Security & Abuse Control
One endpoint that lets a client compose arbitrary queries is a denial-of-service surface before it is anything else. Interviewers ask because disabling introspection is not an answer.
part ofGraphQLoverview, primer and where to startread it →on this pageshowhide
explore
- Introspection Exposure4 questions
- Depth & Breadth Limits3 questions
- Query Complexity Scoring4 questions
- Alias & Batch Amplification3 questions
- Operation Allowlists4 questions
- Field-Level Authorization5 questions
- Error Message Leakage3 questions
- CSRF & Content-Type3 questions
- Timeouts & Subscription Abuse4 questions
- Control Placement by Phase4 questions
questions
page 2 of 2How do you choose which GraphQL abuse controls to run at each phase for a public endpoint?
basics
~20 sRank candidate controls by what each phase knows, what each costs on every legitimate request, and how certain each rejection is. Push size, rate and content-type outward, keep document-shaped limits in the service, and treat execution deadlines as the backstop nothing static can replace.
One GraphQL schema serves your own app and external partners — how do you scope what each audience sees?
basics
~20 sSeparate visibility from authorization. What executes is decided by checks at execution for every audience; what a published schema shows is a contract decision, and a field a partner can see is one you must deprecate rather than delete.
Is an array of operations in one GraphQL request body part of the specification?
basics
~20 sNo. The GraphQL specification describes one request carrying one document and never mentions HTTP, and the GraphQL over HTTP working draft describes a single request per HTTP request. Array batching is a widespread convention, not a specified feature.
How can a denied GraphQL field confirm that a record exists, and when does that matter?
basics
~20 sIf a forbidden record produces an error entry at that field's path while a non-existent one produces a plain null, the difference answers a question the caller was never authorized to ask. It matters when identifiers are guessable or enumerable.
How long does a GraphQL subscription's authorization stay valid, and where is it re-checked?
basics
~20 sFor as long as the server chooses — nothing revokes it automatically. Authorization can be checked when the connection is established, again for each subscribe, and again per delivered payload; only the last catches a credential that expires mid-stream.
An enforced operation allowlist breaks any unregistered document — how do you set enforcement and retention policy when old app builds stay pinned for months?
basics
~20 sRun in log-only mode until the miss log holds no legitimate callers, then enforce. Tie document retention to the client-version support window rather than a fixed timer, scope the set per client, and keep an audited operator escape hatch.
showing 31–37 of 37