Skip to content

Is the use of visibility? sufficient for authorization? #4550

Answered by rmosolgo
maltesa asked this question in Q&A
Discussion options

You must be logged in to vote

Is it safe to assume that a user can NOT run a query if it's invisible for her/him?

Yes, that's a safe assumption. Under the hood, GraphQL-Ruby always filters the total set of types and fields into a limited set of visible types and fields. (When no visible? methods are implemented, the total set equals the limited set.) That limited set is then used for all of query execution.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by maltesa
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants