Hacker News new | ask | show | jobs
by peterhunt 3784 days ago
It doesn't belong in the spec, it belongs in the implementation. But yes, the reference implementation (graphql-js) should probably be updated to demonstrate access control.
1 comments

> I think you misunderstand what GraphQL is.

> For each node type and edge type in the graph, you provide a required canSee() function which controls its visibility.

> It doesn't belong in the spec

_kek_

Am I on candid camera?