Easy Attribute-based Access Control for any GraphQL API

preview_player
Показать описание
Is securing GraphQL APIs harder than securing REST APIs?

Here at StepZen, we're often asked about securing GraphQL APIs. If you only consider that the main method of interacting with a GraphQL API is an HTTP request, the answer is no, it's not harder. There are time-proven ways of handling security for HTTP.

In this video, @gethackteam demonstrates StepZen Field Policies, which allow you to control access to your GraphQL API beyond simply approving or blocking the HTTP request. Field Policies can be used on APIs created in StepZen or applied to any GraphQL API, regardless of implementation technology. As security is as important for GraphQL as for any other GraphQL API.

Learn more about StepZen:

---
Рекомендации по теме