3 ms·
I don't think this author has much experience with GraphQL. Your typical "POST Body" in GraphQL is strong typed the same way as the response body. You also do
by tylergetsay 4y ago
I don't think this author has much experience with GraphQL.
Your typical "POST Body" in GraphQL is strong typed the same way as the response body.
You also don't have to (and I'd say you shouldn't) map your SQL database to your GraphQL schema 1 to 1.
In my experience, databases like Firebase are more likely to be susceptible to these attacks given their hard to understand permission models.
- twblalock 4y ago> You also don't have to (and I'd say you shouldn't) map your SQL database to your GraphQL schema 1 to 1. My main complaint about GraphQL is that junior engineers tend to use it as an excuse to do exactly that. They don't understand that the API and database schema are different things.
- xboxnolifes 4y agoHow is that a complaint about GraphQL when the common alternative, REST, was basically designed to map 1:1 API resources to database tables. Each endpoint is a resource, and every resource is almost always either most of a table or a simple table join.