5 ms·
The argument against GraphQL in this article (and the article is linked to) is hand-wavy. It just says GraphQL is not secure without going into why and the exam
by iddan 3y ago
The argument against GraphQL in this article (and the article is linked to) is hand-wavy. It just says GraphQL is not secure without going into why and the example is: exposing a field on a record that you shouldn’t - which can happen in REST too! Especially if you are implementing something like JSON API includes[0]. After building frontend for 8 years GraphQL seems like the most scalable solution if you have a large dynamic frontend app. The approach of coupled server (whether it’s htmx or Remix or Rails for that matter) works as well but as the article mentions it makes you build another API for any other client.
0: https://jsonapi.org/format/#fetching-includes https://jsonapi.org/format/#fetching-includes
- recursivedoubts 3y ago> The biggest issue that we see is security, as we outline this in The API Churn/Security Trade-off[1] essay. > Apparently facebook uses a whitelist to deal with the security issues introduced by GraphQL, but many developers who are using GraphQL appear to not understand the security threats involved with it. I link to a longer essay on the inherent issues w/ increasing the client-side expressiveness of an API. It boils down to the fact that you give that power to anyone who can fire up a web console, in contrast with server-side expressiveness. [1] - https://intercoolerjs.org/2016/02/17/api-churn-vs-security.html https://intercoolerjs.org/2016/02/17/api-churn-vs-security.h...
- theK 3y agoI agree with the article that security is a topic that a GraphQL implementation needs to grasp and explicitly address but I’m with you in that it is not a showstopper and good strategies already exist and that a JSON api could also fall victim to this. From personal experience the biggest challenge a GraphQL implementation faces is tighter/direct coupling with the backend data Schema which tends to either become friction in schema evolution or attract so much engineering effort that it is essentially also sustaining development of a hypermedia API.