I'm using Apollo Server with Azure Functions and as of a v3.8.0 there is a new embed option for the landing page plugin which allows the sandbox to be embedded into the server endpoint.
This is what my current config looks like
const server = new ApolloServer({
schema,
context: ({ context }) => context,
plugins: [ApolloServerPluginLandingPageLocalDefault({
embed: true
})],
});
export default server.createHandler({
cors: {
origin: '*'
},
});
I'd like to lock down the Function App in Azure by using Azure Active Directory and having any unauthenticated requests get rejected with 401: Unauthorized. The problem, however, is that would also deny access to the sandbox when trying to access it when deployed in Azure.
Is there a way to specify a separate sandbox endpoint that could allow unauthenticated requests? Then from the sandbox we could send in a Authorization: Bearer ... header to the actual graphql endpoint.