vulns.co
/
GKData.io MCP
AP / Application

GraphQL APIs

Treat each GraphQL operation, resolver, and returned field as a separate server-side authorization and disclosure decision.

Guide 05 / 154 review notesUpdated 2026-10-11

The review

What to look for

Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.

  1. Classify operations

    Group queries, mutations, subscriptions, batch operations, and persisted operations by the resources they read or change.

  2. Trace resolver authority

    Verify each resolver forwards caller and tenant context to the service that owns the protected object.

  3. Review field disclosure

    Check nested objects, fragments, errors, and connection edges for fields beyond the caller's policy.

  4. Contain exceptions

    Ensure authorization failures stop execution and do not produce partial protected data.

What to produce

  • Operation-to-resource map
  • Resolver authorization trace
  • Field disclosure review

Common mistakes

  • Assuming schema visibility grants access
  • Skipping nested resolver checks
  • Treating an error as harmless without reviewing its data

Continue the study

Reading & source context

Editorial notes above connect these references. Open each record for its original source and review date.

Visual models

Connected disclosures

From the field toolkit

Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.

Next skillJavaScript and client trust →