5 ms·
In Apollo server you can add directives to your scehma for authz. It's dead simple. I'm surprised how so many HN posts about graphql just slander it. If you go
by bbbbzzz1 3y ago
In Apollo server you can add directives to your scehma for authz. It's dead simple.
I'm surprised how so many HN posts about graphql just slander it. If you go to the website and look at the use case of why it was made, it makes it pretty clear when it could be a good to use. My experience with it has been very straight forward and a joy
- x86x87 3y ago[flagged]
- bbbbzzz1 3y agoFeel free to read how to do it https://www.apollographql.com/docs/apollo-server/schema/directives/ https://www.apollographql.com/docs/apollo-server/schema/dire...
- theturtletalks 3y agoMy SaaS backend is a GraphQL Server that has single-handedly saved me tons of hours for integrations and coding. The first iteration of the app was using rest and that was a pain. Hitting multiple endpoints to get all the details of an order is not something I miss. On top of that, I get a beautiful playground that acts as a query builder and documentation. Have you actually used GraphQL in production or for a wide-scale project? A lot of these criticisms for GraphQL comes from people who have played with it for an hour and determined it's not good. Give it a real chance and you'll see why big companies are using it and understand why the ecosystem is growing so fast.
- x86x87 3y agoYes. Used it for a a couple of large projects at BigCo. Was actually brought in to "polish" a few things. One of the original team members thought it was cool. It was a disaster. Uncovered issue after issue. Convinced management to run a bug bounty program through hackerone and I'm going to let you guess what happened. If you're so brave and confident find a good pen tester and let them have a go at your api. It's a humbling experience.
- withinboredom 3y agoGraphQL (as in the language spec) offers no way to perform authz. Just because there are non-standardized extensions out there for some languages, doesn't mean it is available in whatever language you're using.
- tomtheelder 3y agoOk, but that’s true whether or not you use GQL.
- withinboredom 3y agoSure. I could respond with a 4xx code because you’re not authorized for that field. Ah, but maybe you want to know which field? Too bad GQL doesn’t really support that.
- cameronh90 3y agoAuthorization errors can go in the errors array which has a path reference in the standard. You generally don't want to use HTTP error codes with field level errors in GQL.
- paulryanrogers 3y agoSo still a 200? Or a 202, 206, 207?
- troupo 3y ago401 or 403. Why is this a question?
- paulryanrogers 3y agoBecause there may be fields requested correctly alongside some requested incorrectly
- sodapopcan 3y agoFor me it was the prevalence of GraphQL that was annoying. I have worked with it and liked it as a technology, but it was a tell from the org I worked for an was definitely overkill for what we were doing. No matter how you slice it, GraphQL is added complexity compared to REST but of course, as with a lot in our industry, there are all the people bought in who put in the time to learn it who are going to shout, "Naw, it's easy!" To be clear I'm not saying GraphQL is super complex, just more complex than REST and if all you need is REST then that is what you should be using. Yet in my many interviews over the past year I talked to a bunch of companies who used GraphQL and I'd say, "Oh, cool, why did you choose it?" and they'd say something along the lines of, "Well, the CTO who wrote the original app thought it was cool at the time." So I've always got the impression that the backlash mostly comes from the huge evangelism it got making it out to be The New Way. Again, to be clear, I'm not saying it was marketed this way but it's how it felt at the time. Annnd again, I know this happens constantly in our field.