#55 · [Expert users] Persisted GraphQL Query Support
You can now test the security of Persisted GraphQL Queries with Escape's API security platform. This new capability enhances our GraphQL API security testing, offering deeper insights into vulnerabilities specific to persisted queries, allowing your team to protect APIs from targeted attacks better.
We support the following formats:
- Apollo
- Yoga
- Custom implementations
Why¶
- Optimized Testing for Persisted Queries: Persisted queries are often used for performance and security optimization in GraphQL, but they can introduce unique vulnerabilities if not properly secured. With our new feature, you can now detect security flaws in these pre-saved queries.
- Prevention of API Misuse: Attackers can exploit persisted queries to bypass query validation and inject malicious content. Escape ensures that your queries are thoroughly tested for such risks.
- Enhanced Coverage for GraphQL APIs: Persisted queries are a common practice in modern applications. This feature ensures that your GraphQL API testing is comprehensive, covering both dynamic and persisted queries.
- Seamless Integration with Your CI/CD Pipeline: As with other Escape features, testing persisted GraphQL queries integrates smoothly into your existing CI/CD workflows, keeping security at the forefront of your development process.
Getting started¶
- Go to the Security Scan tab, click on Tested applications, and select the application you want to test.
- Once you're on the scan result page, click on Settings and select Expert mode
- Configure your YAML file by adding the .json file for your persisted queries:
graphql_persisted_queries_url: https://example.com/persisted_queries_manifest.json
- Save the changes and restart the scan.
And that's it!
With these new updates, you should be able to tackle even the most advanced API risks with confidence. `