UsePersistedOperationsEnforcement
Kept so existing hosts compile. It adds nothing to the ASP.NET pipeline: enforcement runs inside HotChocolate's execution pipeline as soon as UsePersistedOperations is configured, whether or not this is called. It is hidden from IntelliSense.
Signature
[EditorBrowsable(EditorBrowsableState.Never)]
public static IApplicationBuilder UsePersistedOperationsEnforcement(
this IApplicationBuilder app
);Returns app unchanged. Throws ArgumentNullException when app is null.
Where enforcement runs
A request middleware placed right after HotChocolate's document parser and before validation. Every transport reaches the executor through that pipeline: a JSON POST, a GET, a multipart POST, a WebSocket subscribe, and a request built in-process.
Decision flow
For each operation:
- If the document came from the store (the request named a persisted id): execute it.
- If the request carries HotChocolate's
AllowNonPersistedOperation()override, which only host code building its own request can set: execute it. - Otherwise the document is inline:
- Allowlist match (operation name in
AllowOperationsor matching a predicate; the document id when there is no name): execute it. Both keys are chosen by the caller and the document is not inspected, so the allowlist is a convenience for trusted networks, not a control. See Allowlist and dev carve-outs. - Management surface (every operation selects
operations { persistedOperations { ... } }and nothing else): execute it. - Introspection (the parsed document's top-level selections are all
__schema,__typeor__typename): execute it unlessDisableIntrospection()was called. - Enforcement off (
RequirePersisted(false)): execute it, logging at Information whenLogNonPersistedRequests(true). - Otherwise: refuse it. Over HTTP the status is
400 Bad Requestand the body is:
- Allowlist match (operation name in
{
"errors": [{
"message": "Only persisted operations are accepted on this server.",
"extensions": { "code": "PERSISTED_OPERATION_REQUIRED" }
}]
}Over a socket the same error arrives as an error message for that operation id. Each entry of a batched request is decided on its own.
Auth ordering
Enforcement runs inside HotChocolate, after ASP.NET authentication and after TraxGraphQLAuthInterceptor built the request, so an endpoint gated by RequireAuthorization() rejects an unauthenticated caller before any persisted-document lookup.