skip to content

Security & Abuse Control

One endpoint that lets a client compose arbitrary queries is a denial-of-service surface before it is anything else. Interviewers ask because disabling introspection is not an answer.

part ofGraphQLoverview, primer and where to startread it →
on this pageshow

questions

page 2 of 2

How do you choose which GraphQL abuse controls to run at each phase for a public endpoint?

level: principalimportance: should knowfreq 33%

basics

~20 s

Rank candidate controls by what each phase knows, what each costs on every legitimate request, and how certain each rejection is. Push size, rate and content-type outward, keep document-shaped limits in the service, and treat execution deadlines as the backstop nothing static can replace.

open as a page

In a GraphQL schema many teams extend, how do you guarantee every new field is authorized before it ships?

level: principalimportance: should knowfreq 42%

basics

~20 s

Make the default deny rather than allow, so an unmarked field fails a build check instead of shipping open; require an explicit, reviewed exception list for genuinely public fields; and prove enforcement with denial tests and denial metrics rather than with schema review.

open as a page

One GraphQL schema serves your own app and external partners — how do you scope what each audience sees?

level: principalimportance: should knowfreq 30%

basics

~20 s

Separate visibility from authorization. What executes is decided by checks at execution for every audience; what a published schema shows is a contract decision, and a field a partner can see is one you must deprecate rather than delete.

open as a page

Is an array of operations in one GraphQL request body part of the specification?

level: middleimportance: nice to knowfreq 29%

basics

~20 s

No. The GraphQL specification describes one request carrying one document and never mentions HTTP, and the GraphQL over HTTP working draft describes a single request per HTTP request. Array batching is a widespread convention, not a specified feature.

open as a page

How can a denied GraphQL field confirm that a record exists, and when does that matter?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

If a forbidden record produces an error entry at that field's path while a non-existent one produces a plain null, the difference answers a question the caller was never authorized to ask. It matters when identifiers are guessable or enumerable.

open as a page

How long does a GraphQL subscription's authorization stay valid, and where is it re-checked?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

For as long as the server chooses — nothing revokes it automatically. Authorization can be checked when the connection is established, again for each subscribe, and again per delivered payload; only the last catches a credential that expires mid-stream.

open as a page

An enforced operation allowlist breaks any unregistered document — how do you set enforcement and retention policy when old app builds stay pinned for months?

level: principalimportance: nice to knowfreq 22%

basics

~20 s

Run in log-only mode until the miss log holds no legitimate callers, then enforce. Tie document retention to the client-version support window rather than a fixed timer, scope the set per client, and keep an audited operator escape hatch.

open as a page

showing 31–37 of 37