Skip to main content

Command Palette

Search for a command to run...

A GraphQL resolver must authorize every field

Updated
•1 min read•View as Markdown
A
Practical lessons on auth, authorization, and access control.

Authenticating the HTTP request that carries a GraphQL query is not enough.

Each field resolver that returns sensitive data or mutates state needs its own authorization check for that actor, object, and action. A single top-level "logged in" gate still lets a clever query walk into nested fields the caller should never see.

Authorize at the leaf, not only at the entrypoint.