3 ms·
Hi, author of the post here! With GraphQL, you can think of each field as a tiny endpoint, and you do access control on that in the same way as before. It tur
by djmashko2 9y ago
Hi, author of the post here!
With GraphQL, you can think of each field as a tiny endpoint, and you do access control on that in the same way as before.
It turns out that while GraphQL allows the frontend developers to select the data they need, that doesn't result in an unlimited set of queries. You often get a number of queries which is similar to what you would get if you hand-coded specific endpoints for different UI views, which turns out to be a common pattern outside of GraphQL.
> What happens if the user doesn't have access to part of the requested data
In this case, the gateway just falls back to the underlying server implementation, and it's a cache miss.
- otto_ortega 9y ago> It turns out that while GraphQL allows the frontend developers to select the data they need, that doesn't result in an unlimited set of queries. Could you please elaborate on that? Im new to GraphQL and I assumed that you only have to provide it with a schema that defines entities and their relations and it will let you query any combination over it. Does queries have to be explicitly set on the server? As an example, if I have the table "doctors" that has a 1:n relationship with the table "patients", do I have to explicitly define something like: queryDoctors { id name patients { id name } } To be able to query a doctor's patients?