8 ms·
Show HN: Graphweaver – Instant GraphQL API on Postgres, MySQL, SQLite and More
Graphweaver is an open-source GraphQL API Server that can connect many data sources to create a single API. Create a headless CMS, API Gateway, BaaS or use it as a BFF.
- skeep 3y agoSuper excited that this is finally released! It's been a great project to work on, can't wait to see what people build with it.
- graphweaver 3y agoThanks for all your hard work skeep!
- captn3m0 3y agoThe REST API connector docs is blank right now, but curious about it. How does it work (how is it configured?), and what’s the usecase for it?
- graphweaver 3y agoYou're right we need to improve the documentation on this. We do have an example though: https://github.com/exogee-technology/graphweaver/tree/main/src/examples/rest https://github.com/exogee-technology/graphweaver/tree/main/s... We have also added the OpenAPI spec on the roadmap however, every REST API we have integrated so far has been custom. The REST connector allows you to have full-control over how it connects to the API: https://github.com/exogee-technology/graphweaver/blob/main/src/examples/rest/src/backend/schema/user/resolver.ts https://github.com/exogee-technology/graphweaver/blob/main/s...
- krosaen 3y agoAnyone have experience with this and postgraphile? The additional data sources is clearly a benefit of graphweaver, but wondering for the postgres use case how they compare.
- graphweaver 3y agoWe have used postgres with every client deployment so far, it's our go to relational db. We have also needed to connect to a 2nd or 3rd data source on every project. So the power is when you combine these data sources.
- crubier 3y agoDo you know about Postgraphile? Your comment did not address that part, I’m curious too
- graphweaver 3y agoYeah sorry will address it directly. Graphweaver is different in a number of ways: - Graphweaver is not just Postgres, you can run it connected to only MySQL - Graphweaver can connect to one or more datasources. You can even connect both MySQL and Postgres together. Sounds crazy but could be good for a migration. - Graphweaver has two layers the API layer and the Data layer. Both of these are represented by coding classes in Typescript. You have full control over how these are exposed and defined in the entity files. - Graphweaver does not automatically reflect the database. Instead you run an import command in our CLI tool that creates Typescript class files for your database. From there you can edit them as needed.
- crubier 3y agoNice, interesting approach. I like Mikro ORM, I was thinking about building on top of it recently, I think it's a good idea. Looks like you went for the ORM equivalent of the Shadcn/ui approach. "We generate your code so you can customize it" instead of the more traditional "You use a library and can provide options to it to customize it". I like it! Postgraphile has a bunch of very cool filtering/grouping capabilities (with plugins), would be nice to have that at some point
- graphweaver 3y agoGreat can you point me to the filtering/grouping capabilities? I will take a look.
- ehutch79 3y agoI didn't go to deep, but I don't immediately see how you add business logic and custom validation. Not like this varchar can only be these values, but like if this field is X, then field Y can only by these values, and field Z is now required. Or, if this date has changed, then it must be a week or more in the future.
- graphweaver 3y agoWe add validation using https://github.com/typestack/class-validator https://github.com/typestack/class-validator. I will make sure we get this documented.
- ushakov 3y agoWhat’s the difference between GraphQL Mesh? Is this thing any relevant if I’m using React Server Components to fetch the data from the db directly?
- graphweaver 3y agoThe main difference is Graphweaver is code-only approach with Typescript. GraphQL Mesh is a schema-first approach. Both great projects, different philosophies.
- gedy 3y agoNice, is this comparable to Hasura? What are some differences if so?
- graphweaver 3y agoYeah it is comparable: - We are 100% open source. - Written in Typescript. - We support any data source directly in the server process, either with pre-built data providers or build your own. - We support cross data source filtering (get orders from database with CRM username)
- cpursley 3y agoBackend being written in TS is a big downside vs. Hasura’s blazing fast Haskell backend.
- gedy 3y agoTrue, but if it's open source, TS is probably a lot more practical for maintenance or contributions vs smaller pool of Haskell devs.
- dventimi 3y agoEvidently, Hasura is migrating to Rust. That's pretty fast and seems to have a lot of developers. https://discourse.haskell.org/t/hasura-migrating-to-rust/6620 https://discourse.haskell.org/t/hasura-migrating-to-rust/662...
- graphweaver 3y agoNot everyone will see TS as an advantage but there are many who will.
- gavinray 3y ago> We are 100% open source I mean, so is Hasura. https://github.com/hasura/graphql-engine https://github.com/hasura/graphql-engine (Disclaimer: Work at Hasura)
- revenga99 3y agodoes this support aggregations? ie sum, count etc.
- graphweaver 3y agoNothing out-of-the-box for this yet. We have actually done this for our clients, but it has been a custom field resolver: https://graphweaver.com/docs/graphql-entities-and-resolvers#25e235177d7f4a698136d9f9fe2c349c https://graphweaver.com/docs/graphql-entities-and-resolvers#...
- andy_ppp 3y agoEvery piece of magic in your application has the possibility of completely screwing you over when you least expect it. This includes all your dependencies and especially your backend. Given how trivial it is to write a real GraphQL API in frameworks these days, where you have complete control, it’s likely better to add that to your skill set rather than trusting a one size fits all solution that unlikely to solve every problem.
- graphweaver 3y agoThis is true but like with any build there are many decisions to make. We have settled on this stack for our API's and we think others will find it useful.
- andy_ppp 3y agoCool! How does security and multi-tenancy work in graph weaver? These were a really excruciating afterthought in Postgraphile…
- graphweaver 3y agoHere are some links around security: https://graphweaver.com/docs/adding-local-authentication https://graphweaver.com/docs/adding-local-authentication https://graphweaver.com/docs/implementing-authorization https://graphweaver.com/docs/implementing-authorization https://graphweaver.com/docs/column-level-security https://graphweaver.com/docs/column-level-security We have deployed Graphweaver using serverless and lambda be interesting to see how we could convert it to multi-tenant.
- crubier 3y agoCould you expand on how security is an afterthought in Postgraphile? My experience of using RLS and the graphile pro plugin was nice and secure imo. Curious if I missed something here
- andy_ppp 3y ago
- pyrolistical 3y agoWatch somebody use this as a public API and complain they got hacked
- graphweaver 3y agoWe agree, with any GraphQL API you need to make sure it is hardened for production. We are looking to add more on documentation on this soon and maybe a tutorial series on exactly this.
- timcobb 3y agoThe first thing I look for in these kinds of systems is access control, like Hasura has. Not seeing that here. Is that planned? Did I miss it?
- eddd-ddde 3y agoWould something like Postgres RLS be enough?
- graphweaver 3y agoWe have some docs on that here: https://graphweaver.com/docs/implementing-authorization https://graphweaver.com/docs/implementing-authorization The auth is at the access control is at the API layer.
- SoftwareDev4 3y agoHow is this different from WunderGraph? https://wundergraph.com/ https://wundergraph.com/
- graphweaver 3y agoWith Wundergraph, you define schema first. This generates types and hooks that you can then use on the front end. The production API is not a GraphQL API its Rest I believe. Graphweaver also generate types and react hooks for the front end, when running `graphweaver watch`. But Graphweaver is a GraphQL API and that is deployed into production. We wrap GraphQL Codegen and also do our own datasource introspection. More on that in this article: https://dev.to/tnodell/exploring-the-benefits-of-graphql-code-gen-22gd https://dev.to/tnodell/exploring-the-benefits-of-graphql-cod...
- gumballindie 3y agoHow does this lib handle GQL Injections?
- skeep 3y agoWe use MikroORM behind the scenes and keep up-to-date with versions and vulnerabilities. There is always more to do and we do accept PRs for improvements!
- gumballindie 3y agoThats pretty aweosme and this seems to be one of the first gql based projects that factor in gql injections that i stumbled upon. Nicely done!
- anonzzzies 3y agoAre there any tools that do this dynamically? Seems all are code generators.
- graphweaver 3y agoWe actually do that with the Contentful integration we’ve built. It dynamically reads the schema then creates the API.
- old_hat 3y agoThis looks really interesting. I'm regularly building systems that are plugged into multiple SaaS things, and would love a way to make that easier. I'll give this a go with a toy project and see if I can find the edges. Do you have any performance benchmarks available to compare to other similar tools?
- graphweaver 3y agoWe have done performance testing when releasing client projects but nothing that directly compares Graphweaver to competitors. I will add this to the list for us to do.