logoalt Hacker News

JAlexoidlast Monday at 3:40 AM1 replyview on HN

Expecting GraphQL to handle security is really one of the poorest ways of doing security, as GQL is not designed to do that.


Replies

scotty79last Monday at 7:16 AM

Sorry, I made a typo:

Request can be tampered with so there's *NO additional security from GraphQL protocol.