logoalt Hacker News

8n4vidtmkvmklast Sunday at 7:07 PM1 replyview on HN

I think you're oversimplifying it. You've left on the part where the client can specify which fields they want.


Replies

verdvermlast Sunday at 7:09 PM

That's something you should only really do in development, and then cement for production. Having open queries where an attacker can find interesting resolver interactions in production is asking for trouble

show 3 replies