4 ms·
I've always been a bit suspicious that mistakes like this are easier in GraphQL than older REST (or even SOAP) models because GraphQL is designed for more front
by robertclaus 2y ago
I've always been a bit suspicious that mistakes like this are easier in GraphQL than older REST (or even SOAP) models because GraphQL is designed for more frontend-driven development. Obviously this is just one example, but it was interesting that it involved "hidden" GraphQL data.
- DimmieMan 2y agoI think GraphQL vs others isn't relevant in this case. Would very likely be returning too much data with a REST API too. This is just neglect rather than a technical problem, any decent server implementation lets you authorise on a per field basis.
- RamblingCTO 2y agoIt has nothing to do with the implementing technology but bad decisions of people. Nothing in particular from the GraphQL standard enables this.