Commit a9d288a
authored
Version Packages (#7712)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.
# Releases
## @apollo/[email protected]
### Patch Changes
- Updated dependencies
\[[`a1c725eaf`](a1c725e)]:
- @apollo/[email protected]
## @apollo/[email protected]
### Patch Changes
-
[`a1c725eaf`](a1c725e)
Thanks [@trevor-scheer](https://github.com/trevor-scheer)! - Ensure API
keys are valid header values on startup
Apollo Server previously performed no sanitization or validation of API
keys on startup. In the case that an API key was provided which
contained characters that are invalid as header values, Apollo Server
could inadvertently log the API key in cleartext.
This only affected users who:
- Provide an API key with characters that are invalid as header values
- Use either schema or usage reporting
- Use the default fetcher provided by Apollo Server or configure their
own `node-fetch` fetcher
Apollo Server now trims whitespace from API keys and validates that they
are valid header values. If an invalid API key is provided, Apollo
Server will throw an error on startup.
For more details, see the security advisory:
<GHSA-j5g3-5c8r-7qfx>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>1 parent b0693aa commit a9d288a
File tree
6 files changed
+33
-24
lines changed- .changeset
- packages
- integration-testsuite
- server
6 files changed
+33
-24
lines changedThis file was deleted.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
3 | 10 | | |
4 | 11 | | |
5 | 12 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
| 31 | + | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
3 | 22 | | |
4 | 23 | | |
5 | 24 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
0 commit comments