{
  "slug": "graphql",
  "name": "GraphQL APIs",
  "category": "Application",
  "summary": "Treat each GraphQL operation, resolver, and returned field as a separate server-side authorization and disclosure decision.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Schema and operation definitions",
    "Resolver or service authorization design",
    "Approved role contexts"
  ],
  "review": [
    {
      "title": "Classify operations",
      "body": "Group queries, mutations, subscriptions, batch operations, and persisted operations by the resources they read or change."
    },
    {
      "title": "Trace resolver authority",
      "body": "Verify each resolver forwards caller and tenant context to the service that owns the protected object."
    },
    {
      "title": "Review field disclosure",
      "body": "Check nested objects, fragments, errors, and connection edges for fields beyond the caller's policy."
    },
    {
      "title": "Contain exceptions",
      "body": "Ensure authorization failures stop execution and do not produce partial protected data."
    }
  ],
  "outputs": [
    "Operation-to-resource map",
    "Resolver authorization trace",
    "Field disclosure review"
  ],
  "pitfalls": [
    "Assuming schema visibility grants access",
    "Skipping nested resolver checks",
    "Treating an error as harmless without reviewing its data"
  ],
  "references": {
    "resources": [
      {
        "id": "graphql-ruby-2026-authorization-exception-integrity",
        "title": "GraphQL-Ruby: authorization exceptions must stop execution",
        "url": "https://vulns.co/research/resources/graphql-ruby-2026-authorization-exception-integrity/"
      },
      {
        "id": "microsoft-graph-batch-member-authorization-outcomes",
        "title": "Microsoft Graph batching: preserve each member authorization outcome",
        "url": "https://vulns.co/research/resources/microsoft-graph-batch-member-authorization-outcomes/"
      },
      {
        "id": "google-aip-158-pagination-authorization-boundary",
        "title": "Google AIP-158: pagination continuation does not grant resource authority",
        "url": "https://vulns.co/research/resources/google-aip-158-pagination-authorization-boundary/"
      }
    ],
    "diagrams": [
      {
        "id": "combined-view-source-authorization",
        "title": "Combined views preserve every source's access boundary",
        "url": "https://vulns.co/research/diagrams/combined-view-source-authorization/"
      }
    ],
    "reports": [
      {
        "id": "github-cross-repository-comparison-authorization-2025",
        "title": "GitHub comparison output lacked source-repository authorization",
        "url": "https://vulns.co/research/reports/github-cross-repository-comparison-authorization-2025/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/graphql/",
  "markdown_url": "https://vulns.co/skills/graphql/SKILL.md"
}
