4 ms·
You're welcome! A small correction: I shouldn't have said that "GraphQL has persisted queries"—they're not part of the spec or something. Just something many to
by dmitryminkovsky 5y ago
You're welcome! A small correction: I shouldn't have said that "GraphQL has persisted queries"—they're not part of the spec or something. Just something many tools allow/enable.
And by the way, in 2021, I wouldn't write a GraphQL backend by hand. I think a tool like Hasura/Postgraphile is the way to go. They put up excellent scaffolds that you can augment. In addition Hasura (I don't know about other tools) provides an access control layer that is really nice as well.
- criddell 5y agoFunny you should mention access control. One of the stumbling blocks for me when I did a bit of GraphQL work was adhering to the best practices listed here: https://graphql.org/learn/authorization/ https://graphql.org/learn/authorization/ That says authorization should not be in the resolver but putting it elsewhere often resulted in much more complicated code. It makes sense if GraphQL is coexisting with REST or other end points because they could all share the same authentication code, but for pure GraphQL projects it seems arbitrary.
- dmitryminkovsky 5y agoYes those docs bewildered me a bit as well. I never got too far with all of that or building a GraphQL server in JS for that matter. The authorization/access control in Hasura is game changing.