4 ms·
I didn't work on the security audit implementation though. I actually forgot what security firm we used, but it was local in our area. They provided a document
by Kagerjay 6y ago
I didn't work on the security audit implementation though. I actually forgot what security firm we used, but it was local in our area.
They provided a document detailing all the security exploits they found though.
I don't recall exactly how this is done in graphQL, but i believe we used the context object and made a request to our database to find the users role. GraphQL endpoints have 4 arguments, the 4th one specifies the datagraph payload coming in. I think we blacklisted everything and whitelisted them depending on what the user requested and their corresponding role.