0Pricing
GraphQL APIs with Spring Boot · レッスン

クエリ複雑度の分析

DoS攻撃を防ぐため、受信したGraphQLクエリの複雑度を分析・制限する仕組みを実装します。

「クエリ複雑度の分析」はCoddyKit上の無料GraphQL APIs with Spring Bootレッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはGraphQL APIs with Spring Boot学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 GraphQL APIs with Spring Bootコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

What is Query Complexity?

When building GraphQL APIs, clients can request a lot of data in a single query. This flexibility is powerful, but it also carries a risk.

Query complexity refers to how much "work" your server needs to do to fulfill a particular GraphQL query. It's not just about the data size, but also the resources required.

Preventing Overload & DoS

Without limits, a malicious or poorly written query could ask for an excessive amount of deeply nested data or very large lists.

  • This can exhaust server resources (CPU, memory, database connections).
  • It can lead to slow response times for all users.
  • In extreme cases, it can cause a Denial-of-Service (DoS) attack, making your API unavailable.

Analyzing query complexity helps prevent these issues.

Deep Queries & Performance

Consider a query like fetching users, their posts, comments on those posts, and the authors of those comments. This creates a deep, nested structure:

users {
  posts {
    comments {
      author {
        name
      }
    }
  }
}

Each nesting level can mean more database queries or service calls, quickly multiplying the server's workload.

The Cost-Based Approach

To manage complexity, we often use a "cost-based" approach. This means assigning a numerical cost to each part of a GraphQL query.

  • Scalars: Simple fields like name or id might have a low cost (e.g., 1).
  • Objects: Complex types like User or Post might have a base cost, plus the sum of their selected fields.
  • Lists: A field returning a list (e.g., posts) is more complex. Its cost might be base + (number_of_items * item_cost).

The total cost of a query is the sum of all its field costs.

Simulating Query Depth (Java)

Let's imagine a simplified "query" as a tree structure. The "cost" could be its total number of nodes. This Java code demonstrates how to calculate the total nodes in such a structure.

Try running this example:

public class QueryNode {
  String name;
  QueryNode[] children;

  public QueryNode(String name, QueryNode... children) {
    this.name = name;
    this.children = children;
  }

  public int getTotalNodes() {
    int count = 1; // Count this node
    if (children != null) {
      for (QueryNode child : children) {
        count += child.getTotalNodes();
      }
    }
    return count;
  }

  public static void main(String[] args) {
    QueryNode author = new QueryNode("author");
    QueryNode comment = new QueryNode("comment", author);
    QueryNode[] comments = {comment, comment}; // Two comments
    QueryNode post = new QueryNode("post", comments);
    QueryNode[] posts = {post, post, post}; // Three posts
    QueryNode user = new QueryNode("user", posts);

    System.out.println("Total nodes (complexity): " + user.getTotalNodes());
  }
}

Complexity with GraphQL-Java

In a Spring Boot GraphQL application, the underlying graphql-java library provides tools for complexity analysis. The key component is an Instrumentation.

An Instrumentation is a hook that allows you to observe and modify the execution of a GraphQL query. For complexity, we use implementations like MaxQueryComplexityInstrumentation.

Configuring Your Max Limit

You configure the MaxQueryComplexityInstrumentation with a maximum allowed complexity value. If any incoming query's calculated cost exceeds this limit, the execution is stopped.

This prevents the server from processing overly expensive queries, protecting your resources. The client will receive an error message instead of a full data response.

What Happens on Overload?

When a query exceeds the configured maximum complexity, the GraphQL server will typically return a specific error message. This message informs the client that the query was too complex.

Example error (simplified):

{
  "errors": [
    {
      "message": "Query complexity of 1500 exceeds max allowed 1000"
    }
  ]
}

This allows clients to adjust their queries.

Customizing Field Costs

Beyond simple node counting, you can define more granular cost rules:

  • Field-specific costs: Assign higher costs to fields known to be expensive (e.g., image processing, external API calls).
  • Argument-based costs: Adjust cost based on arguments. For example, a products(limit: Int) field might cost 1 + (limit * 5).
  • Depth limiting: A simpler form of complexity analysis that only limits how deeply nested a query can be, without calculating a full cost.

Evaluate Complexity Analysis

Query complexity analysis is a crucial technique for robust GraphQL APIs.

Recap: Protecting Your API

In this lesson, we learned about query complexity analysis. It's a vital technique to measure the "cost" of a GraphQL query and set limits to prevent server overload and DoS attacks.

  • We understood how deep nesting and large lists contribute to complexity.
  • We explored the cost-based approach, where fields are assigned numerical costs.
  • We discussed how graphql-java and Spring Boot use Instrumentation to enforce these limits.

Next, we'll explore caching strategies to further boost your API's performance!

よくある質問

「クエリ複雑度の分析」レッスンは無料ですか?

はい。「クエリ複雑度の分析」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、GraphQL APIs with Spring Bootコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 GraphQL APIs with Spring Bootコースには全4レッスンが含まれています。

「クエリ複雑度の分析」で何を学びますか?

DoS攻撃を防ぐため、受信したGraphQLクエリの複雑度を分析・制限する仕組みを実装します。 ブラウザで直接実行するハンズオンコードでGraphQL APIs with Spring Bootを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

GraphQL APIs with Spring Bootを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのGraphQL APIs with Spring Bootは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。

「クエリ複雑度の分析」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このGraphQL APIs with Spring Bootレッスンでコードを書いて実行できますか?

はい。すべてのGraphQL APIs with Spring Bootレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. クエリ複雑度の分析
  2. GraphQLのキャッシュ戦略
  3. GraphQLの監視とトレーシング
  4. 永続化クエリとAutomatic Persisted Queries
← GraphQL APIs with Spring Bootに戻る