Add GraphQL query depth or complexity controls
Apollo Server bootstrap should declare validation rules or plugins that bound query cost.
#Metadata
#Why it matters
Without depth, complexity, persisted operations, or gateway limits, GraphQL endpoints are easier to abuse with expensive queries.
#Remediation
Add depth limits, query complexity rules, persisted operations, rate limits, or terminate behind a gateway/WAF that enforces GraphQL policies.
#Repository path
The generated metadata points to critiq-rules/libs/rules/catalog/rules/typescript/ts.security.apollo-server-missing-query-limits.rule.yaml.