A GraphQL resolver must authorize every field
Authenticating the HTTP request that carries a GraphQL query is not enough.
Each field resolver that returns sensitive data or mutates state needs its own authorization check for that actor, object, and action. A single top-level "logged in" gate still lets a clever query walk into nested fields the caller should never see.
Authorize at the leaf, not only at the entrypoint.
