #10566 )
2026-07-10 17:43:50 +02:00
Manuel
2625489a27
fix: GraphQL variable-coercion suggestions disclose schema to unauthenticated callers ([GHSA-9g8f-h8f3-hjcm]( https://github.com/parse-community/parse-server/security/advisories/GHSA-9g8f-h8f3-hjcm )) ( #10563 )
2026-07-07 23:50:55 +02:00
Manuel
155123ade9
fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj]( https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj )) ( #10467 )
2026-05-18 17:04:56 +02:00
Manuel
56c159ec96
fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm]( https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm )) ( #10463 )
2026-05-17 15:11:10 +01:00
Manuel
f759bda075
fix: GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c]( https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c )) ( #10344 )
2026-03-29 02:32:35 +01:00
Manuel
4dd0d3d8be
fix: GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c]( https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c )) ( #10334 )
2026-03-27 15:03:33 +00:00
Manuel
51efb1efb9
fix: Instance comparison with instanceof is not realm-safe ( #10225 )
2026-03-16 21:30:09 +00:00
Manuel
b321423867
fix: Schema poisoning via prototype pollution in deep copy ([GHSA-9ccr-fpp6-78qf]( https://github.com/parse-community/parse-server/security/advisories/GHSA-9ccr-fpp6-78qf )) ( #10200 )
2026-03-14 16:01:04 +01:00
Manuel
3ffba757bf
fix: GraphQL WebSocket endpoint bypasses security middleware ([GHSA-p2x3-8689-cwpg]( https://github.com/parse-community/parse-server/security/advisories/GHSA-p2x3-8689-cwpg )) ( #10189 )
2026-03-12 14:23:50 +00:00
Manuel
0ae9c25bc1
fix: Denial-of-service via unbounded query complexity in REST and GraphQL API ([GHSA-cmj3-wx7h-ffvg]( https://github.com/parse-community/parse-server/security/advisories/GHSA-cmj3-wx7h-ffvg )) ( #10130 )
2026-03-07 23:40:45 +00:00
Manuel
61261a5aa1
fix: GraphQL __type introspection bypass via inline fragments when public introspection is disabled ([GHSA-q5q9-2rhp-33qw]( https://github.com/parse-community/parse-server/security/advisories/GHSA-q5q9-2rhp-33qw )) ( #10111 )
2026-03-06 02:25:34 +00:00
Antoine Cormouls
a5269f0776
fix: GraphQL introspection disabled in NODE_ENV=production even with master key ( #10071 )
2026-02-23 14:32:12 +00:00
Manuel
4c9c9489f0
feat: Add Parse.File.url validation with config fileUpload.allowedFileUrlDomains against SSRF attacks ( #10044 )
2026-02-07 17:03:39 +00:00
Antoine Cormouls
87c7f076eb
fix: Upgrade to GraphQL Apollo Server 5 and restrict GraphQL introspection ( #9888 )
...
BREAKING CHANGE: Upgrade to Apollo Server 5 and GraphQL express 5 integration; GraphQL introspection now requires using `masterKey` or setting `graphQLPublicIntrospection: true`.
2025-12-12 18:35:01 +01:00
Lucas Coratger
3ca85cd4a6
feat: Add GraphQL query cloudConfig to retrieve and mutation updateCloudConfig to update Cloud Config ( #9947 )
2025-12-03 19:55:30 +01:00
Lucas Coratger
47521974ae
feat: Add Parse Server option enableSanitizedErrorResponse to remove detailed error messages from responses sent to clients ( #9944 )
2025-11-28 19:48:35 +01:00
Lucas Coratger
50edb5ab4b
fix: Server internal error details leaking in error messages returned to clients ( #9937 )
2025-11-23 13:51:42 +01:00
Lucas Coratger
69a925879e
refactor: Add lint rules for no unused vars and unused import ( #9940 )
2025-11-22 22:12:34 +01:00
Antoine Cormouls
7d5e9fcf3c
fix: Race condition can cause multiple Apollo server initializations under load ( #9929 )
2025-11-17 16:18:39 +01:00
Antoine Cormouls
64f104e5c5
feat: Add request context middleware for config and dependency injection in hooks ( #8480 )
2025-10-14 20:16:31 +02:00
Alan Maulana Rahman
7b5395c5d4
fix: GraphQL playground shows blank page ( #9858 )
2025-09-21 17:45:07 +02:00
Manuel
c58b2eb6eb
fix: Data schema exposed via GraphQL API public introspection (GHSA-48q3-prgv-gm4w) ( #9819 )
2025-07-10 04:25:09 +02:00
Daniel
d21dd97336
fix: Remove username from email verification and password reset process ( #8488 )
...
BREAKING CHANGE: This removes the username from the email verification and password reset process to prevent storing personally identifiable information (PII) in server and infrastructure logs. Customized HTML pages or emails related to email verification and password reset may need to be adapted accordingly. See the new templates that come bundled with Parse Server and the [migration guide](https://github.com/parse-community/parse-server/blob/alpha/8.0.0.md ) for more details.
2025-03-02 02:32:43 +01:00
Daniel
889dbb5aee
refactor: Upgrade to eslint 9.19.0 ( #9580 )
2025-02-01 15:32:43 +01:00
Antoine Cormouls
3a9442a42f
refactor: Upgrade to mime 4.0.4 ( #9363 )
2024-10-23 20:03:48 +02:00
Manuel
dfd5a8edbf
ci: Add lint rule for mandatory curly braces ( #9348 )
2024-10-16 19:57:42 +02:00
Antoine Cormouls
907ad4267c
fix: Required option not handled correctly for special fields (File, GeoPoint, Polygon) on GraphQL API mutations ( #8915 )
2024-03-20 23:32:56 +01:00
Onur
105ae7c8a5
feat: Switch GraphQL server from Yoga v2 to Apollo v4 ( #8959 )
2024-03-02 02:06:47 +01:00
Antoine Cormouls
1aba6382c8
fix: GraphQL file upload fails in case of use of pointer or relation ( #8721 )
2024-02-14 21:44:42 +01:00
Daniel
6c79f6a69e
feat: Add request rate limiter based on IP address ( #8174 )
2023-01-06 13:39:02 +01:00
dblythy
5bbf9cade9
feat: Improve authentication adapter interface to support multi-factor authentication (MFA), authentication challenges, and provide a more powerful interface for writing custom authentication adapters ( #8156 )
2022-11-10 17:35:39 +01:00
vzukanov
0388956808
feat: add option to change the default value of the Parse.Query.limit() constraint ( #8152 )
2022-09-30 00:38:57 +02:00
Jong Eun Lee
7f5a15d5df
fix: graphQL query ignores condition equalTo with value false ( #8032 )
2022-07-03 12:13:10 +02:00
Antoine Cormouls
0d818879c2
fix: errors in GraphQL do not show the original error but a general Unexpected Error ( #8045 )
2022-06-17 13:40:31 +02:00
Antoine Cormouls
0cd902b8c2
refactor: upgrade GraphQL dependencies ( #7970 )
2022-06-10 14:01:45 +02:00
Antoine Cormouls
1aa2204aeb
feat: replace GraphQL Apollo with GraphQL Yoga ( #7967 )
2022-05-18 19:55:43 +02:00
Antoine Cormouls
68b15c298e
refactor: replace internal GraphQL array classes to object style ( #7788 )
2022-05-06 02:09:09 +02:00
Antoine Cormouls
626fad2e71
fix: setting a field to null does not delete it via GraphQL API ( #7649 )
...
BREAKING CHANGE: To delete a field via the GraphQL API, the field value has to be set to `null`. Previously, setting a field value to `null` would save a null value in the database, which was not according to the [GraphQL specs](https://spec.graphql.org/June2018/#sec-Null-Value ). To delete a file field use `file: null`, the previous way of using `file: { file: null }` has become obsolete.
2021-10-27 01:33:48 +02:00
Antoine Cormouls
85ef7217b0
feat: alphabetical graphql api, fix internal reassign, enhanced Graphql schema cache system ( #7344 )
2021-10-11 14:51:28 +02:00
Prerna Mehra
5d9bf24b02
GraphQL: reset password with emailed token ( #7290 )
...
* renamed "resetPassword" to "requestResetPassword" & created new "resetPassword" mutation
* added new route to handle resetPassword in UsersRouter.js
* updated resetPassword test to "requestResetPassword" mutation
* updated "resetPassword" mutation args description
* changed token arg description to rerun the tests
* directly using updatePassword for resetPassword
* removed handleResetPassword from UsersRouter.js file
* added test case for reset Password
* changed mutation names to "resetPassword" & "confirmResetPassword"
* changed mutation names in test also
2021-03-28 21:45:41 -07:00
Chris
6313656d8a
Excluding keys that have trailing "edges.node" on them ( #7273 )
...
* Excluding keys that have trailing "edges.node" on them as they will not be selectable anyway
* Updated CHANGELOG and added test case
* Forgot to change fit back to it
2021-03-17 20:40:11 -07:00
Diamond Lewis
a02014f557
Improve single schema cache ( #7214 )
...
* Initial Commit
* fix flaky test
* temporary set ci timeout
* turn off ci check
* fix postgres tests
* fix tests
* node flaky test
* remove improvements
* Update SchemaPerformance.spec.js
* fix tests
* revert ci
* Create Singleton Object
* properly clear cache testing
* Cleanup
* remove fit
* try PushController.spec
* try push test rewrite
* try push enqueue time
* Increase test timeout
* remove pg server creation test
* xit push tests
* more xit
* remove skipped tests
* Fix conflicts
* reduce ci timeout
* fix push tests
* Revert "fix push tests"
This reverts commit 05aba62f1c .
* improve initialization
* fix flaky tests
* xit flaky test
* Update CHANGELOG.md
* enable debug logs
* Update LogsRouter.spec.js
* create initial indexes in series
* lint
* horizontal scaling documentation
* Update Changelog
* change horizontalScaling db option
* Add enableSchemaHooks option
* move enableSchemaHooks to databaseOptions
2021-03-16 16:05:36 -05:00
Diamond Lewis
033a0bd443
Fix Prettier ( #7066 )
2020-12-13 11:19:04 -06:00
Antoine Cormouls
b398894341
Remove viewer from logout ( #7029 )
2020-12-07 15:45:51 -08:00
Antoine Cormouls
88e958a75f
Prettier some files + opti object relation ( #7044 )
2020-12-06 20:25:08 -08:00
Diamond Lewis
e6ac3b6932
fix(prettier): Properly handle lint-stage files ( #6970 )
...
Now handles top level files and recursive files in folders.
Set max line length to be 100
2020-10-25 15:06:58 -05:00
Antoine Cormouls
5693470101
transform input types also on user mutations ( #6934 )
2020-10-09 08:40:30 -07:00
Antoine Cormouls and Antonio Davi Macedo Coelho de Castro
62048260c9
GraphQL: Optimize queries, fixes some null returns (on object), fix stitched GraphQLUpload ( #6709 )
...
* Optimize query, fixes some null returns, fix stitched GraphQLUpload
* Fix authData key selection
* Prefer Iso string since other GraphQL solutions use this format
* fix tests
Co-authored-by: Antonio Davi Macedo Coelho de Castro <adavimacedo@gmail.com >
2020-10-01 15:19:26 -07:00
Antoine Cormouls
78239ac907
Merge pull request from GHSA-236h-rqv8-8q73
...
* Fix graphql viewer breach
* fix
* remove comment
2020-07-17 09:50:41 -07:00