4 ms·
i recently built a fullstack graphql app, and had it audited by a third party security firm Basically you have to blacklist every request at every resolver and
by Kagerjay 6y ago
i recently built a fullstack graphql app, and had it audited by a third party security firm
Basically you have to blacklist every request at every resolver and subresolver unless it passes the given user role iirc
but yeah graphql is just gaping wide open for security exploits especially since it also automatically documents the backend too
- tango12 6y agoYep, you definitely need to implement user authz for _every_ resolver indepedently and safelist/allowlist only those operations you'll use. You probably had to disable introspection in production too. Out of curiosity, could you name the third party security firm?
- Kagerjay 6y agoI didn't work on the security audit implementation though. I actually forgot what security firm we used, but it was local in our area. They provided a document detailing all the security exploits they found though. I don't recall exactly how this is done in graphQL, but i believe we used the context object and made a request to our database to find the users role. GraphQL endpoints have 4 arguments, the 4th one specifies the datagraph payload coming in. I think we blacklisted everything and whitelisted them depending on what the user requested and their corresponding role.