Broken Object-Level Authorization in GraphQL Resolvers
Authenticating a GraphQL caller is not the same as authorizing them for a specific object. When resolvers trust their id arguments, one logged-in user can read and mutate another user's data. Here is how BOLA reaches through resolver arguments, and how to enforce checks at every object.