Guard work item detail queries against the anonymous complexity cap
What does this MR do and why?
all_queries_spec.rb asserts the work item detail queries stay under the authenticated (250) and admin (300) complexity caps, but never under the unauthenticated one (200), which is the limit the widget-splitting work was done to get below. This adds that assertion for the two documents an anonymous visitor can actually send.
Measured with __typename injected, as Apollo sends it, and useWorkItemFeatures: true:
| Document | Complexity | Cap |
|---|---|---|
work_item_by_iid.query.graphql |
200 | 200 |
work_item_by_id.query.graphql |
198 | 200 |
Mutations and subscriptions need a session, so they're deliberately left out of the new block.
References
How to set up and validate locally
-
Run the new examples:
bundle exec rspec ee/spec/graphql/all_queries_spec.rb -e "work item detail query complexity for unauthenticated users" -
Re-add
contacts { nodes { id email } }undercrmContactsinapp/assets/javascripts/work_items/graphql/base_work_item_features.fragment.graphqland confirm both examples now fail, at 204 and 202.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.