4 ms·
Ask HN: What is the current best-practice for authentication for Apollo/GraphQL?
- i6mi6 8y agoYou could easily restrict access to different mutations and queries using standard JWT. I'd say restricting parts of a query is a bit trickier because you would have to make explicit checks for the user context when extracting the data you want to be restricted. Other than that, you could pretty much use all kinds of standard authentication as you would use with REST, I've used JWT the most.
- benawad 8y ago1. Create a login mutation which creates a session and sends back a cookie. 2. Use resolver middleware to check whether the user is authenticated. I like to use express-session (https://github.com/expressjs/session https://github.com/expressjs/session) for part 1 and graphql-middleware (https://github.com/prisma/graphql-middleware https://github.com/prisma/graphql-middleware) for part 2.