Skip to content

Remove GraphQL, user following, and the global activity feed - #2929

Merged
jake-low merged 3 commits into
mainfrom
remove-graphql
Oct 10, 2026
Merged

jake-low merged 3 commits into
mainfrom
remove-graphql

Conversation

@CollinBeczak

@CollinBeczak CollinBeczak commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator
  • replace GraphQL with REST for team management
  • remove following and the global activity feed from the frontend

Requires the backend's includeDetails support on /data/user/activity. maproulette/maproulette-backend#1290

GraphQL support is being removed from the backend, so move its last
frontend consumers to existing REST endpoints and drop Apollo.

- Teams: memberships, members, create/update/delete, invite,
  accept/decline, role changes and removal now use the /team routes.
  Memberships are joined with GET /team/:id for name, description
  and avatar.
- Following: following/followers lists and follow, unfollow, block
  and unblock use the /user/:id routes.
- Activity (Following widget, Global Activity): use
  /data/user/activity with includeDetails=true. GraphQL's offset was
  a page number, so pass page * limit. An empty user list meant "all
  users" in GraphQL; send osmUserIds=-1 for that. Global Activity
  only queries once a user is signed in, since the endpoint requires
  authentication.
- Queries and mutations move from Apollo to react-query, which is
  already in use. Apollo's normalized cache refreshed views after
  each mutation; affected queries are now invalidated explicitly.
- Team edits send the team's existing avatarURL back, because the
  REST update replaces it while the GraphQL mutation left it alone.
- Remove @apollo/client, graphql and
  REACT_APP_MAP_ROULETTE_SERVER_GRAPHQL_URL.

Requires the backend's includeDetails support on /data/user/activity.
…r/contributions

/data/user/activity is being removed along with GraphQL, and feeds of
other users' activity are being dropped to reduce the user data the app
exposes.

- Remove the profile page's "Recent activity from mappers you follow"
  feed, its API hook and its type.
- Load the dashboard Contributions section from GET
  /user/contributions, typed from the generated API types instead of a
  hand-written interface.
- Skip contributions with no date or challenge in the aggregation. The
  generated type marks both optional, and the challenge is absent when
  it has been deleted.

Requires the backend's /user/contributions endpoint.
@jake-low

jake-low commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Thanks for putting this up. I actually think this PR can be revised to:

  • replace GraphQL with REST for team management
  • remove following and the global activity feed from the frontend

Once this is done we can drop the GraphQL endpoint and the following and activity endpoints from the backend.

My goal as mentioned in https://community.openstreetmap.org/t/maproulette-security-incident-october-2026/148566 is to reduce the number of endpoints that return data about individual users. The current follow feature and global activity feed aren't essential to MapRoulette and removing them reduces the surface area that we need to keep secure.

@CollinBeczak
CollinBeczak marked this pull request as ready for review October 10, 2026 01:57
@CollinBeczak
CollinBeczak requested a review from jake-low October 10, 2026 02:03
@jake-low jake-low changed the title Replace GraphQL with REST for teams, following and activity Remove GraphQL, user following, and the global activity feed Oct 10, 2026

@jake-low jake-low left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I modified this to remove the user follow features too

@jake-low
jake-low merged commit 6f43add into main Oct 10, 2026
6 checks passed
@jake-low
jake-low deleted the remove-graphql branch October 10, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants