GraphQL API Security: Introspection, Deep Queries and the Authorization Gap
GraphQL hands clients a flexible query language — and hands attackers a map of your whole schema if you let it. Here is how introspection, query abuse and missing authorization go wrong, and how to lock the endpoint down.