This reminds me of my main concern with GraphQL, namely that I could never find a good example showing how you weave security within a request. The examples I saw made me feel uncomfortable. Like, the client requests progressed further than I felt they should.
My typical approach to securing REST APIs is to use guard clauses + white lists. This is very explicit and easy to comprehend.