3 ms·
You can and should protect GraphQL on the backend. GraphQL will just forward requests to resolvers which actually get the data, these resolvers should see who's
by tmsbrg 5y ago
You can and should protect GraphQL on the backend. GraphQL will just forward requests to resolvers which actually get the data, these resolvers should see who's logged in and only return data this user has access to. I'd say the security model the AI dungeon GraphQL uses (depending on GraphQL interfaces to protect subfields of objects) is broken. These fields should never be returned to GraphQL by the backend in the first place, if you're not authorized.
- holtalanm 5y agoThis. Your resolvers should still do access control. No different than a REST api would.