Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

The $30,000 Gem: Part 1

Summary

HackerOne explains how it designed a permission layer between GraphQL and its database so queries only ever return data the requester is allowed to access; covers relationship-based access control and the Protected Attribute concept.
Published
Collected

original ↗

Related coverage

back