3 ms·
>What about permissions? What if the logged in user is only allowed to see certain fields? Do I make a table that describes every possible field and which roles
by rkv 10y ago
>What about permissions? What if the logged in user is only allowed to see certain fields? Do I make a table that describes every possible field and which roles can access it?
GraphQL is permission agnostic which allows you to develop your own methods. But there are a lot of nice implementations floating around [1].
>How do I know what's available to query, without reading docs?
Introspection[2].
1. https://github.com/joonhocho/graphql-rule https://github.com/joonhocho/graphql-rule
2. http://graphql.org/learn/introspection http://graphql.org/learn/introspection
- atmartins 10y agoI appreciate the answer. It looks like I do want to create a rule for each property. Why? Why not create meaningful objects and not micro-manage individual properties? In case I want to update my front end query in the future? Shouldn't I just make my objects more granular, rather than this extreme of managing individual properties? I'm genuinely interested from an architectural standpoint what the real gain is here, it really seems like there are major portions of a useful api that are not discussed when I've looked in to GraphQL.