The $30,000 Gem: Part 1
hackerone.com | blog | #access-control | #api-security | #graphql | #hackerone | #authorization | #secure-design
Summary
HackerOne explains how it designed a permission layer between GraphQL and its database so queries only ever return data the requester is allowed to access; covers relationship-based access control and the Protected Attribute concept.
- Published
- Collected
Skip to content